Senior Cybersecurity Engineer

Triwill Group

United States

Remote

USD 120,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Indico Data is seeking a Senior Cybersecurity Engineer on a remote basis with East Coast hours preferred. You will be a hands-on technical security leader responsible for hardening AWS, Kubernetes, CI/CD, and incident response across our platform.

You will partner with the CISO and CTO to translate security priorities into practical controls, runbooks, and processes, while balancing security with fast, scalable product development in a startup environment.

Qualifications

  • 6+ years of security experience in software or SaaS environments.
  • Hands-on AWS security experience: IAM, networking, logging, monitoring.
  • Experience securing Kubernetes, containers, CI/CD pipelines.
  • Strong IAM and least-privilege principles.
  • Knowledge of secure coding and threat modeling.
  • Experience with vulnerability management and incident response.
  • Familiarity with security monitoring and remediation tracking.
  • Ability to review changes for material security risk.

Responsibilities

  • Improve Indico’s security posture across cloud and on‑prem environments.
  • Partner with CISO/CTO to translate priorities into controls and processes.
  • Review engineering work against security standards and request changes.
  • Define secure CI/CD patterns and manage secrets handling.
  • Oversee vulnerability management, incident response, and access control.
  • Develop product security support including threat modeling and reviews.
  • Improve detection and response with CloudTrail, GuardDuty, CrowdStrike, SIEM.
  • Own day-to-day security monitoring, triage, and escalation paths.

Skills

AWS security
Kubernetes security
CI/CD security
IAM & access control
Threat modeling
Incident response
Scripting: Python/Go
Security automation
Security reviews
Communication

Tools

CloudTrail
GuardDuty
CrowdStrike
SIEM
Terraform
ArgoCD
GitHub Actions

Job description

Senior Cybersecurity Engineer

Location: USA, East Coast Preferred
Experience Required: 6-10 years

About the Position

The Senior Cybersecurity Engineer is a hands-on technical security role responsible for improving Indico’s security posture across AWS, Kubernetes, CI/CD, product security, internal systems, and incident response.

This role works in partnership with Indico’s CISO and CTO. The CISO owns security strategy, formal risk acceptance, policy approval, and executive accountability. The Senior Security Engineer turns that direction into practical technical controls, security reviews, operating processes, and cross-functional execution.

This role acts as a security check and balance for Engineering and Platform. You will review technical work against defined security expectations, request changes where needed, and help teams build secure systems without creating unnecessary friction.

Security does not own every security task. Engineering and Platform own implementation and remediation for the systems they build and run, including CVEs, infrastructure changes, CI/CD permissions, committed-secret remediation, and production access implementation. IT/Ops, People Ops, and system owners own day-to-day access administration. The Senior Security Engineer owns technical security standards, reviews, escalation paths, control design, and program execution.

This is a remote role, with East Coast hours preferred.

About You

You are a pragmatic technical security generalist with strong cloud security instincts. You are comfortable working across AWS, Kubernetes, IAM, networking, secrets management, CI/CD, monitoring, product security, and incident response.

You are technical enough to earn credibility with Engineering and Platform, independent enough to act as a real check and balance, and practical enough to focus on controls that reduce meaningful risk.

You know how to make security work in a startup: focus on the risks that matter, keep the process lightweight, and build guardrails that help teams move quickly without creating unnecessary exposure.

