Security Engineer

Pantheon

San Francisco (CA)

Remote

CAD 90,000 - 140,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health & Wellness
Remote & In‑Office
Flexible Time‑Off
Book & Gym Allowance
Promoting Inclusivity
Donation Matching
Employee Resource Groups
Professional Development

Job summary

PANTHEON is seeking a Security Engineer II to advance our security program across the Pantheon platform. This hands-on role focuses on building detection rules, vulnerability tooling, and end-to-end security automation that scale with engineering velocity.

You will drive security by design within agile, cloud-native environments, coordinate with squads on remediation, and help mature our CI/CD security integrations and supply chain controls.

Qualifications

  • Minimum 4+ years of overall experience, with at least 2+ years in Application Security or Security Engineering.
  • Hands-on engineering role focused on implementing security controls and automation.
  • Experience with Secure by Design practices and cloud-native environments.

Responsibilities

  • Write detection rules and response playbooks for security monitoring.
  • Build and maintain security automation pipelines and tooling.
  • Own vulnerability management across SAST/DAST/SCA in cloud and on‑prem environments.
  • Implement supply chain security controls and integrate them into engineering workflows.
  • Perform RBAC cleanup and manage GitHub org security policies.

Skills

Python
Go
CI/CD
Security tooling
SAST/DAST/SCA
GCP
Kubernetes
RBAC

Education

Bachelor's degree in Computer Science or equivalent

Tools

Jenkins
CircleCI
Cloud Build
Wiz
CodeQL
Vulntools

Job description

  • Pantheon’s Security Engineering team is responsible for safeguarding, auditing, and testing the security of Pantheon’s entire platform
  • Our Security Engineering team aims to create a comprehensive and multi-dimensional approach to application security, with a focus on Security by Design in agile software development and cloud native environments
  • We are seeking a Security Engineer II to join our growing team
  • This role bridges execution and tooling — you’ll own security domains end-to-end while building the automation and processes that multiply the team’s impact across engineering
  • This is a hands‑on engineering role: you’ll write detection rules, build vulnerability management tooling, implement supply chain security controls, and develop the automation pipelines that make security scale
  • Detection Engineering: Author SIEM detection rules and response playbooks in Chronicle / Google SecOps (YARA-L), expanding coverage across Pantheon’s security monitoring surface
  • Security Tooling Development: Build and maintain security automation pipelines (Python/Go) — vulnerability management tooling (vulntools, Wiz scripts), GHAS automation, and CI/CD security integrations
  • Vulnerability Management: Own vulnerability identification, triage, and remediation coordination with engineering squads across application (SAST/DAST/SCA) and infrastructure layers
  • Supply Chain Security: Implement supply chain security controls (Aikido, SLSA, dependency pinning) and integrate them into engineering workflows
  • Access & Identity: Execute RBAC cleanup, access architecture implementation, and periodic user access reviews. Manage GitHub org-level security policies and access controls
  • Cloud Security: Execute CSPM baseline findings triage, cloud security baseline validation, and data warehouse security implementation (Snowflake)
  • DLP & Secrets: Define DLP policies and evaluate tooling; execute credential and secrets hygiene programs (plaintext credential remediation in repositories)
  • Our mission is to safeguard, audit, and test the security of the entire cloud hosting platform in these core areas:
  • Security by Design: Implement “Security by Design” within agile software development and cloud‑native environments
  • Security Tooling & Automation: Build and maintain security tooling and automation that scales the team’s impact beyond what manual processes can achieve
  • Support and Mentorship: Act as a Subject Matter Expert (SME), mentoring and supporting security engineering efforts across the organization
  • Standard Setting: Contribute to application security policy, process, standards, and guidelines — and build the tooling that enforces them
  • Application Security Performance: Help engineering teams design and build high‑performing, secure applications by mitigating security issues in a risk‑based manner
Benefits
  • Health & Wellness: Taking care of you and your family is important to us. Our healthcare benefits program delivers choice and value so you can prioritize your health
  • Remote & In‑Office: We believe in a flexible employee experience, our San Francisco office is a center for collaboration and connection, but it’s not the only place this happens
  • Flexible Time‑Off: We encourage work/life balance. Take time off when you need it, and return ready to make magic on the internet when you’re ready and refreshed
  • Monthly Book & Gym Allowance: One of the many ways we enable our team to take control of their development and wellness is to take advantage of our books and gym membership allowance
  • Promoting Inclusivity: We strive to have a culture where Pantheors across the globe feel a high sense of belonging and engagement. We have several programs in place to help cultivate inclusion at Pantheon, including educational events, open forums, and training opportunities
  • Giving Back: We believe in cultivating passion and giving back to the community we live and work in. Pantheon offers a Donation Matching program of $500 per employee and holds multiple team volunteer opportunities throughout the year
  • Employee Resource Groups: Our Pantheon Resource Groups (PRGs) allow employees to connect, support each other, and spread awareness
  • Professional Development: We support employee learning and development through company led‑training, leadership forums, and full access to LinkedIn Learning’s catalogue of courses
  • Grit: Understanding that establishing security best practices is a marathon requiring persistence across many stakeholdersCommitment: Demonstrated commitment to teamwork, professionalism, and authenticity, fostering trust and accountabilityBuilder Orientation: You measure impact by what you ship — tooling that engineering teams adopt, automation that replaces manual work, detection rules that catch real threats. Not by tickets closed or alerts triagedCommunication: Strong communication skills essential for partnering with engineering teams across the organization. You advocate for security priorities and tradeoffs across functions without being promptedCI/CD Fundamentals: Hands‑on experience with Jenkins, Cloud Build, CircleCI, or similar (bonus points for experience with reusable workflows)Coding Proficiency: Ability to build maintainable components in Python or Go. You write tools, not just policiesSecurity Tooling: Demonstrated experience building security automation — vulnerability management scripts, CI/CD pipeline integrations, detection rules, or similar tooling that engineering teams use in productionDevelopment Practices: Hands‑on experience with Secure by Design development practices, including participating in security architecture and design reviewsCloud Proficiency: Experience securing production systems in cloud environments (GCP preferred; AWS or Azure also valuable)Education: Bachelor’s degree (preferred) in Computer Science or equivalent practical experienceSecurity Tooling Platforms: Experience with SAST/DAST/SCA/CSPM tools. Familiarity with CodeQL, Wiz, or similar platforms is a plusCloud & Infrastructure: Experience working with containerization (e.g., Docker, OCI), Terraform, and Kubernetes (K8s)Overall Experience: Minimum of 4+ years of overall experience, with at least 2+ years dedicated to Application Security or Security Engineering
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer II
Security Engineer II

