GoodLeap
🔆 GoodLeap is America's leading fintech for sustainable home solutions.
Senior Security Engineer, Security Operations
Security OperationsSecurity OperationsFull TimeRemoteTeam 501-1,000Since 2020H1B SponsorCompany SiteLinkedIn
Location
California + 2 moreAll locations: California, Florida, Utah
Posted
49 days ago
Salary
$146K - $170K / year
Bachelor DegreeEnglishAWSAzureCloudERPGoogle Cloud PlatformGraph QLTerraformVault
Job Description
• The GoodLeap security team is responsible for both business enablement and safeguarding the organization’s information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of GoodLeap’s customers, partners, and employees information.
• The senior security engineer role provides a unique opportunity to shape the security and resilience of GoodLeap systems, services, and operational processes.
• In this role, you will work closely with product, engineering, IT, and business teams within GoodLeap to design, build, implement, and operate security and fraud monitoring, detection, and response capabilities.
Job Requirements
- Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences.
- Expertise in security event management, monitoring, threat hunting, incident response, playbook creation, orchestration/automations, etc.
- Experience with threat modeling methodologies.
- Expertise with EDR solutions/platforms, such as CrowdStrike, S1, Palo Alto Cortex EDR, etc.
- Experience with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus).
- Proven ability to establish credibility and build trust with business, engineers, and operational staff; confident yet humble.
- Experience designing, configuring, and implementing security and fraud monitoring for core enterprise systems, e.g., ERP, HCM, Salesforce, etc.
- Experience working with and creating solutions based AI and ML toolsets – e.g., creation of AI skills, agents, MCP clients, vibe coding.
- Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases.
- Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault.
- Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed.
- Prior experience interfacing and supporting teams outside of security – e.g., internal product teams and other cross-functional areas.
- Proficiency in writing automation scripts in multiple languages and integrating with REST/GraphQL APIs to orchestrate workflows between security tooling and third-party cloud/SaaS platforms, automating detection, response, and operational processes.
- Experience engaging with vendors in design partnerships.
- Experience overseeing vulnerability and threat management at the platform and application levels.
- Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement.
- Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution.
Benefits
- In addition to the above salary, this role may be eligible for a bonus and equity.
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Security Operations60 days ago
Full TimeRemoteTeam ,H1B No Sponsor
SOC Engineer II focusing on security operations and incident response for IEM.
AzureCloudCyber SecurityDNSFirewallsSMTPTCP/IP
California
Cybersecurity Operations, Incident Response Manager
Coastal Community BankCOMMUNITY. It's not just our middle name. It's how we do business.
Security Operations60 days ago
Full TimeRemoteTeam 201-500Since 1997H1B No Sponsor
Cybersecurity Operations & Incident Response Manager leading 24/7 security operations
Security Operations62 days ago
Full TimeRemoteTeam 10,001+Since 1910H1B No Sponsor
Associate Analyst Technology role managing EDI B2B communications for Medline
Security Operations63 days ago
Full TimeRemoteTeam 1,001-5,000Since 2002H1B Sponsor
Security Operations Associate managing operational security services for Everbridge
CloudSFDC