> Markdown version of [/jobs/ext/3017220-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/3017220-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** THECOLLEGECOACH L L C - **Location:** Reston, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $153,000.0 - $166,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Amazon S3, Build Automation, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Linux System Administration, Network Segmentation, PCI Data Security Standards, Role-Based Access Control, Software Vulnerability Management, Data Logging, Cloud Platform System, Delivery Pipeline, Software Security, Cloudformation, Api Design, Terraform, Cyber Warfare, Serverless Computing, Security Orchestration, Automation & Response, Microservices - **Published:** September 20, 2026 - **Apply:** https://www.jofdav.com/jobs/59801376-senior-security-engineer ## About the Role * 5+ years of experience in security engineering, cloud security, or security architecture, with demonstrated ownership of initiatives that scale across multiple teams and environments. * Designed and secured cloud-native architectures, including multi-account AWS environments, microservices, serverless workloads, and API-driven systems. * Have deep experience with AWS security fundamentals, including IAM strategy (least privilege, cross-account access, federation), KMS, Secrets Manager, S3, logging/monitoring, and preventive guardrails using Organizations and SCPs. * Implemented security controls using Infrastructure as Code (Terraform, CloudFormation, CDK) and support policy-as-code approaches to enforce standards at scale. * Understand secure system design across multi-tier architectures and can perform threat modeling to identify systemic risks before they reach production. * Experienced in securing Linux-based systems and cloud infrastructure, with practical expertise in hardening, logging, identity design, and network segmentation., * Relevant certifications (e.g., AWS Security Specialty, CISSP, CCSP) are a plus, but hands-on engineering experience and demonstrable impact matter most. * Ability to travel 3-5 times per year to College Board offices. * Authorization to work in the United States. All roles at College Board require: * A passion for expanding educational and career opportunities and mission-driven work * Authorization to work in the United States for any employer * Curiosity and enthusiasm for emerging technologies, with a willingness to experiment with and adopt new AI-driven solutions and a comfort learning and applying new digital tools independently and proactively. * Clear and concise communication skills, written and verbal * A learner's mindset and a commitment to growth: welcoming diverse perspectives, giving and receiving timely, respectful feedback, and continuously improving through iterative learning and user input. * A drive for impact and excellence: solving complex problems, making data-informed decisions, prioritizing what matters most, and continuously improving through learning, user input, and external benchmarking. * A collaborative and empathetic approach: working across differences, fostering trust, and contributing to a culture of shared success. ## Description The College Board's Cloud Security and Platform Engineering (CSPE) team designs, builds, and secures the cloud foundation that powers our most critical applications and services. We partner closely with product engineering, platform, risk, compliance, and application teams to design, automate, and operationalize scalable security controls, building reusable tooling and guardrails that make secure application deployments the default across AWS environments. Rather than operating as a reactive review function, we implement preventive and detective controls that reduce systemic risk while enabling teams to move quickly. Our work spans multi-account cloud architecture, identity and access management, network segmentation, automation, detection engineering, and compliance alignment. We focus on scalable, repeatable solutions that strengthen security posture across the enterprise., As a Senior Security Engineer, you will play a critical role in strengthening the cloud security foundation that supports College Board's enterprise platforms and services. This position focuses on building and scaling automated, preventive security controls that reduce systemic risk while enabling engineering teams to deliver quickly and confidently. You will work across cloud environments to expand automated guardrails, improve external exposure management, and reduce high-risk misconfigurations through enforceable, enterprise-wide controls. This role emphasizes secure-by-default architecture, infrastructure automation, and measurable risk reduction, ensuring security controls are consistently applied as the organization scales. In partnership with Cloud Engineering, Product Security, and Cyber Operations, you will enhance vulnerability management workflows, increase automation across intake and response processes, and strengthen detection and triage capabilities. You will help drive improved remediation velocity, clearer security posture visibility, and more efficient security operations through engineering-led solutions. You will also contribute to the resilience and reliability of critical security platforms, ensuring continuity of monitoring and posture management capabilities while supporting modernization efforts. Success in this role means delivering durable, scalable security outcomes: stronger preventive coverage, reduced exposure windows, improved operational efficiency, and measurable improvements in enterprise security posture. In this role, you will: Strengthen Cloud Guardrails and Preventive Controls (40%) * Design, implement, and operationalize automated preventive and detective guardrails across enterprise cloud environments. * Build and enforce enterprise-wide controls that prevent or automatically remediate high-risk misconfigurations. * Improve protection coverage for internet-facing systems by validating asset inventories and expanding enforcement mechanisms. * Continuously evaluate control effectiveness through telemetry, compliance validation, and risk trend analysis. * Partner with cloud platform teams to embed secure-by-default infrastructure patterns into reusable modules and deployment workflows. Advance Vulnerability Management and Security Automation (35%) * Enhance vulnerability management processes to improve prioritization, remediation velocity, and cross-team accountability. * Increase automation across vulnerability intake, enrichment, ticketing, and response workflows to reduce manual triage burden. * Design and deliver engineering solutions that improve detection quality and response speed in collaboration with Cyber Operations. * Translate security requirements into scalable technical implementations using infrastructure-as-code and automation frameworks. * Measure and report on workflow efficiency and risk reduction outcomes using operational metrics. Improve Security Posture Visibility and Platform Resilience (25%) * Implement standardized, automated security checks across prioritized security domains to strengthen baseline posture. * Enable measurable security maturity tracking through telemetry-backed reporting and posture metrics. * Support continuity of cloud security monitoring and posture management during tooling transitions or modernization efforts. * Strengthen reliability, scalability, and resilience of critical security platforms to reduce operational risk. * Contribute to documentation, engineering standards, and continuous improvement practices that promote long-term maintainability., * Translate regulatory and compliance requirements (e.g., FERPA, PCI DSS, SOC 2, NIST) into practical technical controls and automated evidence collection. * Build automation to reduce manual security work, leveraging scripting and cloud APIs to create repeatable, measurable security improvements. * Comfortable operating in fast-moving environments where standards and tooling evolve, and you proactively define guardrails rather than waiting for direction. * Influence engineering and product stakeholders by balancing delivery velocity with risk reduction, presenting trade-offs clearly and driving alignment on secure design decisions. * Communicate complex security concepts in practical terms, mentor engineers, and contribute to hiring and technical evaluation processes. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [API Design - Getting Started](https://www.wearedevelopers.com/videos/33-api-design-getting-started) - [WeAreDevelopers LIVE - CSS is DOOMed](https://www.wearedevelopers.com/videos/1838-wearedevelopers-live-css-is-doomed) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)