Senior Cybersecurity Engineer: Secure-by-Default Platform

Shield AI Inc

San Diego (CA)

On-site

USD 180,000 - 240,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Equity
Bonus
Benefits

Job summary

Shield AI Inc. is seeking a senior security engineer to own paved-road security practices across cloud, infrastructure, and CI/CD. You will design and operate IaC modules, guardrails as code, and policy controls to make secure practices the default.

You will read code, configs, and telemetry, delivering durable security solutions that scale without constant manual effort. You will partner with engineering leads to set standards, review designs for risk, and drive automated security across the

Qualifications

  • Extensive experience in security engineering, platform/infrastructure engineering, DevSecOps, or a closely related field, with a track record of owning complex systems end-to-end.
  • Strong software engineering ability - you write, review, and ship production-quality code (any modern language) and treat infrastructure as software.
  • Hands‑on experience building secure‑by‑default mechanisms: Infrastructure-as-Code, CI/CD pipeline security, and policy/guardrails as code.
  • Deep working knowledge of at least one major cloud provider and its security and identity model.
  • Demonstrated ability to design durable, automated solutions that reduce real risk without becoming a bottleneck - and to make explicit tradeoffs between security and the business.
  • Strong communication: you can explain a security concept to a product engineer in their language and to a leader in business terms, and you write recommendations people can act on.

Responsibilities

  • Build the secure defaults: Infrastructure-as-Code modules, CI/CD pipeline templates, internal libraries, and golden-path scaffolding that make the secure choice the easy choice.
  • Engineer guardrails as code - policy-as-code (OPA/Conftest), admission controllers, cloud guardrails (SCPs / org policy), and pre-commit and CI checks - so the insecure path is blocked or flagged automatically.
  • Own the platform security tooling that other teams consume, so they don’t have to build their own; replace recurring manual work with durable, self-service mechanisms.
  • Embed security into the software and infrastructure supply chain: pipeline security, build/artifact integrity, dependency and container scanning, and secrets management.
  • Engineer workload and service identity controls (least privilege, short-lived credentials, federated trust) so zero-standing-privilege is real and observable.
  • Write and maintain production-quality code and infrastructure that backs these controls.
  • Partner with platform, infrastructure, and product engineering teams early - review high-blast-radius designs against the internal Security Engineering standard while the design can still change, and turn recurring findings into a missing paved road, not just another fix.
  • Set technical direction and standards for secure-by-default; document them so they can be applied without us, and mentor and raise the bar for other engineers.

Skills

Security engineering
Infrastructure engineering
DevSecOps
Software engineering
Go
Python

Education

Bachelor’s degree or equivalent

Tools

Kubernetes
Terraform
OPA/Gatekeeper
SCPs / org policy

Job description

Shield AI Inc. is seeking a senior security engineer to own paved-road security practices across cloud, infrastructure, and CI/CD. You will design and operate IaC modules, guardrails as code, and policy controls to make secure practices the default.

You will read code, configs, and telemetry, delivering durable security solutions that scale without constant manual effort. You will partner with engineering leads to set standards, review designs for risk, and drive automated security across the

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Staff Cybersecurity Engineer, Platform Security (R5219)
Senior Staff Cybersecurity Engineer, Platform Security (R5219)

Shield AI Inc • San Diego (CA)

On-site
USD 180,000 - 240,000
Equity
Bonus
Benefits
Staff DevSecOps Engineer: Secure Cloud & CI/CD Architect
Staff DevSecOps Engineer: Secure Cloud & CI/CD Architect

AI Chopping Block • San Diego (CA)

On-site
USD 160,000 - 230,000
Platform Security Architect (DoD Secret)
Platform Security Architect (DoD Secret)

Shieldai • Dallas (TX)

On-site
USD 140,000 - 190,000
Equity
Annual bonus
Competitive benefits
Staff DevSecOps Engineer: Secure Cloud Automation Lead
Staff DevSecOps Engineer: Secure Cloud Automation Lead

Shieldai • San Mateo (CA)

On-site
USD 150,000 - 240,000
Staff DevSecOps Engineer: Cloud Security & Automation
Staff DevSecOps Engineer: Cloud Security & Automation

Shield AI • San Diego (CA)

On-site
USD 150,000 - 230,000
Bonus
Benefits
Equity
Staff DevSecOps Engineer: Secure Cloud & CI/CD Automation
Staff DevSecOps Engineer: Secure Cloud & CI/CD Automation

AI Chopping Block • San Mateo (CA), Northern (KY)

Hybrid
USD 170,000 - 240,000
Staff DevSecOps Engineer: Cloud Security & Automation
Staff DevSecOps Engineer: Cloud Security & Automation

Shieldai • San Diego (CA)

On-site
USD 140,000 - 210,000
Staff DevSecOps Engineer: Secure Cloud & CI/CD Automation
Staff DevSecOps Engineer: Secure Cloud & CI/CD Automation

Shield AI • San Mateo (CA)

On-site
USD 170,000 - 210,000
Excellent Medical Coverage
Mental Health Employee Assistance Plan
Paid Parental Leave
+8
Senior Platform Engineer: Hybrid Cloud & Automation
Senior Platform Engineer: Hybrid Cloud & Automation

Precision Labs • Northern (KY), San Diego (CA)

Hybrid
USD 140,000 - 185,000
Senior Cloud Platform Engineer: Scale, Automate & Secure
Senior Cloud Platform Engineer: Scale, Automate & Secure

Shield AI • Northern (KY)

Hybrid
USD 118,000 - 177,000
Bonus
Benefits
Equity