Senior Security Engineer - DevSecOps, Cloud & Compliance

8090 Solutions Inc

Redwood City (CA)

On-site

USD 180,000 - 350,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

8090 Solutions Inc in Redwood City, CA, seeks a Lead Security Engineer to own application security, cloud security posture, and compliance for the Software Factory and 8090 Enterprise. You will report to the CEO and work with the CTO and engineering teams to secure customer environments and drive security across products.

This hands-on role writes CI/CD security gates, conducts internal and third-party testing, and guides auditors while automating security with the Software Factory to scale a

Qualifications

  • 7 to 10 years of professional IT, DevOps, or application development experience, including at least 3 years in a role where application, cloud, or infrastructure security was a primary responsibility.
  • Led security and compliance functions at a technology startup (Series A, B, or C).
  • Hands-on engineer who builds web applications and DevSecOps pipelines and writes infrastructure-as-code.
  • Application security depth: SAST, DAST, dependency and secrets scanning, CI/CD security gates, threat modeling, vulnerability management, and internal penetration testing.
  • Cloud, networking, systems architecture, and release-engineering fundamentals, with depth in AWS and the ability to secure or direct work in GCP and Azure.
  • Experience with infrastructure as code, containers, identity and access management, secrets and key management, logging, detection, and incident response.
  • Working knowledge of SOC 2, GDPR security requirements, HIPAA safeguards, and FedRAMP mechanics.
  • Experience working in a regulated industry (healthcare, financial services, or GovTech) as an IT professional, software engineer, platform engineer, or security engineer.
  • Experience directing external auditors, security assessors, managed service providers, penetration testers, and compliance or security tooling vendors.
  • Comfortable in front of customer CISOs, CIOs, security teams, and system architects. You can work credibly with engineers and explain architecture, controls, risk, and trade-offs to customers and executives.
  • A record of owning ambiguous problems, learning missing context quickly, and driving work to verified completion, with small internal teams and large, demanding customer organizations.

Responsibilities

  • Own the security program across the Software Factory and 8090 Enterprise applications; build and operate SAST, DAST, software composition analysis, secrets detection, and IaC scanning in GitHub Actions pipelines with remediation SLAs.
  • Perform internal and direct third‑party penetration testing; scope, direct audits, and manage vulnerability disclosure channels.
  • Own the security posture of production environments (AWS primarily; some GCP/Azure); implement least‑privilege IAM, network segmentation, encryption, secrets management, logging, threat detection, and IaC guardrails.
  • Architect security decisions including authentication/authorization, tenant isolation, data handling, audit logging, and AI agent controls; lead threat modeling and design reviews.
  • Own SOC 1/2, GDPR, HIPAA, and FedRAMP controls; manage auditors and compliance tooling; set the roadmap for future frameworks.
  • Partner with sales for security reviews, questionnaires, RFPs, and build a customer trust center; present to CISOs and security teams.
  • Develop AI-driven security automations to reduce manual work; ensure least privilege, isolation, logging, testing, and human approval for changes.
  • Lead the incident response plan, runbooks, tabletop exercises, and breach notification obligations; coordinate with a managed detection and response partner.
  • Maintain vendor and subprocessor inventories; manage vendor security reviews and AI/LLM supply chain risk; align with IT for remediation.

Skills

DevSecOps
Penetration testing
Cloud security
Security architecture
Compliance
Security automation
Incident response
Vendor management
Security governance
Communication with executives
Threat modeling

Tools

GitHub Actions
AWS
Terraform
AWS CDK
Docker

Job description

8090 Solutions Inc in Redwood City, CA, seeks a Lead Security Engineer to own application security, cloud security posture, and compliance for the Software Factory and 8090 Enterprise. You will report to the CEO and work with the CTO and engineering teams to secure customer environments and drive security across products.

This hands-on role writes CI/CD security gates, conducts internal and third-party testing, and guides auditors while automating security with the Software Factory to scale a

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Security Engineer: DevSecOps & Cloud Security
Lead Security Engineer: DevSecOps & Cloud Security

Worky • Redwood City (CA)

On-site
USD 180,000 - 350,000
Lead Security Engineer
Lead Security Engineer

8090 Solutions • Redwood City (CA)

On-site
USD 180,000 - 240,000
Stock Options
Medical Insurance
Dental Insurance
+2
Senior Cloud Security DevSecOps Lead – Incident Response
Senior Cloud Security DevSecOps Lead – Incident Response

8090 Solutions • Redwood City (CA)

On-site
USD 180,000 - 240,000
Stock Options
Medical Insurance
Dental Insurance
+2
Senior Cloud Security & DevSecOps Engineer
Senior Cloud Security & DevSecOps Engineer

DANASTAR Professional Services, LLC • Washington

Hybrid
USD 140,000 - 190,000
Medical insurance
Three weeks of paid time off
Paid Federal holidays
+1
Security Engineer
Security Engineer

Factory • San Francisco (CA)

On-site
USD 120,000 - 150,000
Secure Software Engineer - DevSecOps & SDLC
Secure Software Engineer - DevSecOps & SDLC

Active Soft Inc. • San Francisco (CA)

On-site
USD 140,000 - 190,000
Lead Security Engineer - Cloud & App Security
Lead Security Engineer - Cloud & App Security

Wise Insight • San Francisco (CA)

On-site
USD 150,000 - 210,000
Senior AppSec Engineer: DevSecOps & Secure SDLC
Senior AppSec Engineer: DevSecOps & Secure SDLC

Tential Solutions • United States

On-site
USD 120,000 - 180,000
PTO
Benefits package
Career growth
Software Engineer, Security
Software Engineer, Security

Factory • San Francisco (CA)

On-site
USD 150,000 - 190,000
Senior Security Engineer for AI & Regulated FinTech
Senior Security Engineer for AI & Regulated FinTech

Salient • San Francisco (CA)

On-site
USD 180,000 - 230,000
Medical coverage
Dental coverage
Vision coverage
+2