> Markdown version of [/jobs/ext/3086641-security-engineer-ii-remote](https://www.wearedevelopers.com/jobs/ext/3086641-security-engineer-ii-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer II (Remote) - **Company:** Dream Hospitality Inc - **Location:** Phoenix, AZ, United States (Remote available) - **Experience:** Expert - **Salary:** $125,000.0 - $145,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Application Firewall, Software System Penetration Testing, Build Automation, Microsoft Azure, Bash Shell, Ubuntu (Operating System), Continuous Integration, Debian Linux, Linux, File Systems, Perl (Programming Language), Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Log Analysis, Open Source Technology, OpenStack, PCI Data Security Standards, Ansible, Reverse Engineering, Security Information and Event Management, Software Vulnerability Management, Web Hosting Services, WordPress, Google Cloud, Cloud Platform System, Large Language Models, Multi-Agent Systems, Software Security, Malware, Git, Kubernetes, Software Version Control, Docker, Vulnerability Analysis, Golang - **Published:** September 26, 2026 - **Apply:** https://www.careerjet.com/jobad/us78c32db335be446b772e90fb8ed8e8c4 ## About the Role 3-6 years in security engineering, incident response, application security, offensive security, or systems administration, with demonstrated ability to resolve complex security problems independently. Depth in at least one of: application security, incident response and detection engineering, or offensive security and penetration testing plus working competence in the other two. Strong hands-on Linux (Debian/Ubuntu preferred), including low-level concepts: processes, namespaces, capabilities, filesystems, kernels, and how things actually break. Experience operating long-lived production systems that can't simply be rebuilt including repairing hosts in place, under load, with real users on them. Experience in multi-tenant or customer-facing environments where users are untrusted. Scripting and automation you've shipped and operated in production. Python, Go, Bash, Perl, or similar. We care that you've built and maintained real tooling, not which language. Log analysis and investigation at scale, and comfort with intrusion detection and web application firewalls (mod_security or similar). Working knowledge of cloud platform security (AWS, GCP, Azure, or OpenStack) including IAM, network controls, and workload isolation. Familiarity with secrets management and CI/CD security (Vault or equivalent, pipeline hardening, dependency and supply-chain risk). Version control and infrastructure-as-code fluency (Git, Ansible or similar). Practical, current fluency with AI tooling in your own work. You use it daily, you know where it fails, and you can say what you don't let it do. We are not looking for enthusiasm or for resistance, but for someone who has integrated these tools into real engineering work and formed opinions from experience. Clear written and verbal communication, including translating technical risk for non-technical stakeholders. A strong sense of ethics, healthy skepticism, and the patience to stay useful under pressure. Nice to have Web hosting or WordPress-at-scale experience, as a provider or a customer. Container and orchestration security (Podman, Docker, Kubernetes) including escape and isolation failure modes. Malware analysis, YARA rule authorship, or reverse engineering. Detection-as-code or SIEM engineering experience. Hands-on experience securing AI/LLM systems, agent frameworks, or MCP tooling. Prompt injection, tool-permission scoping, or data-boundary work. Familiarity with PCI DSS, SOC 2, or ISO 27001 - as context, not as a career. ## Description You will work on a small security team where everyone owns real workstreams end to end, partners directly with Systems, Development, Abuse, and Support, and is expected to exercise judgment without waiting for permission. What you'll work on Incident response across shared, virtualized, and dedicated Linux hosts - compromise investigation, blast-radius scoping, containment, evidence preservation, and write-ups. Detection engineering: malware and webshell signatures, log-based detections, and reducing the false positives that create alert fatigue at fleet scale. Application security review of our in-house control plane, customer panel, and internal tooling, plus the third-party and open-source code we depend on. Secrets management modernization such as moving static credentials into Vault, adopting dynamic credentials, and eliminating plaintext secrets from code, logs, and CI. Identity and access lifecycle: directory and SSO migration, privileged access review, and durable offboarding. Vulnerability management and patch velocity across a large, heterogeneous fleet, including end-of-life OS and runtime remediation. Automation. Anything done manually more than twice is a candidate for tooling, and you'll build it. Security review and governance of AI and agent tooling as it's adopted internally - data exposure, permission scope, agent identity, and abuse paths. You'll also be using these tools heavily yourself; the team runs on them. Responsibilities Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the role. Lead investigation and resolution of complex security incidents, coordinating across teams and communicating status clearly while facts are still incomplete. Design and implement safeguards protecting customer sites, accounts, and infrastructure from active and evolving threats. Conduct vulnerability assessments, security reviews, and risk analysis, with remediation guidance engineers can act on. Build automation and tooling that improves detection, monitoring, response, and operational safety. Partner with Systems, Development, Abuse, and Support to get security controls implemented rather than merely recommended. Mentor less experienced team members and contribute to the team's shared knowledge and runbooks. Contribute to security policy, standards, and process, and support compliance efforts without mistaking compliance for security., Description : ESSENTIAL FUNCTIONS SOC Engineering - Engineer and enhance Security Operations Center (SOC) capabilities, integrating security monitoring tools, SIEM solutions, … + 6 days ago, Kforce has a client in Phoenix, AZ that is seeking a Senior Azure Infrastructure & Security Engineer. Summary: Work covers architecture, implementation, and tracking the assigned t… + 7 days ago + ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)