Senior Security Engineer

Near East Foundation
United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Systems Engineering Bash Shell Software as a Service Cloud Computing Cyber Security Multi-Factor Authentication Identity and Access Management Information Technology Operations Python (Programming Language) Security Information and Event Management
+5 more
Software Vulnerability Management Data Logging Scripting Okta Gsuite

Job description

We are hiring a Senior IT Security Engineer to be the deep technical owner of our information security work. This is a senior individual contributor role for someone who has spent years operating at the engineering edge of IT and security and is now looking for broad scope and meaningful ownership., You will bring the technical depth to design, harden, and automate the security systems and controls our team and ecosystem rely on, and you will lead our information security program end-to-end. You will work alongside our IT Director, who owns the broader IT function, and partner with our IT Operations team, who handle day-to-day support and provisioning - letting you focus squarely on security engineering and program leadership. Near-term priorities include leading SOC II Type 2 and ISO 27001 readiness at NEAR AI, supporting the needs of the NEAR Security Committee (NSC), and partnering with the incoming NEAR Intents Head of Security on shared standards., * Drive SOC II Type 2 and ISO 27001 readiness and ongoing compliance at NEAR AI: control design, evidence collection, auditor liaison, and remediation.

  • Support the needs and operation of the NEAR Security Committee (NSC).
  • Run logging, monitoring, and alerting; lead investigation and response for security incidents.
  • Run vulnerability management, third-party risk reviews, and security awareness across the organization.

Security Engineering

  • Own the security architecture and hardening of our identity, access, and endpoint stack (SSO/MFA, MDM, EDR, conditional access, privileged access) - partnering with the IT Director and IT Operations team on day-to-day operations.
  • Engineer security and compliance automation across our SaaS estate - evidence collection, control monitoring, access reviews, and workflows that tighten controls and reduce manual work.
  • Be the senior technical escalation point for complex security issues across the organization.
  • Lead security tooling rollouts and security vendor selection; provide deep security input into the broader IT roadmap and technical due diligence.

Cloud and Policy

  • Help maintain a secure cloud footprint (AWS / GCP) - baseline configuration, secrets management, and posture monitoring - in partnership with infrastructure and product teams.
  • Maintain the security policy library; ensure policies are accurate, enforced, and updated as we evolve.

Requirements

Do you have experience in SSO?, * 7+ years in information security with strong IT engineering depth, including meaningful time as a senior IC owning programs end-to-end.

  • Demonstrated ownership of SOC II Type 2 and ideally ISO 27001 readiness and audit cycles in a fast-moving environment.
  • Deep hands-on experience across IAM, endpoint, and at least one cloud (AWS or GCP).
  • Comfortable scripting (Python, Go, or Bash) and automating IT and security workflows.
  • Practical experience with SSO/IdP platforms (Okta, Google Workspace, Entra), MDM/EDR tooling, and modern logging/SIEM stacks.
  • Strong written communication - clear policy, clean post-incident reviews, credible audit narratives.
  • Pragmatic about risk and process; calm under pressure; bias to action.
  • Crypto or AI/ML exposure is a plus.

Benefits & conditions

A competitive compensation aligned with senior-level security engineering roles across leading AI and Web3 organizations, including a combination of salary and NEAR token incentives. Benefits include comprehensive healthcare coverage, a remote-first work environment, and a professional development and learning budget.

We value

  • ECOSYSTEM-FIRST: always put the health and success of the ecosystem above any individual’s interest
  • OPENNESS: operate transparently and consistently share knowledge to build open communities
  • PRAGMATISM OVER PERFECTION: find the right solution not the ideal solution and beat dogmatism by openly considering all ideas
  • MAKE IT FEEL SIMPLE: strive to make the complex feel simple so the technology is accessible to all
  • GROW CONSTANTLY: learn, improve and fail productively so the project and community are always becoming more effective

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all