Senior Security Automation Engineer

Beyond Finance

Chicago (IL)

On-site

USD 160,000 - 195,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, dental, and vision coverage
Generous PTO and paid holidays
401(k) matching

Job summary

Beyond Finance is seeking a Staff Security Engineer to design and implement automated security controls, logging pipelines, and SIEM integrations in a fast-growing environment. You will own tooling that scales security across cloud and on‑prem resources while writing custom Python code and building reusable IaC modules.

You will work hands‑on across AWS, SIEM, endpoints, CI/CD, and infrastructure repos, delivering secure defaults and self‑service capabilities for the security team.

Qualifications

  • 8+ years of hands-on security engineering with a focus on automation, tooling, and instrumentation.
  • Proficient in Python to build your own tooling and log pipelines.
  • Hands-on experience building and operating log pipelines end to end: collection, parsing, enrichment, and delivery to a SIEM.
  • Hands-on SIEM experience: onboarding sources and building or tuning detections and alerts.
  • Experience deploying and managing endpoint security across macOS and Windows workstations, including virtual desktops.
  • Hands-on Infrastructure as Code experience; Terraform required.
  • Experience building CI/CD pipelines and wiring security checks into them.
  • Working knowledge of a major cloud provider, ideally AWS.
  • Operates independently and drives projects without day-to-day oversight.

Responsibilities

  • Build and own our security log pipelines: extract logs, transform and enrich, land in SIEM for detection and investigation.
  • Operate and tune our SIEM: onboard sources, build detections and alerts.
  • Deploy and tune security controls across endpoints and AWS WorkSpaces desktops.
  • Build internal tooling and automation in Python to reduce toil.
  • Instrument environment by integrating tooling through APIs and connecting stack components.
  • Establish secure defaults in IaC via reusable modules and policy as code.
  • Build security into CI/CD: scanning, secrets detection, and policy gates.
  • Treat pipelines and tooling as a platform you own and maintain reliability.
  • Work directly in systems you don’t own; make safe changes and drive fixes.

Skills

Python scripting
Security automation
Log pipelines
Independent work
AWS familiarity

Tools

Terraform
CI/CD tooling
GitHub Advanced Security
SIEM tooling

Job description

At Beyond Finance, we've made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care,a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions, we've helped over 1 million clients on their path to a brighter future.

While we're proud of what we've already accomplished, we're searching for new collaborators to help us get to the next level! If you're looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.

The Role

As a Staff Security Engineer, you'll build and deploy the controls, automation, and log pipelines that let a lean security team cover a large and growing surface. Much of the role is hands‑on: standing up controls, wiring up tooling, and building the internal tooling that makes the team and our processes better. When the work calls for custom code, you write it yourself rather than waiting on someone else.

You’ll sit inside security engineering and work hands‑on across our AWS environment, our SIEM, our endpoint fleet, our CI/CD systems, and our application and infrastructure repos. Where a lot of security teams find a problem and hand off a ticket, we implement the fix ourselves, and this person is a big part of how we do that at scale.

Key Responsibilities
  • Build and own our security log pipelines: get logs out of the systems that produce them, transform and enrich them, and land them in our SIEM where the team can detect and investigate. This is a large part of the role.
  • Operate and improve our SIEM: onboard new sources, and build and tune the detections and alerts the team runs on.
  • Deploy and tune security controls across our endpoint fleet of managed macOS and Windows workstations and AWS WorkSpaces virtual desktops running Windows Server.
  • Build internal tooling and automation that makes the team and our processes better, from removing manual toil in triage and remediation to giving the team capabilities it doesn't have today. When it calls for custom code, it's primarily Python.
  • Instrument our environment for security signal by integrating our tooling through their APIs and writing the connective code that ties the stack together.
  • Establish secure defaults in our Infrastructure as Code through reusable modules and policy as code.
  • Build security into CI/CD: scanning, secrets detection, and policy‑as‑code gates that live in the developer workflow.
  • Treat the pipelines and tooling you build as a platform you own, including their reliability and coverage.
  • Work directly in systems your team does not own: read the code or infra, make the change safely, and get it through review rather than filing a ticket.
Requirements
  • 8+ years of hands‑on security engineering with a focus on automation, tooling, and instrumentation.
  • Comfortable writing custom code and scripting, primarily in Python, to build your own tooling and log pipelines from scratch. You do not have to be a career software engineer, but you are well past copy‑and‑paste.
  • Hands‑on experience building and operating log pipelines end to end: collection, parsing, enrichment, and delivery into a SIEM.
  • Hands‑on SIEM experience: onboarding sources and building or tuning detections and alerts.
  • Experience deploying and managing endpoint security across a mixed fleet of macOS and Windows workstations, including virtual desktops.
  • Hands‑on Infrastructure as Code experience; Terraform required.
  • Experience building CI/CD pipelines and wiring security checks into them.
  • Working knowledge of a major cloud provider, ideally AWS.
  • Operates independently and drives projects without day‑to‑day oversight.
Nice to Have
  • A background in Cloud Security or Application Security to build on from a more automation‑focused seat.
  • Experience with our stack: Wiz, Cloudflare, GitHub Advanced Security, Spacelift, and AWS‑native services.
  • Policy as code experience such as OPA/Rego or Sentinel.
  • Experience with a SIEM or log platform as a pipeline destination.
  • AI/ML security exposure: prompt injection, data poisoning, model abuse, and the controls that mitigate them.
  • PCI‑regulated or financial services environment.
  • Familiarity with Ruby on Rails, Python, or Go.
The Ideal Candidate

