> Markdown version of [/jobs/ext/2646291-security-engineer-cloud-and-product-security](https://www.wearedevelopers.com/jobs/ext/2646291-security-engineer-cloud-and-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Cloud and Product Security - **Company:** LOB Corporation - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $197,500.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Computing, Cloud Computing Security, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Zero Trust Network Access, Security Information and Event Management, Software Security, Kubernetes, Cloudflare, Terraform, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 6, 2026 - **Apply:** https://www.dice.com/job-detail/6a267eeb-22c1-4aa2-9043-a45c5d9126db ## About the Role * 8 or more years in security engineering, with meaningful depth in cloud security * Hands on expertise with AWS security services, IAM design, and infrastructure as code * Demonstrated detection engineering experience: you have written detections, tuned them, and cut false positive rates * Real incident response experience as a responder or lead, not just as a plan author * Fluency in application security sufficient to review findings, judge severity, and argue exploitability with engineers * Track record of shipping security improvements through other teams by earning trust rather than filing tickets * Comfort as the senior technical security voice in an organization without a large security team Nice to have * Experience supporting SOC 2 Type 2, HIPAA, or Microsoft SSPA from the engineering side * Container and orchestration security, particularly Nomad or Kubernetes * Cloudflare, including Zero Trust and WAF * Experience in a company handling regulated or consumer-identifiable data at scale * Prior experience mentoring or managing engineers or contractors ## Description This is the senior technical security role at Lob and the first hire in a newly split security function. You will own the engineering side of security: cloud infrastructure, detection and response, application security, and incident response. A dedicated GRC counterpart owns audit, compliance, and customer trust, so you are not the questionnaire desk. You will partner with them, not absorb them. You will report directly to the CTO, manage our application security contractor, and work day to day with our Platform, Logistics, and IT teams. This is a builder role with real autonomy and a mandate to raise the security floor of a system that processes hundreds of requests per second and moves millions of physical mailpieces. What you will own Cloud infrastructure security * Security posture of our AWS environment, including our CNAPP program and cloud misconfiguration risk * Security review of infrastructure changes across Terraform, Nomad, and our Cloudflare edge * WAF strategy and tuning at the domain level * Working with Platform engineers so security is designed in rather than reviewed at the end Detection and response * Build and own our detection engineering practice on our SIEM, moving us from noisy alert channels to curated, high signal detections * Define alert triage ownership, runbooks, and severity criteria * Own security incident response: escalation paths, tabletop exercises, post incident reviews * Partner with IT on endpoint detection and endpoint vulnerability coverage Application and product security * Own the vulnerability management program across SCA, SAST, DAST, and container scanning * Manage and mentor our application security contractor, and route remediation work into engineering teams effectively * Threat modeling and security architecture review for new products and major changes * Improve secure SDLC practice in a high velocity, AI-assisted engineering org Penetration testing and assurance * Technical ownership of our annual independent penetration test: scoping, findings triage, remediation routing, retest coordination * Produce the technical evidence our GRC counterpart needs for SOC 2, HIPAA, and Microsoft SSPA, without owning the audit itself, * You will not be the primary owner of security questionnaires, RFPs, or Trust Center requests * You will not own the auditor relationship or the compliance calendar * You will not be the sole owner of vendor security reviews or policy authoring Those live with our GRC lead. You will contribute technical input and evidence. You will not run the program. First 90 days * 30 days: own alert triage and incident escalation, know our AWS and edge posture, take over the penetration test findings workflow * 60 days: a working detection engineering backlog, endpoint and cloud vulnerability coverage verified end to end, application security contractor's work routed cleanly into engineering teams * 90 days: a prioritized security engineering roadmap you own and defend, with the top three infrastructure risks either closed or explicitly accepted ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Fireside Chat with Cloudflare's Chief Strategy Officer, Stephanie Cohen (with Mike Butcher MBE)](https://www.wearedevelopers.com/videos/1366-fireside-chat-with-cloudflare-s-chief-strategy-officer-stephanie-cohen-with-mike-butcher-mbe) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)