> Markdown version of [/jobs/ext/138674-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/138674-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Kaizen Laboratories Inc. - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $180,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Application Layers, Software as a Service, Continuous Integration, Cloud Platform System, Delivery Pipeline, Terraform - **Published:** May 27, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=dec2c4ee9456b7a5 ## About the Role Do you have experience in Terraform?, * 5+ years of hands-on experience building and securing cloud-native platforms in AWS and Terraform - you can architect controls and also implement them yourself * Direct experience with federal authorization work - FedRAMP, CMMC, DoD IL, or comparable regulated environments. You don't need to have shepherded a full authorization across the finish line, but you've done enough of the real work to know what it takes * Deep familiarity with NIST 800-53 and the ability to translate controls into pragmatic engineering work rather than checkbox compliance * Strong working knowledge of modern supply chain security: SBOMs, image signing, workload identity, secure CI/CD * Track record operating effectively in early-stage or fast-moving environments where you set the bar rather than inherit it Strong Candidates May Also... * Have supported federal SaaS, defense tech, or regulated infrastructure companies through accreditation * Have led a company through its first federal authorization rather than maintaining an existing one * Have hands-on experience with Chainguard, AI-powered security tooling, or similar leverage-multiplying platforms * Have worked with platforms like Second Front or similar federal compliance accelerators ## Description Kaizen's platform reaches 40M residents across 50+ agencies in 17 states. We've already signed multiple federal customers with many more in the pipeline - and the work of making Kaizen federal-ready is currently spread across a handful of engineers. That doesn't scale. We're hiring our first dedicated security engineer to sit on the platform team and own this end to end: architect the controls, write the SSPs, and partner with engineering to embed compliance into how we ship rather than bolt it on after., * Architect and operationalize security across infrastructure, platform, CI/CD, and application layers, with a focus on AWS (including GovCloud) and Terraform * Lead readiness across federal compliance frameworks - FedRAMP, CMMC, and DoD Impact Levels - translating NIST 800-53 and related controls into real engineering implementations, and owning the SSPs, POA&Ms, and technical policy documentation * Build continuous compliance and audit-readiness workflows that make accreditation a byproduct of how we ship, not a separate workstream * Be smart about AI and tooling - use automated AI-driven security scanning, modern hardened-image platforms like Chainguard, and other leverage points to multiply the impact of a small security team * Establish secure software supply chain practices: SBOMs, image signing, workload identity, and hardened deployment pipelines * Own the technical relationship with assessors, auditors, and federal security stakeholders - you are the credible technical voice in those rooms * Drive a secure-by-default engineering culture so residents and public servants can trust the systems we put in front of them, * You want to own policy and hand the implementation to someone else - this role lives in the code and the infrastructure * You think compliance is paperwork - at Kaizen it's a load-bearing engineering discipline * You think AI tools are a crutch rather than a force multiplier * You need a mature security program already in place to be effective Kaizen exists to strengthen trust in American public services. Security and compliance aren't constraints on that mission - they're the foundation that makes the work matter at the federal scale. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Building Trustworthy AI in Industry: Beyond Traditional Cybersecurity](https://www.wearedevelopers.com/videos/1948-building-trustworthy-ai-in-industry-beyond-traditional-cybersecurity) - [How will artificial intelligence change the future of software testing?](https://www.wearedevelopers.com/videos/85-how-will-artificial-intelligence-change-the-future-of-software-testing) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)