Remote job
Security Engineer
Job details
About this role
Role overview Own security engineering for a multi-tenant compliance platform where access boundaries and reliable records are central to customer trust. You’ll strengthen existing controls and help teams make secure design decisions as features and operational practices evolve.
Responsibilities - Threat-model new features and identify risks to tenant isolation, permissions, authentication, and audit records. - Review database migrations and changes to row-level security policies for tenant-scoped data. - Make security review a required part of changes that affect authentication or authorization. - Guide decisions about adding multifactor authentication and single sign-on. - Improve web application firewall rules, secret rotation, and security controls for builds and deployments. - Help establish compliance practices and an internal approach to red-team exercises.
Requirements - Experience with application security engineering and threat modeling. - Understanding of multi-tenant architecture, role-based access, and database-level security controls. - Ability to review authentication and authorization changes, including database migrations. - Familiarity with security hardening, secrets management, and secure software delivery. - Ability to work with engineers to turn security risks into practical design and implementation steps.