Senior Security Engineer (FedRAMP)

Veeam Software

San Jose (CA)

On-site

USD 238,000 - 442,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Unlimited PTO
Paid parental leave
Medical, dental, vision coverage
SupportLinc EAP
401(k) with matching
Maven fertility/adoption support
AirVet

Job summary

Veeam Software is seeking a Senior Security Engineer to lead security engineering for Veeam Data Cloud (VDC), securing FedRAMP-boundary and regulated workloads on Azure and AWS. You will partner with product, platform engineering, and SRE to embed secure-by-design patterns and establish baselines to keep VDC compliant at scale.

This role requires hands-on collaboration across engineering, security, and compliance teams, with an on-call rotation and ongoing efforts to adapt controls to evolving

Qualifications

  • 8+ years in security engineering within cloud environments.
  • Experience delivering cloud products to meet regulated compliance (FedRAMP, CMMC, IL2/IL4/IL5, sovereign cloud).
  • Translate compliance controls into concrete architecture and operational decisions.
  • Working knowledge of NIST 800-53, continuous monitoring, vulnerability management, configuration management.
  • Experience hardening infrastructure to STIGs or CIS benchmarks.
  • Strong cloud security fundamentals: identity, network, encryption, remediation.
  • Collaborative hands-on partner across engineering, product, security, compliance, and SRE.
  • AI tools as a force multiplier in security workflows.

Responsibilities

  • Champion secure design patterns to enable compliance-driven engineering across cloud environments.
  • Support onboarding of workloads into regulated environments from a security perspective.
  • Harden infrastructure against secure baselines (STIGs/CIS).
  • Oversee vulnerability scanning and remediation with the Platform team.
  • Support change control and baseline configuration with Platform Engineering and SRE.
  • Review architecture changes for security input and approvals.
  • Build reusable guardrails and evidence for FedRAMP and other frameworks.
  • Review code and identify security deficiencies.
  • Align roadmaps so controls carry across environments and frameworks.
  • Participate in on-call rotation to respond to alerts.

Skills

Security engineering
Cloud security
NIST 800-53
Vulnerability management
Cross-team collaboration

Tools

Azure
AWS
Terraform
GitHub
Wiz
Nessus

Job description

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.

About The Role

We’re looking for a Senior Security Engineer to support the development and growth of Veeam Data Cloud (VDC), our cloud-native SaaS platform. This role owns hands‑on security engineering for VDC’s regulated environments, starting with our FedRAMP boundary but extending to the broader set of regulated customer needs we will take on as our platform grows. VDC delivers high‑trust, secure data protection services on Microsoft Azure and AWS for customers in regulated industries.

You’ll partner closely with product, platform engineering, and SRE to embed compliant, secure‑by‑design patterns into everything we ship — designing controls that satisfy NIST 800‑53 today but will adapt to other frameworks as we expand.

This is a role with room to shape how security engineering scales across VDC’s regulated footprint: you will own the domain end to end, work independently on complex, ambiguous problems, and set baselines, review practices, and remediation standards to keep VDC compliant and secure at scale.

Due to the fact that this position will deal with highly sensitive data and will support federal customers, we are only considering US citizens at this time. Security clearance is not required, but there is a slight chance it maybe requested in the future

What You’ll Do
  • Champion secure design patterns that enable compliance‑driven engineering across VDC’s Cloud environments, including VDC‑wide standards such as supply chain security
  • Support the design and onboarding of new workloads into regulated environments from a security compliance perspective
  • Partner with VDC Engineering to harden shared infrastructure (e.g. VMs, containers, and operating systems) against secure baselines such as STIGs and CIS benchmarks
  • Oversee and support vulnerability scanning alongside the Platform team, providing remediation guidance and tracking fixes against SLAs
  • Support configuration management change control and configuration baseline compliance with Platform Engineering and SRE
  • Review significant architecture changes across our regulated environments and provide security input on approvals
  • Build reusable, framework‑agnostic guardrails and evidence so security controls scale across FedRAMP, sovereign cloud, and emerging regulatory requirements
  • Review application and platform code and identify security deficiencies
  • Align commercial, government, and other product roadmaps so controls and standards carry cleanly across environments and frameworks
  • Participate in an on‑call rotation shared across the Security Engineering team to respond, triage, and resolve alerts to closing
What You’ll Bring
  • 8+ years in security engineering, with hands‑on experience securing cloud environments (strong preference for experience in Azure and/or AWS)
  • Experience delivering cloud products to meet regulated compliance requirements such as government (FedRAMP, CMMC, IL2/IL4/IL5, sovereign cloud), financial services (PCI‑DSS), and/or healthcare (HIPAA, HITRUST)
  • Ability to translate specific compliance controls into concrete architecture and operational decisions (e.g., how an audit logging requirement drives log retention design, or how boundary protection requirements shape network segmentation)
  • Working knowledge of NIST 800-53, including continuous monitoring, vulnerability management, and configuration management standards
  • Experience hardening infrastructure to secure baselines such as STIGs or CIS benchmarks
  • Strong understanding of cloud security fundamentals in identity, network boundaries, encryption, and vulnerability remediation domains
  • Ability to learn large, complex platforms quickly with limited guidance: Being comfortable building understanding from code, docs, and architecture artifacts
  • A collaborative, hands‑on approach to partnering across engineering, product, security, compliance, and SRE
  • Deep partner mindset: Ability to take a hands‑on approach to enable engineering teams rather than serving as gatekeepers
  • AI as a force multiplier: AI tools are woven into how we work, and we build security at AI-speed using these tools. We want engineers who treat AI as a force multiplier, not an afterthought
Bonus Skills
  • Experience designing and working with controls to satisfy requirements across multiple compliance frameworks
  • Hands‑on experience with vulnerability scanning tools (e.g. Wiz, Nessus)
  • Experience with IaC tools (e.g. Terraform)
  • Experience using GitHub for configuration management and change control
  • Exposure to supply chain security standards and secure‑by‑design practices
  • Relevant certifications (e.g., CISSP, CCSP, or cloud provider security certs)
What You’ll Get
  • Unlimited paid time off, plus 3 global VeeaMe Days for self‑care
  • Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
  • Medical, dental, and vision coverage from day one
  • Mental health support, therapy sessions, and digital wellness tools via SupportLinc EAP
  • 401(k) retirement plan with matching contributions up to annual limits
  • Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
  • AirVet: 24/7 virtual veterinary care at no cost
  • Legal services, identity protection, and supplemental health insurance options
  • Tax‑advantaged spending accounts for healthcare, dependent care, and commuting
  • Professional training and education, including courses and workshops, internal meetups, and unlimited access to our online learning platforms (LinkedIn Learning, Athena, O’Reilly) and mentoring through our MentorLab program
What You'll Get
  • Unlimited paid time off, 12 paid holidays including 4 global VeeaMe Days for self‑care and 24 paid volunteer hours annually through Veeam Cares
  • Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
  • Medical, dental, and vision coverage starting on your first day
  • Mental health support, therapy sessions, and digital wellness tools via our Employee Assistance Program
  • 401(k) retirement plan with company matching contributions
  • Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
  • AirVet: 24/7 virtual veterinary care at no cost
  • Legal services, identity protection, and supplemental health insurance options
  • Tax‑advantaged spending accounts for healthcare, dependent care, and commuting
  • Opportunities to learn and grow through on‑demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning
Pay Transparency

