Jobgether logo
Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Lead Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteLeadH1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

5 days ago

Salary

Not specified

Seniority

Lead

AWSTerraformCI/CDDevSecOpsContainer SecurityThreat ModelingSOC 2IAMNetwork SecuritySecrets ManagementPolicy-as-CodeOPARisk AssessmentIncident Response

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

This role offers the opportunity to lead and shape the security posture of a rapidly growing, cloud-native platform. The Lead Security Engineer will partner with engineering, product, and corporate teams to:

  • Design secure systems
  • Implement DevSecOps practices
  • Drive compliance initiatives

You will balance strategic planning with hands-on engineering, ensuring robust protections across SaaS, mobile, and IoT environments. This position provides visibility into planning and execution at all levels, allowing you to influence security strategy, mentor teams, and embed security into daily operations. Ideal candidates thrive in a collaborative environment, are self-directed, and are motivated by making high-impact security decisions that enable business growth and customer trust.

Accountabilities:

  • Own and manage the organization’s security risk register, threat models, and remediation efforts across applications, infrastructure, and services.
  • Design secure architectures focusing on authentication, authorization, data protection, and network boundaries for SaaS, mobile, and IoT products.
  • Implement and maintain security tools, DevSecOps guardrails, and CI/CD pipelines to detect vulnerabilities and misconfigurations early.
  • Lead compliance initiatives, including SOC 2 and other relevant frameworks, and respond to customer security inquiries.
  • Define and maintain security policies, standards, KPIs, and dashboards; provide visibility and guidance to teams and executives.
  • Conduct internal security assessments and coordinate external penetration tests.
  • Mentor engineering teams in secure design practices and foster a security-aware culture across the organization.
  • Develop and maintain incident response plans, serve as escalation point for incidents, and lead investigations and remediation.

Qualifications

  • 5+ years of experience in security engineering with both hands-on and strategic responsibilities.
  • Strong expertise securing cloud-native environments (AWS preferred), including IAM, networking, logging/monitoring, and secrets management.
  • Experience with infrastructure-as-code (Terraform) and policy-as-code frameworks (OPA, Sentinel, or similar).
  • Hands-on experience integrating security into CI/CD pipelines and development workflows.
  • Knowledge of container and orchestration security, threat modeling, and risk assessment.
  • Familiarity with compliance frameworks (SOC 2 preferred) and audit processes.
  • Strong communication skills to collaborate with both technical and non-technical stakeholders.
  • Self-directed, able to operate autonomously, and comfortable leading cross-functional initiatives.

Requirements

  • CISSP or cloud security certifications.
  • Experience securing AI/ML or LLM-powered features.
  • Mobile application security experience (Android preferred).
  • Knowledge of GRC and compliance platforms.
  • Experience with international compliance frameworks and regulated industries.
  • Familiarity with IoT, embedded systems, or fleet device security and MDM solutions.

Benefits

  • Competitive salary and equity compensation.
  • Medical, dental, and vision insurance.
  • Retirement plan with employer match (401(k)/RRSP).
  • Flexible Spending Accounts (FSA) and wellness stipends.
  • Home office setup reimbursement and monthly internet/cell stipend.
  • Flexible PTO, 16 paid holidays, and 8 fully paid weeks for childbirth/adoption leave.
  • Flexible, remote-friendly work environment.
  • Annual company offsites to build team relationships.
  • Opportunity to make high-impact contributions to security, compliance, and business growth.

Job Requirements

  • 5+ years of experience in security engineering with both hands-on and strategic responsibilities.
  • Strong expertise securing cloud-native environments (AWS preferred), including IAM, networking, logging/monitoring, and secrets management.
  • Experience with infrastructure-as-code (Terraform) and policy-as-code frameworks (OPA, Sentinel, or similar).
  • Hands-on experience integrating security into CI/CD pipelines and development workflows.
  • Knowledge of container and orchestration security, threat modeling, and risk assessment.
  • Familiarity with compliance frameworks (SOC 2 preferred) and audit processes.
  • Strong communication skills to collaborate with both technical and non-technical stakeholders.
  • Self-directed, able to operate autonomously, and comfortable leading cross-functional initiatives.
  • CISSP or cloud security certifications.
  • Experience securing AI/ML or LLM-powered features.
  • Mobile application security experience (Android preferred).
  • Knowledge of GRC and compliance platforms.
  • Experience with international compliance frameworks and regulated industries.
  • Familiarity with IoT, embedded systems, or fleet device security and MDM solutions.

