Senior Security Engineer

Talentify

El Segundo (CA)

Remote

USD 145,000 - 170,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Talentify is seeking a Senior Security Engineer for a 100% remote role (CST preferred). You will own the security tooling, cloud posture, IAM design, and incident response in a senior, autonomous capacity.

This is a full-time position reporting to IT leadership and focusing on end-to-end security domain ownership. The role emphasizes building scalable security architectures, phishing-resistant MFA, and automation, with collaboration across IT and security teams to elevate organizational security

Qualifications

  • 5+ years of hands-on security engineering experience
  • Detection engineering experience and SIEM ownership
  • 4+ years of cloud engineering with GCP focus
  • IAM/SAML/SCIM proficiency
  • Phishing-resistant MFA, secrets-management, and OAuth governance knowledge
  • Incident response and forensics methodology
  • EDR operations experience and device-trust design
  • Vulnerability/exposure management program experience
  • Security automation and infrastructure-as-code fluency

Responsibilities

  • Own security tooling portfolio and integrate the stack
  • Shape identity, access, and session governance across providers
  • Define and enforce cloud security posture and policies
  • Drive authentication, secrets management, and SSO governance
  • Oversee OAuth app vetting, token lifecycle, and third-party risk
  • Lead incident response and forensics with external partners
  • Advocate automation and IaC with Terraform and guardrails
  • Mentor team members and inform security decisions across the org

Skills

Security engineering
SIEM
Cloud security
Identity and access management
Incident response
Automation
Terraform

Tools

CrowdStrike Falcon
GCP IAM

Job description

JOB TITLE: Senior Security Engineer
LOCATION: 100% Remote, CST preferred
DURATION: Full-time
SALARY RANGE: $145-170k

POSITION SUMMARY:

The Senior Security Engineer is a newly established senior individual contributor role that will drive the design, implementation, and continuous advancement of Wpromote's security engineering program. Reporting to the Director of IT, you will operate as a true partner to IT leadership, trusted to shape security decisions with a depth of expertise that elevates the whole organization. This is not an analyst or application security role; you will be expected to build and improve our security systems, ideal for someone energized by owning a domain end to end and continuously raising the bar. This is a remote role, serving as a senior security presence and point of escalation across the function.

