> Markdown version of [/jobs/ext/563077-security-engineer](https://www.wearedevelopers.com/jobs/ext/563077-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Stedi, Inc. - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Audit Trail, Cyber Security, Customer Data Management, Information Leak Prevention, Amazon DynamoDB, Github, Identity and Access Management, Information Technology Operations, Amazon Simple Notification Service (SNS), Software Engineering, TypeScript, Software Security, Backend, Stripe, Opsworks, Functional Programming, Api Gateway, Amazon Simple Queue Service (SQS), Serverless Computing, Pagerduty - **Published:** June 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9bdda425ce0d399a ## About the Role Do you have experience in TypeScript?, * 4+ years of experience in engineering, working as a security engineer or in security-adjacent roles * Familiarity with compliance frameworks such as SOC, HIPAA, and/or HITRUST * 4+ years working with AWS services, including compliance and governance services like AWS Organizations, AWS CloudTrail, AWS Config, Security Hub, and GuardDuty. * Proficiency in TypeScript. * Ability to prioritize your work based on the needs of the business and the customers * High bandwidth; thoughtful attention to many areas simultaneously * Ability to context switch throughout the course of the day or week as priorities shift * Philosophical alignment with the Stedi Standards and the Unwritten laws of engineering. ## Description We are seeking an experienced Security Engineer to join our Platform Team. This team is at the core of our infrastructure, responsible for managing multiple AWS Organizations and providing the foundational tools and services that enable our engineering teams to build reliable, secure, and compliant applications. The Platform Team's responsibilities span a wide range of areas, including: * The AWS infrastructure that our engineering teams rely on. * Management of our GitHub organization and IT operations. * Supporting compliance efforts to ensure alignment with industry standards (SOC, HIPAA, HITRUST). As a Security Engineer, you will play an active role in how we set up our AWS infrastructure, software development lifecycle, and endpoint security. Your contributions will help ensure our engineering teams build applications in a way where it is easy to demonstrate alignment with regulatory and compliance requirements., * We use AWS exclusively for our backend infrastructure that processes customer data. We use tools like GitHub, Stripe, Vanta, and PagerDuty, but all of our application work happens on AWS. * We use serverless technologies almost exclusively: Lambda, API Gateway, SQS, SNS, DynamoDB, Aurora Serverless, and more. We don't run a single server on prem or in the cloud. * We use the CDK (TypeScript) to define infrastructure-as-code. * We have a strong preference for using AWS products over 3rd party solutions. This simplifies vendor management and compliance, and ensures we can benefit from AWS's integration capabilities and innovations now and in the future. What you'll do * Develop playbooks and address security-related tasks in our AWS serverless environments. * Drive improvements in our broader security posture, including application security, endpoint security, access management / just-in-time access, email and web gateways, browser security, and data loss prevention. * Collaborate with product engineering teams to raise the bar for security, supporting CI/CD pipelines, dependency management, and secure application design reviews. * Help secure and improve our AWS organization using infrastructure as code (CDK), enforcing security controls, and ensuring strong tenant isolation. * Continuously assess vulnerabilities and perform regular risk assessments. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Navigating Growth, Scaling Challenges, and Office Expansions with David Singleton, CTO at Stripe](https://www.wearedevelopers.com/videos/100362-navigating-growth-scaling-challenges-and-office-expansions-with-david-singleton-cto-at-stripe) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 119 - ❤️ === ❤️](https://www.wearedevelopers.com/magazine/454-dev-digest-119) - [Dev Digest 159: AI Pipelines, 10x Faster TypeScript, How to Interview](https://www.wearedevelopers.com/magazine/563-dev-digest-159-ai-pipelines-10x-faster-typescript-how-to-interview) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 139 - Soft and hard queries](https://www.wearedevelopers.com/magazine/487-dev-digest-139-soft-and-hard-queries)