Senior Security Engineer – VC Backed Startups

Jobtailor

New York (NY)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a security engineer to design and implement controls across applications, cloud environments, and development workflows. You will conduct threat modeling, architecture reviews, and security assessments for new products, while identifying and remediating vulnerabilities across the stack.

You will embed security into the SDLC through secure coding practices, automated testing, and tooling, and help build detection, monitoring, and incident response capabilities.

Qualifications

  • 5+ years of experience across security engineering, application security, cloud security, infrastructure security, or related disciplines.
  • Strong software engineering or systems engineering foundation.
  • Proficiency in languages such as Python, Go, Java, JavaScript, TypeScript, or Rust.
  • Experience securing cloud-native applications and infrastructure on AWS, GCP, or Azure.
  • Knowledge of common vulnerabilities, attack techniques, and mitigation strategies.
  • Experience with threat modeling, secure design reviews, or vulnerability research.
  • Familiarity with IAM, secrets management, encryption, and network security.
  • Experience building security automation and CI/CD integrations.
  • Ability to communicate risks to engineering teams and stakeholders.
  • Strong judgment around risk prioritization and remediation.

Responsibilities

  • Design and implement security controls across applications, cloud infrastructure, internal systems, and development environments.
  • Conduct architecture reviews, threat modeling, code reviews, and security assessments for new products and features.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.
  • Embed security into the software development lifecycle through secure coding standards, automated testing, and developer tooling.
  • Build and improve detection, monitoring, incident response, and vulnerability management capabilities.
  • Partner with engineering and infrastructure teams to strengthen cloud, container, network, identity, and access security.
  • Lead or support the investigation and remediation of security incidents.
  • Develop reusable security tooling, automation, documentation, and guardrails.
  • Evaluate third-party technologies for potential security risks.
  • Support customer security reviews, enterprise diligence, and compliance requirements.
  • Help establish security policies aligned with SOC 2, ISO 27001, HIPAA, or PCI DSS.
  • Mentor engineers and promote shared ownership of security.

Skills

Security Engineering
Cloud Security
Python
Threat Modeling
Vulnerability Management
CI/CD Integration
Incident Response
Risk Prioritization

Tools

AWS
GCP
Azure
Identity Management
Secrets Management
Encryption
Network Security

Job description


  • Design and implement security controls across applications, cloud infrastructure, internal systems, and development environments

  • Conduct architecture reviews, threat modeling, code reviews, and security assessments for new products and features

  • Identify, prioritize, and remediate vulnerabilities across the technology stack

  • Embed security into the software development lifecycle through secure coding standards, automated testing, and developer tooling

  • Build and improve detection, monitoring, incident response, and vulnerability management capabilities

  • Partner with engineering and infrastructure teams to strengthen cloud, container, network, identity, and access security

  • Lead or support the investigation and remediation of security incidents

  • Develop reusable security tooling, automation, documentation, and technical guardrails

  • Evaluate third-party technologies, integrations, and vendors for potential security risks

  • Support customer security reviews, enterprise diligence, and technical compliance requirements

  • Help establish security policies and controls aligned with frameworks such as SOC 2, ISO 27001, HIPAA, or PCI DSS

  • Mentor engineers and promote shared ownership of security across the organization


Requirements


  • 5+ years of experience across security engineering, application security, cloud security, infrastructure security, or related disciplines

  • Strong software engineering or systems engineering foundation

  • Proficiency in languages such as Python, Go, Java, JavaScript, TypeScript, or Rust

  • Experience securing cloud-native applications and infrastructure on AWS, GCP, or Azure

  • Knowledge of common application and infrastructure vulnerabilities, attack techniques, and mitigation strategies

  • Experience with threat modeling, secure design reviews, penetration testing, or vulnerability research

  • Familiarity with identity and access management, secrets management, encryption, and network security

  • Experience building security automation and integrating controls into CI/CD pipelines

  • Ability to communicate technical risks and recommendations to engineering teams and business stakeholders

  • Strong judgment around risk prioritization, remediation, and balancing security with execution speed

  • Experience in venture-backed startups, security-sensitive industries, or rapidly scaling technology companies


Core Competencies

Demonstrates expertise in security engineering, application security, and cloud security, with a strong foundation in software engineering. Proficient in threat modeling, vulnerability management, and integrating security controls into development processes.


Highest-signal resume keywords


  • Security Engineering

  • Cloud Security

  • Python Programming

  • Threat Modeling

  • Vulnerability Management


ATS Optimization Keywords

Hard Skills


  • Application Security

  • Infrastructure Security

  • Secure Coding Standards

  • Penetration Testing

  • CI/CD Integration

  • Vulnerability Research

  • Incident Response

  • Security Automation

  • Risk Prioritization

  • Technical Compliance


Soft Skills


  • Communication

  • Judgment

  • Mentoring


Certifications & Qualifications


  • SOC 2

  • ISO 27001

  • HIPAA

  • PCI DSS


Industry Keywords


  • Security Controls

  • Cloud-Native Applications

  • Security Assessments

  • Technical Guardrails

  • Security Policies


Tools & Technologies


  • AWS

  • GCP

  • Azure

  • Identity Management

  • Secrets Management

  • Encryption

  • Network Security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • United States

On-site
USD 140,000 - 190,000
Principal Security Engineer
Principal Security Engineer

Jobtailor • Town of Texas (WI)

On-site
USD 140,000 - 190,000
Chief Information Security Officer – CISO
Chief Information Security Officer – CISO

Jobtailor • Salt Lake City (UT)

On-site
USD 180,000 - 240,000
Senior Security Engineer
Senior Security Engineer

Jobtailor • Colorado

On-site
USD 170,000 - 250,000
Senior Application Security Architect
Senior Application Security Architect

Jobtailor • Cary (NC)

On-site
USD 120,000 - 180,000
Software Engineer – Security
Software Engineer – Security

Jobtailor • California (MO)

On-site
USD 120,000 - 150,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • North Carolina

On-site
USD 110,000 - 170,000
Lead Associate Principal, Adversarial Red Team
Lead Associate Principal, Adversarial Red Team

Jobtailor • United States

On-site
USD 170,000 - 210,000
Director – Security Remediation Operations
Director – Security Remediation Operations

Jobtailor • Arizona

On-site
USD 180,000 - 280,000
Application Security Engineer
Application Security Engineer

Jobtailor • Atlanta (GA)

On-site
USD 120,000 - 160,000