> Markdown version of [/jobs/ext/542163-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/542163-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Shelfflip, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $80,000.0 - $100,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Amazon S3, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Data Governance, Github, Identity and Access Management, Intrusion Detection and Prevention, Secure Coding, Security Information and Event Management, Software Vulnerability Management, Data Logging, Large Language Models, Software Security, Kubernetes, Terraform, Docker, Security Orchestration, Automation & Response - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fc9835c6151bce1e ## About the Role Do you have experience in SOC 2?, * Solid grasp of attacker techniques and modern application security (web/API, cloud, supply chain). * Hands-on secure code review experience, including AI/LLM systems. * Comfort tuning detection (GuardDuty / SIEM) and running incident response., * ISO 27001 Lead Implementer or Lead Auditor experience. * ISO 42001 / AI governance familiarity. * Hands-on Kubernetes / container security. * Light coding ability (Java preferred) - our security automation lives in code, and you'll extend it. * Experience with auditing LLM security ## Description You will be UserGems' single dedicated security person, taking over the operational majority of the security work the Sr. Director currently owns. This is a compliance-led role with hands-on operational components - heavy on SOC 2 / ISO ownership, customer security reviews, day-to-day program operations, and Drata-driven remediation in AWS. Compliance is the primary focus and over time you'll own the full technical scope described below as well. The Sr. Director approves direction; you propose, shape, and execute the program. Cadence is a bi-weekly 1:1 with the Sr. Director plus a weekly work discussion, same as every UserGems employee., * Lean strongly into compliance/GRC operations - with enough hands-on AWS comfort to action Drata-flagged remediations independently. * Want to own operations end-to-end and influence direction - you propose, the Sr. Director approves, you ship. * Like a startup environment where priorities are clear, ownership is real, and you ship and move on. What You'll Do * Own SOC 2 - keep Drata green and audits clean. * Lead ISO 27001 implementation, then ISO 42001. * Run the customer security questionnaire process (SafeBase + Trust Center) - fast turnaround directly unblocks revenue. * Drata-driven AWS remediation. Action simple Drata findings directly in AWS yourself - IAM tweaks, S3 settings, secrets hygiene, audit-trail follow-ups. Larger or higher-risk changes go to engineering. * Vulnerability management. Oversee and extend the existing scanner-findings automation in Linear; hit SLAs. * Light secure code review. Spot-check high-risk features and new repositories (especially AI/LLM systems) before they go to production; escalate deeper AppSec questions to engineering and external pen testers. * Threat detection & response. Tune GuardDuty findings, evaluate central logging / SIEM options, run tabletop exercises, mature the IRP from written to rehearsed. * Offensive security. Run the annual external pen test, perform regular internal pen tests yourself, handle external researcher reports and bug bounty payouts. * Onboarding & offboarding. Own access provisioning and revocation. * Be the security person at UserGems. Internally and externally, you are the face of security - questions, escalations, customer security reviews, and audit conversations come to you., * Model & data governance for Gem-E and our self-hosted LLMs on Azure: data residency posture, prompt-injection threat modeling, access controls on training/inference data. * Internal AI tooling built by non-engineering teams. Sales, marketing, and ops are building their own AI-powered internal tools. You'll shape how this scales safely - guardrails, access boundaries, monitoring, and review. * AI in our own security stack - extending our in-house Linear/scanner automations, AI-assisted questionnaire workflows, and security review of AI-generated code. * Customer-facing AI security narrative - shaping the answers, Trust Center statements, and policies that prospects' security teams will scrutinize., * Cloud: AWS (primary), some Azure (self-hosted LLMs) * Compliance / GRC: Drata, SafeBase (Trust Center), Linear * Detection / Endpoint: AWS GuardDuty, CrowdStrike Complete (managed MDR) * Scanners feeding Linear: GitHub, AWS Inspector, ZAP * Infra (owned by engineering): Terraform, Kubernetes, Docker, GitHub, * Working AWS knowledge - you can navigate the AWS console, action Drata-flagged remediations yourself (IAM, S3, KMS, audit trails), and read CloudTrail when investigating an alert. You do not need to be a cloud-infrastructure engineer. * Can understand Terraform with AI help - fluency isn't required. What matters is that you can drive AI to explain a diff, follow it critically, and catch when AI is wrong about IaC. Engineering owns infrastructure authorship. * High ownership and accountability - you ship audits, questionnaires, and policy work without a project manager keeping you on track. * Excellent written English - questionnaires, Trust Center, and policies are customer-facing. * Comfortable with async collaboration across Europe and the U.S. Most US work is async, but some late-afternoon CET availability helps - around once a week, same-day US input turns a multi-day back-and-forth into a 10-minute conversation., * Real operational ownership. You run the program day-to-day; the Sr. Director is your strategic partner and approves direction. * Mature foundation, not firefighting. You inherit a working program, not a smoking ruin. * Headroom to grow the program - real greenfield work, not maintenance theater. * Shape how a 70-person AI company runs AI safely - internally and in the product. Unusual scope; real impact. * Proven product with real traction. Customers love us, and reviews back it up (G2 Reviews). * High trust culture. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [WeAreDevelopers LIVE - CSS is DOOMed](https://www.wearedevelopers.com/videos/1838-wearedevelopers-live-css-is-doomed) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)