Security Engineer
Join a new security team during a critical build-out phase, working across application and infrastructure security. The role is a generalist position involving code reviews, cloud hardening, incident response, secure design, security findings, remediation, and documentation while collaborating closely with engineering teams.
Responsibilities
- Perform application security reviews through code reviews, SAST/DAST, and dependency scanning.
- Participate in threat modeling for new features and architecture changes.
- Harden cloud and container infrastructure using GCP, Kubernetes, and IAM configurations.
- Triage penetration test findings and coordinate remediation with engineering teams.
- Review architectures and advise on secure implementation patterns.
- Identify, assess, document, and track security findings through remediation.
- Investigate and document security events and contribute to root-cause analysis.
- Write async security advisories, best-practice documentation, and practical guidance.
- Support product security reviews for customer-facing services.
Requirements
- Understanding of common vulnerability classes, secure coding patterns, and meaningful code review.
- Experience with GCP or a similar cloud provider, including IAM, networking, and container concepts.
- Ability to read and review Go, Python, or PHP code.
- Familiarity with SAST, DAST, or dependency scanning tools.
- Strong written communication and clear async documentation skills.
- Ability to partner effectively with engineering teams.
- Eagerness to learn and comfort with ambiguity.