Senior Security Engineer

Armada

Bellevue (WA)

On-site

USD 157,596 - 196,995

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Armada is seeking a senior Security Engineer to own and drive security strategy across Azure cloud, hybrid infrastructure, and edge platforms. You will set direction for detection engineering, Kubernetes hardening, and CI/CD controls while mentoring engineers on secure deployment practices.

The role is office-based in Bellevue, WA, with responsibilities spanning cloud/security architecture, incident response, threat modeling, and governance aligned to NIST/ISO 27001/SOC 2.

Qualifications

  • Bachelor degree and 8+ years in information security; or Master’s with 6+ years.
  • 8+ years in information security with 5+ years cloud security.
  • Azure security services expertise including Defender for Cloud, Sentinel, Entra ID, Key Vault, Policy and network security.
  • Production experience across SIEM, EDR/XDR, WAF, email security, CSPM/CNAPP and vulnerability management.
  • Kubernetes security in production at scale.
  • CI/CD security with SAST, DAST, SCA, secrets scanning and IaC scanning.
  • Advanced app security testing for web/API and secure code review.
  • Vulnerability management tools: Nessus, Nexpose, Qualys, Defender VM.

Responsibilities

  • Own and evolve security architecture across Azure, hybrid, and edge deployments.
  • Direct the use of SIEM, EDR/XDR, WAF, email security, and CSPM/CNAPP tooling.
  • Design detection rules, correlation logic, and automated response playbooks.
  • Lead end-to-end incident response as senior escalation point.
  • Lead security assessments, vulnerability scanning, and penetration testing.
  • Test web applications and APIs for auth flaws and OWASP Top 10 issues.
  • Threat model new services and guide risk tradeoffs with engineering.
  • Own vulnerability lifecycle: prioritization, SLA tracking, remediation.
  • Integrate SAST, DAST, SCA, secrets scanning, IaC scanning into CI/CD.
  • Harden software supply chain: SBOM, provenance, artifact signing.
  • Define policy-as-code guardrails with Azure Policy, OPA/Gatekeeper, Kyverno.
  • Serve as senior security reviewer for designs and code across teams.

Skills

Azure security
Incident response
Security architecture
Kubernetes security
CI/CD security
Threat modeling
SAST/DAST
Python automation
NIST ISO SOC2

Education

Bachelor's degree in Computer Science or Cybersecurity
Master's degree

Tools

SIEM
EDR/XDR
WAF
CSPM
Nessus

Job description

Bellevue Office, Sunset Corporate Campus

About the Company

Armada is thehyperscalerfor the edge, delivering modular AI infrastructure from first deployment to AI factory with speed,scaleand sovereignty. Namedone of Fast Company's Most Innovative Companiesandtothe CNBC Disruptor 50, Armada’s solutions are deployed in over 60 countries globally for organizations ranging from energy to defense.

With nearly $500 million in funding to date, Armada is backed by leading investors including FoundersFund, Lux, BlackRock and Microsoft (M12), alongside strategic partnerships with Microsoft, Dell,Palantir, NVIDIA, SpaceX, and Skydio. We are building the infrastructure layer for sovereign and edgeAI - rugged, deployable compute for customers that cannot rely on centralized cloud.

Working at Armada means taking ownership, driving autonomy, and delivering impact. You’ll tackle challenges that haven’t been solved before and help build something transformative from the ground up. What you do here will not only define your career but help further Armada’s mission to bridge the digital divide for customers around the world.

About the Role

You will own and drive security engineering strategy across our Azure cloud, hybrid infrastructure, and edge computing platform. This is a senior, hands-on role: you'll set direction for detection engineering, application security testing, Kubernetes hardening, and CI/CD controls, while also advising other engineers and teams on complex security decisions. You will also help define our strategic approach to securing AI/ML workloads running at the edge.

Location. This role is office-based at our Bellevue, Washingtonoffice.

