Skip to content

Jobgether

Security Engineer

Compensation
$120K–$150K / yr
From job posting
Location
US
Arrangement
Remote
Employment type
Full-time
Posted
30 September 2026 (today)

Checked todayApplications go to the employer, never to RoleSprint

About this role

Accountabilities: • Identify and remediate vulnerabilities across applications, infrastructure, and cloud environments by contributing directly to application repositories and Terraform code and driving fixes through deployment.

• Build, maintain, and tune security detections within a SIEM, reducing false positives and improving detection coverage while mapping capabilities to MITRE ATT&CK.

• Lead security incident response activities, including investigation, containment, evidence handling, root-cause analysis, and tracking remediation through completion.

• Harden AWS environments using services and controls including IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, Secrets Manager, VPC controls, and least-privilege access.

• Strengthen security throughout the software delivery pipeline through code scanning, dependency management, secret scanning, container and image scanning, and Kubernetes admission controls.

• Automate repetitive security operations by developing workflows and scripts that support alert triage, enrichment, investigation, and remediation.

• Develop and maintain security runbooks, standards, detection documentation, and technical evidence supporting compliance requirements.

• Collaborate with engineering, sales, executive, and other cross-functional stakeholders to communicate security risks and drive practical remediation.

• Contribute to security programs supporting PCI DSS Level 1, GDPR, and SOC 2 requirements.

Requirements:

• Bachelor's degree in a relevant field with 4 years of experience, or at least 6 years of practical experience in security engineering, detection engineering, or incident response.

• Strong programming skills and the ability to investigate unfamiliar application code, understand vulnerabilities, and implement fixes through pull requests.

• Deep hands-on AWS security experience, including IAM and least-privilege design, GuardDuty, CloudTrail, KMS, VPC controls, and securing containerized and serverless workloads.

• Practical experience with security detection engineering in a SIEM, including writing detection rules, tuning alerts, managing false positives, and evaluating detection coverage.

• Proven cloud incident response experience covering investigation, containment, evidence handling, root-cause analysis, and post-incident documentation.

• Strong application security fundamentals, including the OWASP Top 10, dependency and secrets management, and CI/CD security practices such as SAST, DAST, SCA, and infrastructure-as-code scanning.

• Strong written and verbal communication skills, with the ability to explain technical risks clearly and influence stakeholders through evidence and sound reasoning.

• Experience with Datadog Cloud SIEM, CrowdStrike, Okta, or GitHub Advanced Security is a plus.

• Experience supporting PCI DSS Level 1 or SOC 2 audits from an engineering perspective is a plus.

• Experience with Kubernetes, ArgoCD, policy-as-code, Python automation, or Terraform is a plus.

• Must be currently authorized to work in the United States without requiring employer sponsorship for a work visa.

Benefits:

• Annual compensation range of $120,000–$150,000 USD, with flexibility to consider packages above this range based on skills and experience.

• Remote-first, remote-always working environment for U.S.-based employees.

• PTO in accordance with local labor requirements.

• Fully paid parental leave.

• Home office stipend based on country of residency.

• Professional development courses through Cloudbeds University.

• Access to professional development opportunities, including manager training, upskilling, and knowledge-sharing programs.

• Opportunity to work with a globally distributed team across 40+ countries.

• Hands-on exposure to modern cloud security, application security, detection engineering, and incident response practices.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Work location

  • US

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 30 September 2026, last checked today. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

Browse all current openings

No credit card requiredStart free