Veeam is committed to pay transparency and equitable compensation. For this role, the compensation range below reflects the expected total target compensation (TTC), inclusive of base pay and a competitive performance‑based bonus. For roles with a commission plan, the compensation range represents On Target Earnings (OTE), which includes base salary plus variable commission. When determining compensation, Veeam takes into consideration factors such as experience, education, skills, and geographic zone. Offers are typically made below the midpoint of the range.

In addition to compensation, Veeam provides a comprehensive benefits package, including health coverage, retirement plans, and unlimited time off.

Compensation Range (TTC / OTE)

$237,800—$441,500 USD

Veeam Software is an equal opportunity employer

Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.

Personal data collected during the recruitment process will be processed in accordance with our Recruiting Privacy Notice, which explains how your information is collected, used, and handled in connection with hiring activities. By applying for this position, you consent to this processing.

By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer, Product AppSec
Senior Security Engineer, Product AppSec

Veeam Software • United States

On-site
USD 172,000 - 321,000
Unlimited PTO
Paid holidays
Medical/dental/vision coverage
+4
DevSecOps
DevSecOps

Veeam Software • San Jose (CA)

On-site
USD 111,000 - 184,000
Unlimited PTO
12 holidays incl. VeeaMe Days
Volunteer hours
+1
Site Reliability Engineer
Site Reliability Engineer

Veeam Software • United States

On-site
USD 110,000 - 253,000
Unlimited PTO
Paid holidays
Medical, dental, vision
+2
Principal Sales Systems Engineer
Principal Sales Systems Engineer

Veeam Software • United States

On-site
USD 220,000 - 563,000
Unlimited PTO
Paid holidays (12)
Medical/dental/vision coverage fromDay
+1
Security Engineer III
Security Engineer III

Veeam • San Jose (CA), Northern (KY)

Hybrid
USD 209,000 - 348,000
Unlimited PTO
Medical, dental, and vision coverage
401(k) with company match
+1
Cyber-Security Operations Analyst III, Product AppSec
Cyber-Security Operations Analyst III, Product AppSec

Veeam Software • United States

On-site
USD 102,000 - 171,000
Unlimited paid time off
Paid parental leave
Medical, dental, and vision coverage
+2
Senior Cyber-Security Operations Analyst, Product AppSec
Senior Cyber-Security Operations Analyst, Product AppSec

Veeam Software • United States

Hybrid
USD 121,000 - 226,000
Unlimited paid time off
Paid parental leave
Medical, dental, and vision coverage
+2
Senior Manager, Center of Expertise
Senior Manager, Center of Expertise

Veeam Software • United States

Hybrid
USD 149,000 - 383,000
Unlimited paid time off
401(k) retirement plan
Paid parental leave
+1
Senior Product Manager, Secure Azure CI/CD Platform
Senior Product Manager, Secure Azure CI/CD Platform

Veeam Software • United States

On-site
USD 147,000 - 378,000
Unlimited paid time off
12 paid holidays
401(k) retirement plan with matching contributions
+1
Senior Domain Engineering Specialist- Vault & Cloud
Senior Domain Engineering Specialist- Vault & Cloud

Veeam Software • United States

Hybrid
USD 121,000 - 311,000
Unlimited paid time off
Medical, dental, and vision coverage
401(k) plan with matching contributions