> Markdown version of [/jobs/ext/2708687-corporate-security-automation-engineer](https://www.wearedevelopers.com/jobs/ext/2708687-corporate-security-automation-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Corporate Security Automation Engineer - **Company:** Nilon Global LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Android Software Development, Apple IOS, Information Leak Prevention, Data Security, Python (Programming Language), Node.Js, Ansible, Zero Trust Network Access, Software Engineering, TypeScript, Software Vulnerability Management, Web Platforms, Cloud Platform System, Mitre Att&ck, Kubernetes, Infrastructure Automation Frameworks, Information Technology, React Native, CIS Benchmarks, Puppet, NestJS, Terraform, Microservices - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/corporate-security-automation-engineer-iac-one-8018385 ## About the Role * 5+ years of IT experience, including 3+ years in enterprise security within cloud environments. * Expertise in IaC tools like Terraform (preferred), Puppet, Chef or Ansible. * Proven ability to lead projects, drive measurable security improvements through automation, leveraging scripting (Python, Go, and/or TypeScript). * Solid understanding of networking, authentication standards, and security frameworks (MITRE ATT&CK, NIST CSF, CIS benchmarks), with hands-on experience in ZTNA and DLP solutions (e.g., Netskope, Zscaler). * Skilled at simplifying technical concepts for non-technical audiences and influencing decisions. * Experience with workflow automation tools like n8n is a plus., We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. While you don't need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly. ## Description As a Corporate Security Engineer at OnePay, you will lead the design, implementation, automation, and optimization of our corporate security infrastructure. You will enhance security controls, align goals with business objectives, and drive automation and self-service capabilities to maintain a strong security posture in a rapidly scaling environment. * Work with IaC tools like Terraform to ensure enterprise configurations are steady, change-managed and machine-readable. * Design and deploy endpoint security measures aligned with industry standards, including vulnerability management. * Ensure a strong security posture for corporate SaaS applications by configuring vendor capabilities or building automations to meet OnePay standards. * Mature and manage data protection controls, including Data Loss Prevention (DLP) tools and secure data handling processes. * Build secure methods for sharing data with internal teams and external partners. * Collaborate with IT, Infrastructure, and Security teams to implement security measures, maintain critical corporate systems (ensuring availability and compliance), and drive process improvement through automation. * Develop and run incident response and disaster recovery plans, including tabletop exercises. ## Related Videos - [Automate everything via NodeJS and Puppeteer](https://www.wearedevelopers.com/videos/322-automate-everything-via-nodejs-and-puppeteer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [The Memory Leak That Ate Our Cluster: A Postmortem](https://www.wearedevelopers.com/videos/2057-the-memory-leak-that-ate-our-cluster-a-postmortem) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)