Security Engineer

Factory

San Francisco (CA)

On-site

USD 120,000 - 150,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

A technology firm is seeking a Security Engineer to enhance its security framework. The role involves designing security measures, conducting code reviews, and collaborating with engineering teams. Candidates should have over 5 years of experience in securing cloud environments, proficiency in TypeScript and Python, and knowledge of security compliance frameworks. This position is based in San Francisco, requiring in-office presence five days a week.

Qualifications

  • 5+ years of experience as a Security Engineer with a focus on product security.
  • Strong background in securing cloud-based environments (AWS, Azure, GCP).
  • Expertise in application security, network security, and incident response.
  • Experience with container security (Docker, Kubernetes).
  • Knowledge of security compliance frameworks (ISO 27001, SOC 2, GDPR).

Responsibilities

  • Design and manage security measures for cloud infrastructure.
  • Collaborate with engineering teams to integrate security into the software development lifecycle.
  • Conduct security code reviews to identify and remediate vulnerabilities.
  • Develop and implement automated security testing procedures.
  • Respond to security incidents and participate in incident response.

Skills

TypeScript
Python
Kubernetes
Terraform
AWS
Azure
GCP
CI/CD

Tools

Docker Security
Firewalls
IDS/IPS
Vulnerability Scanners
WAF
SIEM
Encryption Solutions

Job description

Factory is seeking a talented Security Engineer to join our team. In this role, you will play a critical role in developing and maintaining the security foundation of our platform. You will conduct in-depth code reviews, implement security best practices, and influence the overall security strategy. Your expertise in TypeScript, Python, Kubernetes, CI/CD, and terraform orchestration will be crucial in identifying and mitigating potential security vulnerabilities.

What you will do and achieve:
  • Design, implement, and manage security measures for the protection of our cloud infrastructure, applications, and data, focusing on both preventative controls and rapid response capabilities.

  • Collaborate closely with our engineering teams to integrate security practices into the software development lifecycle, including secure coding standards, automated security testing, and secure architecture design.

  • Stay up-to-date on the latest security threats, vulnerabilities, and mitigation strategies.

  • Conduct security code reviews to identify and remediate security vulnerabilities.

  • Develop and implement automated security testing procedures to identify vulnerabilities and risks, recommending and implementing appropriate mitigation strategies.

  • Respond to security incidents and participate in incident response procedures.

  • Document security processes, procedures, and best practices.

  • Lead security awareness and training programs, empowering all team members to recognize and prevent potential security threats.

Qualifications
  • Minimum 5+ years of experience as a Security Engineer with a focus on product security, with a strong background in securing cloud-based environments (AWS, Azure, GCP) and understanding of Infrastructure as Code (IaC) security practices.

  • Strong coding skills with proficiency in TypeScript and Python.

  • Expertise in various security domains such as application security, network security, security operations, and incident response.

  • Experience with container security (Docker Security, Kubernetes Security).

  • Familiarity with a wide range of AWS services, including but not limited to VPC, EC2, Lambda, Amazon RDS, and S3.

  • In-depth knowledge of CI/CD pipeline tools and practices, ideally with experience in GitHub Actions or Jenkins.

  • Knowledgeable in security compliance frameworks and regulations (e.g., ISO 27001, SOC 2, GDPR) and experience with security assessments and third-party audits.

  • Proficiency with security tools and technologies, such as firewalls, IDS/IPS, vulnerability scanners, WAF, SIEM, and encryption solutions.

  • Demonstrated ability to influence security strategies and drive improvements within a team.

  • The team goes into the office 5 days a week in San Francisco (walking distance to Caltrain).

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Software Engineer, Security
Software Engineer, Security

Factory • San Francisco (CA)

On-site
USD 150,000 - 190,000
Platform Security Engineer – Cloud, IaC & Kubernetes
Platform Security Engineer – Cloud, IaC & Kubernetes

Factory • San Francisco (CA)

On-site
USD 150,000 - 190,000
Security Engineer
Security Engineer

Enterprise Engineering Inc. (EEI) • New York (NY)

On-site
USD 120,000 - 160,000
Security Engineer, Product Security Washington, DC Apply →
Security Engineer, Product Security Washington, DC Apply →

Scale AI, Inc. • Seattle (WA)

On-site
USD 228,800 - 286,000
Comprehensive health coverage
Retirement benefits
Learning and development stipend
+1
Security Engineer
Security Engineer

Methodic • San Francisco (CA)

On-site
USD 120,000 - 150,000
Security Engineer
Security Engineer

Invictus Direct • San Francisco (CA)

On-site
USD 100,000 - 200,000
Relocation assistance
Visa sponsorship
Lead Security Engineer
Lead Security Engineer

8090 Solutions • Redwood City (CA)

On-site
USD 180,000 - 240,000
Stock Options
Medical Insurance
Dental Insurance
+2
Security Engineer
Security Engineer

Red Cup IT, Inc. • United States

On-site
USD 90,000 - 120,000
Security Engineer
Security Engineer

Red Cup IT, Inc. • Los Angeles (CA)

On-site
USD 100,000 - 130,000
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000