What You'll Do (Key Responsibilities)

Cloud and Infrastructure Security

  • Own and evolve security architecture strategy across Azure, hybrid infrastructure, and edge deployments, guiding design decisions across teams
  • Direct the use of SIEM (Microsoft Sentinel), EDR/XDR, WAF, email security, and CSPM/CNAPP tooling, adapting approach as the environment evolves
  • Design detection rules, correlation logic, and automated response playbooks, and guide others in building their own
  • Lead incident response end-to-end, from triage through containment and remediation, serving as the senior escalation point for complex incidents

Offensive Security and Assessment

  • Lead security assessments, vulnerability scanning, and penetration testing across cloud, infrastructure, and application layers
  • Test web applications and APIs for authentication and authorization flaws, business logic abuse, and OWASP Top 10 issues
  • Threat model new services and architectures before they ship, advising engineering teams on risk tradeoffs
  • Own the vulnerability lifecycle end-to-end: risk-based prioritization, SLA tracking, and remediation follow-through, holding owning teams accountable
  • Direct the integration of SAST, DAST, SCA, secrets scanning,IaCscanning, and container image scanning into CI/CD as automated gates
  • Harden the software supply chain: build provenance, artifact signing, SBOM generation, dependency governance
  • Define and enforce guardrails as policy-as-code using Azure Policy, OPA/Gatekeeper, orKyverno
  • Serve as a senior security reviewer for designs and code across engineering teams, influencing secure deployment practices org-wide

AI/ML Security

  • Define and lead our approach to securing AI/ML development and deployment, including model and data supply chain integrity, inference endpoint exposure, prompt injection and agentic tool abuse, and training data governance

Governance

  • Own security policies, standards, and procedures aligned to NIST, ISO 27001, and SOC 2, and drive their adoption across teams
  • Produce audit evidence and lead customer security assessments
  • Track emerging threats and translate them into roadmap priorities,advisingleadership on risk

Required Qualifications:

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field and 8+ years of experience; orMaster'sdegree and 6+ years; or equivalent practical experience
  • 8+ years in information security, including 5+ years focused on cloud security
  • Deep, hands‑onexpertisewith Azure security services including Defender for Cloud, Sentinel, Entra ID, Key Vault, Azure Policy, and network security
  • Production experience across multiple of: SIEM, EDR/XDR, WAF, email security, CSPM/CNAPP, vulnerability management, with the judgment to adapt tooling strategy as needs evolve
  • Proven experience securing Kubernetes and containerized workloads in production at scale
  • Experience embedding security testing into CI/CD pipelines using SAST, DAST, SCA, secrets scanning, andIaCscanning
  • Advanced application security testing experience covering web and API penetration testing and secure code review
  • Proficiencywith vulnerability management platforms such as Nessus, Nexpose, Qualys, or Defender Vulnerability Management
  • Python and SQL/KQL for automation, tooling, and log analysis
  • Strong working knowledge of NIST, ISO 27001, and SOC 2, with experience applying them to real audit and compliance cycles
  • Experience leading incident response as the primary or senior responder on complex, high‑stakes incidents
  • Demonstrated experience advising or mentoring other engineers on security best practices

Preferred Qualifications:

  • Experience securing edge, disconnected, or intermittently connected environments
  • Experience securing AI/ML or LLM-based systems, including OWASP Top 10 for LLM Applications and MITRE ATLAS
  • Advanced detection engineering experience: writing and tuning KQL, detection‑as‑code, purple team exercises
  • Infrastructure‑as‑code fluency with Terraform or Bicep
  • Familiarity with MITRE ATT&CK for threat modeling and detection coverage mapping
  • Experience leading or supporting SOC 2 Type II or FedRAMP audit cycles

Certifications

At leastone from eithergroup is preferred.

  • Defensive and architecture: CISSP, CCSP, Azure Security Engineer Associate (AZ-500), GCIH, GCIA
  • Offensive: OSCP, OSWE, OSWP, OSEE, GPEN, GWAPT, CEH

Forselectroles, due to the nature of our clientele and the technologies involved, there may be specific nationality or citizenshipindicatedin the required qualifications section.These roles may involve access to sensitive information that is subject to export control regulations or other legal restrictions.In such cases, employment offers will be contingent upon your ability tocomply withthese requirements.

Compensation

For U.S. Based candidates: To ensure fairness and transparency, the starting base salary range for this role for candidates in the U.S. are listed below, varying based on location experience, skills, and qualifications.

