Security Site Reliability Engineer

Vantage Aging
Pleasant Grove, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Part-time / full-time
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
$ 67K

Job location

Pleasant Grove, United States of America

Tech stack

Kubernetes Security
API
Amazon Web Services (AWS)
Audit Trail
Bash
Cloud Computing
Cloud Computing Security
Computer Networks
DevOps
Identity and Access Management
Intrusion Detection and Prevention
Python
Linux System Administration
Role-Based Access Control
Reliability Engineering
Security Information and Event Management
Tripwire
TypeScript
Datadog
Policy as Code
Data Logging
Scripting (Bash/Python/Go/Ruby)
Grafana
Software Security
Amazon Web Services (AWS)
Backend
Terraform
Go

Job description

You'll OwnOwn cloud infrastructure security across AWS and GCP - IAM policies, network segmentation, encryption at rest/in transit, and CIS benchmark complianceHarden our IaC (Terraform) patterns - create secure modules, enforce policy-as-code (OPA/Sentinel/Checkov), and prevent misconfigurations before they reach productionEstablish security oversight of patching - engineering owns patching execution; you verify coverage, flag gaps, and ensure critical vulnerabilities are remediated on scheduleImplement and manage cloud-native security tooling - GuardDuty, Security Hub, Cloud Armor, Config Rules, and similar servicesSupport our Wazuh SIEM - maintain and extend cloud log ingestion (CloudTrail, VPC Flow Logs, GCP Audit Logs) and help tune detection rules after initial setup by a detection engineering contractorCollaborate with engineering teams to make secure infrastructure patterns the path of least resistance, not a gateSupport ISO 27001 compliance efforts by maintaining evidence of, defensible by default.What You'll OwnOwn cloud infrastructure security across AWS and GCP - IAM policies, network segmentation, encryption at rest/in transit, and CIS benchmark complianceHarden our IaC (Terraform) patterns - create secure modules, enforce policy-as-code (OPA/Sentinel/Checkov), and prevent misconfigurations before they reach productionEstablish security oversight of patching - engineering owns patching execution; you verify coverage, flag gaps, and ensure critical vulnerabilities are remediated on scheduleImplement and manage cloud-native security tooling - GuardDuty, Security Hub, Cloud Armor, Config Rules, and similar servicesSupport our Wazuh SIEM - maintain and extend cloud log ingestion (CloudTrail, VPC Flow Logs, GCP Audit Logs) and help tune detection rules after initial setup by a detection engineering contractorCollaborate with engineering teams to make secure infrastructure patterns the path of least resistance, not a gateSupport ISO 27001

Requirements

infrastructure security controls (Vanta deployment planned Q3 2026)Respond to security incidents involving infrastructure - contain, remediate, document, and improveQualificationsMust have:3+ years in SRE, DevOps, or Infrastructure Engineering with a security focus (or security engineering with strong infrastructure skills)Hands-on experience with AWS (IAM, VPC, EKS/ECS, Security Hub, GuardDuty, CloudTrail, Config)Working experience with GCP (doesn't need to be as deep as AWS)Strong Terraform skills - written modules, not just applied themExperience with Kubernetes security - RBAC, network policies, pod security standards, image scanningSolid understanding of Linux systems administration and OS-level hardeningComfortable scripting in Go, TypeScript, Python, or Bash for automation and toolingExperience with centralized logging - bonus if you've worked with Wazuh, but ELK/Datadog/Grafana experience translatesNice to haveExperience with Wazuh (our SIEM platform)Familiarity with policy-as-code frameworks (OPA, Sentinel, Checkov)Experience with container security scanning (Trivy, Snyk Container, Aqua, etc.)Background in incident response from an infrastructure perspectiveExperience securing IoT backend infrastructure or high-volume device API trafficExperience with ISO 27001 or similar compliance frameworksRelevant certifications (AWS Security Specialty, CKS, etc.)Who you areYou default to automation over manual processesYou think in terms of blast radius and defense in depthYou can explain infrastructure security concepts to application developers without condescensionYou're comfortable being the first person in a role and building the playbookYou stay current on cloud security threats and vulnerability disclosuresYou're excited to grow - this role has a clear path to senior as the security program maturesPura provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type ... without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.All candidates are subject to a background check.#J-18808-Ljbffr, compliance efforts by maintaining evidence of infrastructure security controls (Vanta deployment planned Q3 2026)Respond to security incidents involving infrastructure - contain, remediate, document, and improveQualificationsMust have:3+ years in SRE, DevOps, or Infrastructure Engineering with a security focus (or security engineering with strong infrastructure skills)Hands-on experience with AWS (IAM, VPC, EKS/ECS, Security Hub, GuardDuty, CloudTrail, Config)Working experience with GCP (doesn't need to be as deep as AWS)Strong Terraform skills - written modules, not just applied themExperience with Kubernetes security - RBAC, network policies, pod security standards, image scanningSolid understanding of Linux systems administration and OS-level hardeningComfortable scripting in Go, TypeScript, Python, or Bash for automation and toolingExperience with centralized logging - bonus if you've worked with Wazuh, but ELK/Datadog/Grafana experience translatesNice to haveExperience with Wazuh (our SIEM platform)Familiarity with policy-as-code frameworks (OPA, Sentinel, Checkov)Experience with container security scanning (Trivy, Snyk Container, Aqua, etc.)Background in incident response from an infrastructure perspectiveExperience securing IoT backend infrastructure or high-volume device API trafficExperience with ISO 27001 or similar compliance frameworksRelevant certifications (AWS Security Specialty, CKS, etc.)Who you areYou default to automation over manual processesYou think in terms of blast radius and defense in depthYou can explain infrastructure security concepts to application developers without condescensionYou're comfortable being the first person in a role and building the playbookYou stay current on cloud security threats and vulnerability disclosuresYou're excited to grow - this role has a clear path to senior as the security program maturesPura provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type ... without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.All candidates are subject to a background check.#J-18808-Ljbffr

About the company

Security Site Reliability EngineerYou'll be the first dedicated Security SRE at Pura, reporting to the CISO. This is a high-impact, high-autonomy role where you'll own the security posture of our AWS and GCP environments. You'll work alongside our AppSec engineer and Security Director to protect the infrastructure that powers millions of connected devices, our API backends, and our growing suite of internal tools.This isn't a "monitor dashboards and elevate" role. You'll be hands-on - hardening infrastructure, enforcing secure patterns in Terraform, establishing security oversight of patching processes, and responding to the accelerating pace of vulnerability disclosures driven by AI-powered security research.Our infrastructure is in good shape - 75%+ is managed via Terraform, secrets are centrally managed, and we have a solid engineering team handling reliability. What we need is someone who brings a security lens to all of it and makes our infrastructure defensible by default.What, Security Site Reliability EngineerYou'll be the first dedicated Security SRE at Pura, reporting to the CISO. This is a high-impact, high-autonomy role where you'll own the security posture of our AWS and GCP environments. You'll work alongside our AppSec engineer and Security Director to protect the infrastructure that powers millions of connected devices, our API backends, and our growing suite of internal tools.This isn't a "monitor dashboards and elevate" role. You'll be hands-on - hardening infrastructure, enforcing secure patterns in Terraform, establishing security oversight of patching processes, and responding to the accelerating pace of vulnerability disclosures driven by AI-powered security research.Our infrastructure is in good shape - 75%+ is managed via Terraform, secrets are centrally managed, and we have a solid engineering team handling reliability. What we need is someone who brings a security lens to all of it and makes our infrastructure

Apply for this position