> Markdown version of [/jobs/ext/2715039-security-engineer](https://www.wearedevelopers.com/jobs/ext/2715039-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** SHEIN --- - **Location:** United States - **Experience:** Expert - **Salary:** $130,000.0 - $169,000.0 - **Contract:** Permanent contract - **Skills:** Authentication Protocols, Build Automation, Cyber Security, Identity and Access Management, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Public Key Infrastructure, Security Assertion Markup Language (SAML), Cloud Platform System, Build Tools - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-security-engineer-shein-8122626 ## About the Role * 5+ years of security engineering experience, including meaningful handson work in PKI, cryptography infrastructure, or closely related security engineering domains. * Strong practical experience managing production PKI environments, including: CA hierarchy certificate lifecycle across devices and services certificate-based authentication troubleshooting trust, issuance, and renewal failures at scale. * Experience with NAC-related certificate authentication and technologies such as ClearPass, NDES, SCEP, or similar systems. * Experience contributing to security architecture reviews: evaluating security controls, advising on secure design decisions, and helping engineering teams build systems that are secure by default. * Familiarity with authentication protocols (SAML, OAuth 2.0, OIDC, LDAP) as they relate to certificate-based authentication and PKI integration. * Proficiency in Python, Go, or similar languages for automation, tooling, and workflow improvement. * Ability to make sound security design decisions and work directly with engineers to turn those decisions into practical implementations. * Strong communication skills and the ability to collaborate effectively across teams, functions, and time zones. Nice to Have * Experience contributing to security architecture documentation, design reviews, or security control frameworks. * Familiarity with relevant security and compliance frameworks such as SOC 2, ISO 27001, NIST, or privacy/security control implementation in regulated environments. * Certifications such as CISSP or CCSP. ## Description We're hiring a Senior Security Engineer to help build and mature the security foundations that support our global business. This is an engineering role for someone with deep, practical experience in PKI and cryptography infrastructure, plus hands-on experience in security architecture as a secondary domain. You'll work closely with engineering, infrastructure, and product teams to design and implement security controls that are effective, durable, and usable in production. We're looking for someone who can go beyond policy and theory: a hands-on engineer who can improve systems, automate processes, troubleshoot failures, and make strong design decisions in complex environments. We operate at meaningful scale: Customers in 150+ countries, footprint across three cloud providers, and engineering teams shipping continuously. We've already made significant investments in our security foundations, including a global certificate rollout, and are now focused on the next stage of maturity. In this role, your primary focus will be PKI and cryptography infrastructure: certificate lifecycle, CA operations, certificate-based authentication, and the tooling and standards needed to run these systems well at scale. You'll also contribute to security architecture work: conducting design reviews, evaluating security controls, and helping engineering teams make strong security decisions across cloud and enterprise environments. This is a strong fit for someone who wants to combine hands-on engineering, practical architecture judgment, and cross-functional influence in a role with real scope and ownership., * Own and mature PKI and cryptography infrastructure across enterprise and cloud environments. * Define and improve standards, guardrails, and reference patterns for certificate issuance, renewal, revocation, and trust management. * Support and enhance certificate-based authentication systems, including network/device-related use cases, and code-authentication. * Build automation and operational tooling to improve reliability, visibility, and lifecycle management. * Partner with engineering and infrastructure teams early in the design process to help implement secure, practical solutions. * Contribute to security architecture reviews and design decisions across cloud, infrastructure, and platform initiatives - helping engineering teams build secure systems from the ground up. * Contribute to security design reviews for initiatives related to PKI, cryptography, and adjacent security infrastructure. * Troubleshoot PKI and cryptography related production issues, perform root cause analysis, and help drive durable remediation. * Mentor other security engineers through design feedback, implementation guidance, and operational best practices. * Partner with audit and GRC teams to ensure cryptography- and identity related controls are implemented and evidenced in a sustainable way. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Modern Data Architectures need Software Engineering](https://www.wearedevelopers.com/videos/1030-modern-data-architectures-need-software-engineering) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Building a framework-independent component library](https://www.wearedevelopers.com/videos/1679-building-a-framework-independent-component-library) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Top Characteristics of a Software Engineer](https://www.wearedevelopers.com/magazine/166-top-characteristics-of-a-software-engineer)