Sr Lead Security Engineer - Workforce
Role details
Job location
Tech stack
Job description
- Independently design, build, and implement advanced security solutions across cloud, hybrid, and on-prem environments, ensuring alignment with the latest industry best practices and regulatory requirements.
- Actively write code, develop automation, and integrate security controls throughout the software development lifecycle, collaborating with engineering teams to embed security from ideation to deployment.
- Facilitate security requirements clarification for multiple networks to enable multi-level security that satisfies organizational needs.
- Drive adoption and direct implementation of emerging cybersecurity technologies (e.g., zero trust architectures, container security, AI/ML-driven security analytics) to enhance the organization's security posture.
- Be responsible for triaging based on risk assessments of various threats and managing resources to cover the impact of disruptive events.
- Utilize a deep understanding of the threat landscape and risk to build security into products and new features.
- Mentor and provide technical guidance to junior engineers through code reviews and knowledge sharing, while remaining an individual contributor.
- Collaborate cross-functionally with product, infrastructure, and business teams to ensure security requirements are understood, prioritized, and implemented effectively.
- Stay abreast of the latest cybersecurity trends, threat intelligence, and attack techniques, and translate insights into actionable improvements for the organization.
- Develop and maintain incident response playbooks, and lead post-incident reviews to drive continuous improvement from a technical perspective.
- Actively contribute to an inclusive team environment by mentoring and supporting diverse perspectives.
Requirements
- Obtain 5 plus years of applied training or certification on software engineering concepts
- Proven track record in hands-on design, development, and deployment of enterprise-grade security solutions in public cloud environments (AWS, GCP, Azure), with direct experience integrating security controls into cloud-native architectures.
- Demonstrated ability to perform comprehensive threat modeling and risk assessments for applications, systems, and architectures using frameworks such as STRIDE, DREAD, or PASTA.
- Advanced proficiency in at least one modern programming language (e.g., Python, C/C#, Go, Java) and scripting for automation and security tooling, with a focus on building and deploying solutions.
- Deep understanding of secure software development practices, including code review, static/dynamic analysis, and vulnerability remediation across multiple technology domains (cloud, AI/ML, mobile, etc.).
- Experience implementing and managing CI/CD pipelines (e.g., Jenkins, GitHub Actions) with integrated security testing and controls.
- Expertise in version control systems (e.g., Git, BitBucket) and agile work management tools (e.g., Jira), with a focus on collaborative, cross-functional engineering environments.
- Ability to independently solve complex design and functionality challenges, proactively identifying and mitigating security risks with minimal oversight.
- Experience working with vendors to assess the sufficiency of their security practices and controls to meet industry standards.
- Strong analytical and communication skills, with the ability to translate technical security requirements into actionable engineering tasks and clear documentation.
Preferred Qualifications, Capabilities, and Skills
- Experience with modern security engineering practices, such as infrastructure as code (IaC), DevSecOps, and automated security testing.
- Hands-on experience with cloud-native security tools (e.g., AWS Security Hub, Azure Sentinel, GCP Security Command Center) and container orchestration platforms (e.g., Kubernetes).
- Active participation in the cybersecurity community, such as contributing to open-source projects, attending or speaking at conferences, or publishing research.
- Experience implementing zero trust architectures, micro-segmentation, or advanced identity and access management solutions.
- Strong understanding of privacy and data protection regulations (e.g., GDPR, CCPA) and their impact on security engineering.
- Experience within Cyber Security is preferred with a good understanding of industry frameworks like MITRE ATT&CK, NIST, CIS, etc.
- Relevant advanced certifications (e.g., CISSP, CCSP, AWS Certified Security Specialty, GIAC, OSCP) are highly desirable.
- Excellent communication and presentation skills, with the ability to convey complex security concepts to technical and non-technical audiences.
- Experience with security automation and orchestration using tools like Terraform, Ansible, or custom scripting.
- Prior experience in highly regulated industries (finance, healthcare, etc.).
- Willingness to learn and drive to excel.
Benefits & conditions
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.