The ideal candidate is a Driver, not a Passenger. They take an ambiguous problem, find the biggest‑impact piece, and start building rather than waiting for a fully specified ticket, and they would rather ship 60% this week and iterate to the rest than spend a quarter on the perfect design. Automating a problem is their first move, and when the fix lives in someone else’s system they go make it rather than recommend it. They catch a fragile pipeline or a bad design before it ships, not just the ones they built themselves.

#LI-LB2

The base annual salary range is listed below. This role is eligible for additional incentives, including an annual bonus.

Base Salary Range

$160,000 - $195,000 USD

Why Join Us?

While you make a difference for others, we’ll work to make a difference for you, providing an uplifting, collaborative work environment and benefits that reflect your value to us. For eligible full‑time employees, we offer:

  • Considerable employer contributions for health, dental, and vision programs
  • Generous PTO, paid holidays, and paid parental leave
  • 401(k) matching program

And finally, our team spirit and culture! We cultivate an environment of community, connection, and belonging across our entire organization.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer
Staff Security Engineer

Beyond Finance • United States

On-site
USD 160,000 - 195,000
Health, dental, and vision program
Generous PTO and paid holidays
401(k) matching program
+2
Detection & Response Engineering Manager
Detection & Response Engineering Manager

Beyondfinance • Chicago (IL)

On-site
USD 150,000 - 180,000
Health/dental/vision
PTO & holidays
Parental leave
+2
Senior Security Automation Engineer
Senior Security Automation Engineer

Beyond Finance • Chicago (IL)

On-site
USD 160,000 - 195,000
Health, dental, and vision coverage
Generous PTO and paid holidays
401(k) matching
Senior Corporate Security Engineer
Senior Corporate Security Engineer

United States Digital Space LLC • Bellevue (CA)

Hybrid
USD 166,000 - 195,000
Health insurance
Equity ownership
401(k) matching
+2
Senior Security Engineer
Senior Security Engineer

Silversmith Capital Partners • United States

Hybrid
USD 126,000 - 154,000
HDHP + telehealth
Calm subscription
LinkedIn Learning
+3
Senior Security Engineer – Hybrid (4649)
Senior Security Engineer – Hybrid (4649)

Hireclout • Los Angeles (CA)

On-site
USD 180,000 - 200,000
Competitive compensation package
Equity participation
100% covered medical, dental, and vision coverage
+5
Software Engineer, Proactive Capabilities
Software Engineer, Proactive Capabilities

United States Digital Space LLC • Bellevue (CA)

Hybrid
USD 166,000 - 195,000
Equity ownership
401(k) matching
Health insurance (employee)
Staff Application Security Engineer
Staff Application Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 240,000 - 300,000
Up to four weeks of fully remote work per year
Staff Security Engineer
Staff Security Engineer

Forward Financing • United States

Hybrid
USD 160,000 - 200,000
Security Automation Lead
Security Automation Lead

Point72 Asset Management, L.P • New York (NY)

On-site
USD 250,000 - 350,000
Fully-paid health care benefits
Generous parental leave policies
Tuition assistance
+1