Staff Security Engineer - Enterprise & Third Party Risk Management

LinkedIn

Mountain View (CA)

On-site

USD 156,000 - 255,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

LinkedIn is seeking a Staff Security Engineer focused on Third-Party Technology Security (TPS) to strengthen our security posture against external vendors and integrations. You will design scalable security programs and tooling to automate risk assessments and enforcement across the enterprise.

You will collaborate with GRC, procurement, legal, and security teams, lead incident response, and mentor engineers while driving automation and risk-based decision making.

Qualifications

  • BA/BS degree in Computer Science, Cybersecurity, Information Security, or related field, or equivalent experience.
  • 5+ years leading technical security reviews and risk assessments for third-party tech, SaaS, cloud services, APIs or vendor integrations.
  • 5+ years security engineering with in-depth knowledge in application, cloud, or security architecture domains.
  • Experience with threat modeling, security design reviews, and security governance.
  • Programming experience in Java/Go/Python and building automation to improve workflows.
  • Familiarity with NIST, PCI DSS, SOC 2, ISO 27001 controls.

Responsibilities

  • Establish a foundational TPS assessment framework that automates security requirements into the enterprise security ecosystem.
  • Lead TPS design, implementation, and continuous improvement of processes, controls and workflows.
  • Architect AI-driven automation to accelerate vendor onboarding and provide risk metrics across LinkedIn.
  • Build automation to replace manual GRC tasks using Python or agentic coding tools.
  • Design workflow orchestration across systems including GRC, ticketing, and identity providers.
  • Translate business requirements into scalable security solutions and decision frameworks.
  • Drive program excellence with repeatable processes, SLAs, metrics and reporting.
  • Manage escalations, lead technical reviews, and roadmap high-risk vendors to meet security standards.
  • Act as incident commander during third-party data breaches and coordinate resolution.

Skills

Security engineering
Threat modeling
Python
Automation tooling
Agentic coding tools
Java
Go
Communication skills

Education

BS in Computer Science or related field

Tools

GRC platforms
Ticketing systems
Identity providers
Cloud platforms

Job description

Staff Security Engineer - Enterprise & Third Party Risk Management
  • Full-time
  • Workplace Type: Hybrid

LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We're also committed to providing transformational opportunities for our own employees by investing in their growth. We aspire to create a culture that's built on trust, care, inclusion, and fun – where everyone can succeed.

Join us to transform the way the world works.

At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. The work location of this role is hybrid, meaning it will be performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team.

This role will be hybrid in LinkedIn’s Mountain View office location.

About the Team

LinkedIn's members entrust us with their information every day and we take their security seriously. Our core value of putting our members first powers all the decisions we make, including how we manage and protect the data of our members and customers. Information Security at LinkedIn is dedicated to protecting and securing business-critical member data and company assets. Our core mission is to empower LinkedIn to create a secure and thriving platform for every member of the global workforce.

LinkedIn’s Enterprise & Third-Party Security team is dedicated to protecting our data, systems, and global members by managing security and privacy risks throughout our external ecosystem. We collaborate across the organization to evaluate the security maturity of our partners and suppliers, identifying systemic threats and providing the technical guidance necessary for the secure integration of external services. Our mission is to leverage security engineering, advanced risk analytics, and automation to provide continuous assurance and visibility throughout the third-party lifecycle. We are committed to building scalable, high-impact solutions that mitigate vulnerabilities and ensure all external engagements align with LinkedIn’s rigorous security, privacy, and regulatory standards.

About the Role

As a Staff Security Engineer focused on Third-Party Technology Security (TPS), you will strengthen LinkedIn's security posture by identifying and mitigating security risks introduced by third-party technologies, services, platforms, and integrations.You will be a foundational technical leader driving enterprise security initiatives responsible for evolving the TPS program beyond traditional security governance, risk and compliance programs to an engineering driven program that designs, automates, and scales the controls, workflows and tooling that protect LinkedIn and our customers. The ideal candidate is equally comfortable shaping policy and shipping modern tooling using Python, Claude, and other agentic coding platforms to replace manual GRC work with scalable, code defined workflows. They will partner with enterprise innovation, GRC, procurement, legal, and technical security teams to ensure that third party vendors including complex SaaS/AI tools meet our security standards. You serve as the subject matter expert in transforming security risk management from a compliance oriented function into a security engineering discipline.