Benefits

  • Competitive salary and equity compensation.
  • Medical, dental, and vision insurance.
  • Retirement plan with employer match (401(k)/RRSP).
  • Flexible Spending Accounts (FSA) and wellness stipends.
  • Home office setup reimbursement and monthly internet/cell stipend.
  • Flexible PTO, 16 paid holidays, and 8 fully paid weeks for childbirth/adoption leave.
  • Flexible, remote-friendly work environment.
  • Annual company offsites to build team relationships.
  • Opportunity to make high-impact contributions to security, compliance, and business growth.

Related Categories

Related Job Pages

More Security Engineer Jobs

FM logo

Cyber Specialist Co-Op

FM

Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk management and the resilience of its policyholder-owners. These owners, who share the belief that the majority of property loss is preventable, represent many of the world’s largest organizations, including one of every four Fortune 500 companies. They work with FM to better understand the hazards that can impact their business continuity to make cost-effective risk management decisions, combining property loss prevention with insurance protection. This US-based remote opportunity may require periodic travel to our corporate headquarters in Johnston, RI, which is part of the greater Providence area. With a large college-age population, Providence offers a vibrant arts and entertainment scene that includes local theatre and music, collegiate and minor league sporting events, and excellent restaurants, and we’re not that far from the breathtaking RI beaches!

Security Engineer5 days ago
Full TimeRemote

The Cyber Specialist Co-Op will join the Cyber Threat Operations and Engineering Team, assisting senior members with the day-to-day operations and monitoring of security infrastructure technologies used for prevention, detection, and response to security incidents. This includes supervising alerts, managing ticket queues, responding to service desk incidents, and processing change requests.

Windows ServerNetworkingFirewallVulnerability ManagementPowerShellIncident ResponseIntrusion DetectionAntivirus
United States
$24 - $33 / hour
FM logo

Cyber Co-Op

FM

Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk management and the resilience of its policyholder-owners. These owners, who share the belief that the majority of property loss is preventable, represent many of the world’s largest organizations, including one of every four Fortune 500 companies. They work with FM to better understand the hazards that can impact their business continuity to make cost-effective risk management decisions, combining property loss prevention with insurance protection. This US-based remote opportunity may require periodic travel to our corporate headquarters in Johnston, RI, which is part of the greater Providence area. With a large college-age population, Providence offers a vibrant arts and entertainment scene that includes local theatre and music, collegiate and minor league sporting events, and excellent restaurants, and we’re not that far from the breathtaking RI beaches!

Security Engineer5 days ago
Full TimeRemote

The Cyber Co-Op will join the Cyber Threat Services Teams, which are responsible for detecting cyber security threats impacting Company Global and responding to those events. This role offers exposure to the latest enterprise security tools in a multifaceted environment.

United States
$24 - $33 / hour
Full TimeRemote

Senior Cybersecurity and Privacy Program Manager leading complex cybersecurity teams at Criterion.

AzureCloudCyber SecurityJavaPMPPythonSDLCSplunkSQLVBA
Washington
$180K - $190K / year
Security Engineer5 days ago
Full TimeRemoteTeam 51-200

The engineer will architect, configure, implement, and maintain Palo Alto Next Generation Firewalls (NGFWs), focusing on complex environments for a Federal client. Key duties include managing SSL decryption and inspection for all web traffic, integrating Wildfire analysis, and tuning configurations to enhance threat detection capabilities.

Palo Alto NGFWFirewall configurationSSL decryptionWildfireSMTP traffic inspectionThreat detectionSIEM integrationNetwork securityUser-ID loggingChange management
United States