Responsibilities
  • Improve Indico’s technical security posture across AWS, Kubernetes, CI/CD, product security, internal systems, and incident response
  • Partner with the CISO and CTO to turn security priorities into practical technical controls, standards, reviews, and operating processes
  • Review Engineering work against security standards, with authority to request changes where needed
  • Partner with Engineering on AWS security controls, including IAM, networking, account structure, logging, encryption, key management, backups, production access, and customer-dedicated environments
  • Review and improve Kubernetes and container security controls, including workload identity, RBAC, network boundaries, image security, runtime monitoring, and deployment patterns
  • Define and improve secure CI/CD patterns, including GitHub permissions, branch protections, privileged workflows, secrets handling, release controls, and deployment access
  • Define and oversee processes for vulnerability management, committed-secret response, secure development, incident response, and access control while Engineering, Platform, IT/Ops, and system owners operate them in their domains
  • Provide product security support, including secure design review, threat modeling for sensitive features, scanner tuning, and high-risk change review
  • Improve detection and response coverage across tools such as CloudTrail, GuardDuty, CrowdStrike, SIEM/logging platforms, vulnerability scanners, and secrets detection
  • Own day-to-day security monitoring and response operations, including alert routing, triage expectations, escalation paths, and detection improvements
  • Coordinate technical containment during security incidents across Engineering, Platform, IT/Ops, and leadership
  • Maintain incident response runbooks and partner with the CISO on severity, executive escalation, counsel/compliance coordination, and customer communication strategy
  • Create practical security guidance, standards, procedures, and runbooks for security-sensitive work such as production access, secrets handling, vulnerability remediation, incident response, customer data handling, and secure engineering
  • Maintain reusable technical security documentation, standard responses, and evidence packages for customer due diligence and compliance support
  • Evaluate security tools and vendors with a focus on technical coverage, operational fit, and reducing manual work
  • Build or sponsor lightweight automation, checks, dashboards, and workflows that make security controls repeatable
Requirements
  • 6+ years of relevant security experience, ideally in a startup, SaaS, cloud-native, or enterprise software environment
  • Strong hands-on experience with AWS security, including IAM, networking, logging, monitoring, encryption, access controls, and production security
  • Experience securing Kubernetes, containers, CI/CD pipelines, infrastructure-as-code, and modern cloud deployment patterns
  • Strong understanding of identity and access management, least privilege, privileged access, workload identity, and service-to-service permissions
  • Working knowledge of application and product security, including authentication, authorization, secure coding, common web risks, and secure design review
  • Experience defining or operating vulnerability management, secrets management, secure development, access control, or incident response processes
  • Experience with secrets management, cloud key management, encryption design, data residency, threat modeling, or secure SDLC programs
  • Experience with security monitoring, alert triage, incident response coordination, and remediation tracking
  • Experience with Python, Go, Bash, or other scripting languages for security automation
  • Ability to review infrastructure, application, and operational changes for material security risk
  • Ability to partner with Engineering and Platform while maintaining appropriate independence and oversight
  • Strong written and verbal communication skills, including clear technical guidance, standards, runbooks, and customer-facing security documentation
  • Good judgment around risk prioritization, compensating controls, exceptions, and startup-appropriate tradeoffs
  • Ability to operate independently, create structure, and drive work to completion
Bonus
  • Experience as a first or early security hire at a startup
  • Experience securing single-tenant SaaS or customer-dedicated cloud environments
  • Experience with AWS EKS, Terraform, Helm, ArgoCD, GitHub Actions, or similar infrastructure tooling
  • Experience with CrowdStrike
  • Experience supporting SOC 2, ISO 27001, HIPAA, GDPR, customer audits, or enterprise security questionnaires
  • Pragmatic, risk-based, comfortable with ambiguity, and focused on security practices people actually use
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Senior Cybersecurity Engineer – Cloud & DevSecOps
Remote Senior Cybersecurity Engineer – Cloud & DevSecOps

Triwill Group • United States

Remote
USD 120,000 - 190,000
Senior Cloud Security Engineer - AWS, Kubernetes & CI/CD
Senior Cloud Security Engineer - AWS, Kubernetes & CI/CD

Indico Data • Boston (MA)

Remote
USD 150,000 - 190,000
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Cscgeneration 2 • San Jose (CA)

Hybrid
USD 70,000 - 100,000
Remote work option
Private medical and life insurance
Additional paid time off
+2
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Devsecops Engineer
Devsecops Engineer

Sutherland • United States

Remote
USD 140,000 - 180,000
Principal Security Engineer
Principal Security Engineer

Jobtailor • Town of Texas (WI)

On-site
USD 140,000 - 190,000
Senior Information Security Engineer
Senior Information Security Engineer

Grayson Search Partners • Nashville (TN)

On-site
USD 120,000 - 150,000