In addition to base salary, this role will also be offered equity and subsidized benefits

  • Competitive base salary and equity
  • Medical, dental, and vision (subsidized cost)
  • Health savings accounts (HSA), flexible spending accounts (FSA), and dependent care FSAs (DCFSA)
  • Retirement plan options, including 401(k) and Roth 401(k)
  • Unlimited paid time off (PTO)
  • 14 paid company holidays per year

#LI-ST1

#LI-Onsite

#770

Compensation

$157,596 - $196,995 USD

You're a Great Fit if You're

  • A go-getter with a growth mindset.You're intellectually curious, have strong business acumen, and actively seek opportunities to build relevant skills and knowledge
  • A detail-oriented problem‑solver.You can independently gather information, solve problems efficiently, and deliver results with a \"get-it-done\" attitude
  • Thrive in a fast-paced environment.You're energized by an entrepreneurial spirit, capable of working quickly, and excited to contribute to a growing company
  • A collaborative team player.You focus on business success and are motivated by team accomplishment vs personal agenda
  • Highly organized and results-driven.Strong prioritization skills and a dedicated work ethic are essential for you

Equal Opportunity Statement

At Armada, we are committed to fostering a work environment where everyone is given equal opportunities to thrive. As an equal opportunity employer, we strictly prohibit discrimination or harassment based on race, color, gender, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other characteristic protected by law. This policy applies to all employment decisions, including hiring, promotions, and compensation. Our hiring is guided by qualifications, merit, and the business needs at the time.

Unsolicited Resumes and Candidates

Armada does not accept unsolicited resumes or candidate submissions from external agencies or recruiters. All candidates must apply directly through our careers page. Any resumes submitted by agencies without a prior signed agreement will be considered unsolicited and Armada will not be obligated to pay any fees.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer, Infrastructure
Senior Software Engineer, Infrastructure

Garuda Ventures • Bellevue (WA)

On-site
USD 158,000 - 197,000
Equity
Subsidized benefits
Healthcare
+3
AI Engineer
AI Engineer

Armada • Bellevue (WA), Northern (KY)

Hybrid
USD 155,000 - 193,000
Equity
Medical, dental, vision insurance
401(k) and Roth 401(k)
+1
Senior Platform/DevOps Engineer (Kubernetes-Linux)
Senior Platform/DevOps Engineer (Kubernetes-Linux)

Armada • Bellevue (WA)

On-site
USD 158,000 - 197,000
Competitive base salary
Equity
HSA/FSA medical benefits
+3
Senior Product Manager, Federal
Senior Product Manager, Federal

Armada • Washington

Hybrid
USD 130,000 - 196,000
Medical benefits
Equity
Unlimited PTO
Senior Software Engineer - GPUaaS
Senior Software Engineer - GPUaaS

Armada • Bellevue (WA)

On-site
USD 158,000 - 197,000
Equity
Subsidized benefits
Medical, dental, and vision
+3
Principal Product Manager, AEP Foundation & Partner Platforms
Principal Product Manager, AEP Foundation & Partner Platforms

Armada • Bellevue (WA)

On-site
USD 231,564 - 289,455
Equity
Health benefits
Distinguished Engineer / Technical Fellow
Distinguished Engineer / Technical Fellow

Garuda Ventures • Bellevue (WA)

On-site
USD 223,000 - 300,000
Competitive base salary
Medical, dental, and vision
Health savings accounts
+3
Senior Mission Success Engineer, US Federal
Senior Mission Success Engineer, US Federal

Armada • Springfield (VA)

Remote
USD 188,000 - 235,000
Medical, dental, and vision benefits
401(k) and Roth 401(k) plan options
Unlimited paid time off
+1
Senior Platform/DevOps Engineer (Kubernetes-Linux)
Senior Platform/DevOps Engineer (Kubernetes-Linux)

Armada • Bellevue (WA)

On-site
USD 144,000 - 180,000
Unlimited paid time off (PTO)
14 paid company holidays
Medical, dental, and vision benefits
+1
Senior Customer Solutions Engineer, Edge AI, AMER
Senior Customer Solutions Engineer, Edge AI, AMER

Armada • United States

On-site
USD 188,000 - 235,000
Unlimited paid time off (PTO)
Medical, dental, and vision insurance
401(k) retirement plan
+1