WebHosting • United States

Hybrid
USD 120,000 - 180,000
Security Engineer II
Security Engineer II

Pantheon Systems, Inc • San Francisco (CA), Chicago (IL)

On-site
CAD 94,000 - 118,000
Equity plan
Flexible time off
Medical insurance
+4
Security Engineer II: Cloud Security & Tooling
Security Engineer II: Cloud Security & Tooling

Pantheon • San Francisco (CA), Chicago (IL)

On-site
CAD 94,000 - 118,000
Equity plan
Flexible time off
Medical insurance
+4
Security Engineer II - Automation & Cloud Security
Security Engineer II - Automation & Cloud Security

WebHosting • United States

Hybrid
USD 120,000 - 180,000
Staff DevSecOps Engineer
Staff DevSecOps Engineer

Red Ventures • United States

Hybrid
USD 180,000 - 240,000
Hybrid Schedule
Flexible PTO
Mentorship Culture
+2
Staff Security Engineer - Security Operations
Staff Security Engineer - Security Operations

Pantheon • United States

Remote
USD 180,000 - 240,000
Security Engineer
Security Engineer

Factory • San Francisco (CA)

On-site
USD 120,000 - 150,000
Senior Security Engineer (Sec-Ops)
Senior Security Engineer (Sec-Ops)

RXinsider LTD. • Philadelphia

On-site
USD 150,000 - 190,000
Security Engineer
Security Engineer

Clay • San Francisco (CA), New York (NY)

On-site
USD 150,000 - 190,000
Security Engineer II: Remote, Automate & Harden Cloud Apps
Security Engineer II: Remote, Automate & Harden Cloud Apps

Pantheon • San Francisco (CA)

Remote
CAD 90,000 - 140,000
Health & Wellness
Remote & In‑Office
Flexible Time‑Off
+5