YOU ARE:
  • Composed under fire: When a security event lands, you move toward it, not away. You stay methodical and let the evidence drive your decisions, instead of panicking or jumping to conclusions.
  • Relentlessly current: You live at the leading edge of the security field, tracking emerging threats, techniques, and tooling, and you treat staying ahead of the threat landscape as a core part of the job rather than an afterthought.
  • Evidence-driven and precise: You distinguish what is observed from what is assessed, and you hold that line even when stakeholders are pushing for a certainty you cannot yet responsibly give.
  • Deeply autonomous: You own investigations end to end, escalating genuine judgment calls rather than routine unknowns, and you operate with high autonomy on security architecture and incident decisions.
  • A detailed planner who executes: You translate ambiguous problems into granular, sequenced plans of action, then deliver against them. Your plans are specific enough that others can trust and follow them.
  • A builder at heart: You are energized by owning solutions, testing new ideas, and driving improvements quickly rather than settling for the status quo.
  • An audience-aware communicator: You write clearly for executive, technical, and non-technical readers, and you exhibit good judgement and discretion during sensitive incidents where accuracy, confidentiality, and timing matter
YOU WILL BE:
  • Owning the Security Tooling Portfolio: Evaluating, integrating, and rationalizing the security tool stack so investments are coherent, well-integrated, and earning their value
  • Owning Identity and Access Architecture: Designing identity, access, and session governance across Google Workspace and additional identity providers, including least-privilege design, credential and secrets hygiene, service-identity architecture, and joiner, mover, and leaver controls at the design layer.
  • Governing Cloud Security Posture: Defining security requirements for the GCP environment and translating them into policy and controls across Cloud IAM, organization policy, service account governance, and audit logging. Partnering with platform engineering on implementation, governing posture against those requirements, and feeding cloud telemetry into the detection pipeline.
  • Advancing Authentication and Secrets: Driving our phishing-resistant MFA strategy such as passkeys and hardware keys, strengthening secrets-management architecture, and advancing SAML SSO, SCIM provisioning, and session policy across the SaaS environment.
  • Governing OAuth and Token Lifecycle: Owning OAuth app vetting and governance, token lifecycle and revocation, and third-party application risk management.
  • Owning Incident Response: Owning incident response and forensic practice, running investigations independently, and coordinating external partners during major escalations.
  • Applying Security Automation and DaC: Treating detection, policy, configuration, and response automation as code that is version-controlled, peer-reviewed, and tested. Partnering with platform engineering on Terraform and cloud guardrails where security controls intersect with infrastructure.
  • Developing Internal Capability: Mentoring and developing team members on security practice over time, and partnering with the Director of IT to inform security decisions across the organization.
YOU MUST HAVE:
  • 5+ years of hands-on security engineering experience in a professional environment, with a track record of owning security architecture and projects end to end
  • Detection engineering experience, including selecting, building, and operating a SIEM, writing and tuning detections, and owning log pipelines, alerting, and monitoring
  • 4+ years of hands-on security cloud engineering, GCP strongly preferred, including Cloud IAM, organization policy, service account governance, and audit logging
  • Deep identity and access management expertise, including federation (SAML SSO) and SCIM provisioning and deprovisioning
  • SaaS identity security depth, including phishing-resistant MFA (passkeys, hardware keys), secrets-management architecture, and OAuth app governance, token lifecycle, and third-party application risk
  • Hands‑on incident response and forensic methodology, including sound evidence handling
  • Endpoint security posture experience, including EDR operations (CrowdStrike Falcon or equivalent) and device-trust or conditional‑access design
  • Experience operating vulnerability management or exposure management programs, including prioritization by exploitability, asset criticality, and business risk
  • Security automation and infrastructure‑as‑code fluency, including detection‑as‑code and a tool such as Terraform, at a level beyond ad hoc scripting
NICE TO HAVE:
  • A background in infrastructure, cloud platform, DevOps, SRE, or systems engineering before moving into security, bringing an automation‑first foundation to detection and governance work
  • Experience scaling or maturing a security program in a fast‑growing environment
  • Industry certifications (GCP Professional Cloud Security Engineer, GIAC such as GCIH, GCDA, or GDAT, CISSP, OSCP)
  • Experience managing least‑privilege access across many vendor systems, including those that do not support SSO
  • Player‑coach or mentoring experience: while this role is scoped as a senior individual contributor, candidates who can develop internal talent will be considered for expanded scope
  • Exposure to SOC 2 or similar compliance frameworks, partnering with GRC on audit readiness
  • Scripting and automation experience (Python, Bash) for security tooling and workflow optimization
BENEFITS SUMMARY:

Individual compensation is determined by skills, qualifications, experience, and location. Compensation details listed in this posting reflect the base hourly rate or annual salary only, unless otherwise stated. In addition to base compensation, full‑time roles are eligible for Medical, Dental, Vision, Commuter and 401K benefits with company matching.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

Calance • Lemont (IL)

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

KPG99 INC • New York (NY)

On-site
USD 150,000 - 230,000
Cloud Security Engineer - GCP
Cloud Security Engineer - GCP

ExecuSource • Marietta (GA)

On-site
USD 115,000 - 155,000
Staff Security Engineer Manager
Staff Security Engineer Manager

Google • Kirkland (WA)

On-site
USD 207,000 - 301,000
Health insurance
Retirement plan
PTO 20 days
+4
Staff Security Engineer Manager
Staff Security Engineer Manager

Google • New York (NY)

On-site
USD 207,000 - 301,000
Health insurance
Dental insurance
Vision insurance
+8
Security Engineer (Google SecOps Technical Credential)
Security Engineer (Google SecOps Technical Credential)

Infinite Ranges • United States

On-site
USD 100,000 - 140,000
Senior GCP Security Engineer
Senior GCP Security Engineer

Madison-Davis, LLC • New York (NY)

On-site
USD 180,000 - 240,000
Security Engineer, PSO
Security Engineer, PSO

Google • Seattle (WA)

On-site
USD 152,000 - 221,000
Health insurance
401(k) match
Paid time off
+4
Staff Security Engineer, Product Security Engineering, Cloud CISO
Staff Security Engineer, Product Security Engineering, Cloud CISO

Google • Kirkland (WA)

On-site
USD 207,000 - 300,000
Health insurance
Dental insurance
Vision insurance
+8
Staff Security Engineer, Google Distributed Cloud, Federated Security
Staff Security Engineer, Google Distributed Cloud, Federated Security

Google • Seattle (WA)

On-site
USD 207,000 - 300,000
Health insurance
Dental insurance
Vision insurance
+8