Webflow

Webflow is the way to design, build, and launch powerful websites visually — without coding.

Senior Security Engineer – Infrastructure & Automation

Security EngineerSecurity EngineerFull TimeRemoteTeam 501-1,000Since 2013H1B SponsorCompany SiteLinkedIn

Location

California

Posted

3 days ago

Salary

$139K - $198K / year

Bachelor Degree5 yrs expEnglishAWSCloudFirewallsGoogle Cloud PlatformJava ScriptKubernetesPythonTerraformGo

Job Description

• You’ll lead and execute cloud security initiatives that strengthen Webflow’s infrastructure and operational security posture. Responsibilities are grouped by scope and impact. • Perform infrastructure security reviews across cloud services, network design, IAM, and platform components. • Design, implement, and maintain secure AWS and GCP infrastructure following best practices (least privilege, network segmentation, encryption, monitoring). • Partner with infrastructure and platform teams to embed security controls in CI/CD pipelines, infrastructure as code, and containerized environments. • Own the cloud security posture management (CSPM) strategy, ensuring continuous compliance and automated detection of misconfigurations. • Collaborate with engineering teams to secure Kubernetes and containerized workloads, ensuring adherence to runtime and image scanning policies. • Respond to and investigate cloud-related security incidents, providing technical expertise during triage and remediation. • Contribute to the design and execution of Webflow’s cloud security roadmap, identifying areas for automation and scalability. • Conduct threat modeling and risk assessments for cloud architecture and new service deployments. • Translate raw findings into actionable engineering fixes, not just tickets or reports. • Design and build internal security services, APIs, and tools that automate infrastructure vulnerability detection, triage, reporting, and remediation. • Develop security automation that integrates with CI/CD, cloud control planes, and developer workflows to shift detection and remediation earlier in the lifecycle. • Experiment with and operationalize agentic and AI-assisted approaches to security detection, analysis, and response as the threat landscape evolves.

Job Requirements

  • Have 5+ years of experience in cloud security, infrastructure engineering, or security automation (with at least 3 years focused on AWS and GCP).
  • Demonstrate strong knowledge of AWS and GCP services and security controls.
  • Have hands-on experience securing Kubernetes and containerized workloads.
  • Are proficient with infrastructure as code (Pulumi, Terraform, CloudFormation).
  • Understand network security concepts including firewalls, segmentation, and zero trust.
  • 3+ years of automation script authoring for security tasks using Python, Go, Javascript, Typscript, or similar languages. Comfortable architecting automation solutions using full stack components.
  • Are comfortable operating in ambiguous, fast-changing environments, adapting tooling and approaches as threats and technologies evolve.
  • Bring a proactive, builder’s mindset — identifying and closing gaps before they become issues.

Benefits

  • Ownership in what you help build. Every permanent Webflower receives equity (RSUs) in our growing, privately held company.
  • Health coverage that actually covers you. Comprehensive medical, dental, and vision plans for full-time employees and their dependents, with Webflow covering most premiums.
  • Support for every stage of family life. 12 weeks of paid parental leave for all parents and 6+ weeks of additional paid leave for birthing parents. Plus inclusive care for family planning, menopause, and midlife transitions.
  • Time off that’s actually off. Flexible vacation, paid holidays, and a sabbatical program to help you recharge and come back inspired.
  • Wellness for the whole you. Access to mental health resources, therapy and coaching.
  • Invest in your future. A 401(k) with 100% employer match (up to $6,000/year) in the U.S., and support for retirement savings globally.
  • Monthly stipends that flex with your life. Localized support for work and wellness expenses — from Wi-Fi to workouts.
  • Bonus for building together. All full-time, permanent, non-commission employees are eligible for our annual WIN bonus program.

Related Categories

Related Job Pages

More Security Engineer Jobs

Lead Security Engineer

Swiftly, Inc.

Making cities move more efficiently

Security Engineer3 days ago
Full TimeRemoteTeam 51-200H1B No Sponsor

The Lead Security Engineer will own the security risk register and threat models, driving remediation across application and infrastructure, while designing secure architectures for SaaS, mobile, and IoT integrations. This role also involves leading compliance renewals like SOC 2, defining security standards, and building DevSecOps guardrails into CI/CD pipelines.

AWSTerraformCI/CDDevSecOpsSOC 2IAMNetworkingLoggingMonitoringSecrets ManagementPolicy-as-CodeOPASentinelContainer SecurityOrchestration SecurityThreat ModelingRisk AssessmentIncident ResponseApplication Security
United States + 1 moreAll locations: United States, Canada
$140K - $200K / year
Security Engineer3 days ago
Full TimeRemoteTeam 5,001-10,000Since 2000H1B No Sponsor

The High School Science Teacher is responsible for delivering specific course content in an online environment, providing instruction, managing the learning process, and actively working with students and parents to advance learning goals. Essential functions include providing engaging synchronous and asynchronous learning experiences, differentiating instruction, maintaining the grade book, and preparing students for high-stakes standardized tests.

United States
Security Engineer3 days ago
Full TimeRemote

We are seeking a Cybersecurity Engineer to help protect our organization's systems, networks, and data from cyber threats. This role will design, implement, and maintain security controls and technologies while monitoring and responding to security incidents. The ideal candidate ...

SIEMIDSIPSEDRFirewallEndpoint SecurityVulnerability ManagementIncident ResponseNetwork SecurityAWSAzureGCPPythonBashPowerShellPenetration TestingThreat HuntingDevSecOpsNISTISO 27001CIS
United States

Senior Developer, Product Security

1Password

Productive businesses use 1Password to secure employees at scale.

Security Engineer3 days ago
Full TimeRemoteTeam 501-1,000Since 2009H1B Sponsor

Senior Developer implementing new security features for 1Password applications

RustSwiftTypeScriptGo
United States
$153K - $214K / year