Responsibilities:

Establish a foundational framework for third party security (TPS) assessment to automate and integrate security requirements seamlessly into the broader enterprise security ecosystem

Lead and mature the TPS including the design, implementation, and continuous improvement of processes, controls, and operational workflows

Architect AI drive automation to accelerate vendor on boarding velocity and implement a centralized data engine that provides executive level visibility and granular risk metrics across LI

Build and maintain automation that replaces manual GRC tasks like intake, triage, evidence collection, control validation, tracking, escalation, and reporting using either Python or agentic coding tools

Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity provides and cloud control planes

Translate ambiguous business requirements into practical, scalable security solutions and decision frameworks

Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog

Drive program operational excellence by establishing repeatable processes, service level expectations, metrics, and reporting for third party security risk management

Manage complex escalations, act as technical lead for escalations, evaluating edge case architectures and designing technical roadmaps for high risk vendors to ensure they meet LinkedIn’s security standards

Act as lead incident commander within LinkedIn in the event of data security breach of third party and drive successful resolution

Partner with other teams in InfoSec to conduct holistic reviews and engineer “paved path” blueprints for common high risk third party scenarios

Conduct threat modeling on high risk integrations and partner with Security SMEs for deeper diligence

Act as trusted advisor and SME on third party security risk management, helping stakeholders make informed risk based decisions

Provide foundational technical leadership and mentorship to security engineers, driving strategic direction and high impact risk reduction initiatives across the org

Basic Qualifications

BA/BS degree in Computer Science, Cybersecurity, Information Security, or related technical field, or equivalent technical experience

5+ years of experienceleading technical security reviews and risk assessments for third-party technologies, SaaS platforms, cloud services, APIs, enterprise applications, or vendor integrations.

5+ years of experience in security engineering with in-depth knowledge in one or more areas such as application security, cloud security, security architecture, identity and access management, infrastructure security, or software supply-chain security

5+ years of experience with technical security assessment methodologies such as threat modeling, security architecture or security design reviews

Experience with programming languages such as Java, GO, or Python and building automation or tooling to improve security engineering workflows

Experience with industry based information security and controls frameworks like NIST, PCI DSS, SOC 2, and ISO 27001

Preferred Qualifications

BS and 8+ years of relevant work experience, MS and 7+ years of relevant work experience, or PhD and 4+ years of relevant work experience

Experience building or scaling a Third-Party Security, Vendor Security, or Supply Chain Security programs within a large scale technology company

Experience integrating security workflows across GRC platforms, ticketing systems, identity providers, cloud platforms, asset inventories, and vendor management systems.

Experience designing automation that replaces manual security governance, risk management, or compliance processes, including intake, evidence collection, risk assessment, control validation, reporting, and workflow orchestration

Experience building, deploying and reviewing automation for complex security workflows, including use of both AI driven and traditional automation tools

Experience building automation or security tooling that improves assessment coverage, control validation, attack-surface identification, or continuous security monitoring

Demonstrated ability to identify systemic security risks and translate individual security findings into platform-level controls and architectural improvements

Ability to partner with global stakeholders to align technical strategies and security initiatives with broader organizational objectives

Demonstrated ability to influence architecture and engineering decisions across multiple organizations without direct authority

Ability to understand the communicate technical issues to non technical teams

Demonstrated ability to drive projects towards completion

Hands on experience with agentic coding tools

Excellent verbal and written skills

Suggested Skills

Third-Party Security & Vendor Risk Engineering

Security Automation

Security Design Reviews & Threat Modeling

Technical Leadership

You will Benefit from our Culture

We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels.

LinkedIn is committed to fair and equitable compensation practices. The pay range for this role is $156,000 to $255,000. Actual compensation packages are based on a wide array of factors unique to each candidate, including but not limited to skill set, years & depth of experience, certifications and specific office location. This may differ in other locations due to cost of labor considerations.

The total compensation package for this position may also include annual performance bonus, stock, benefits and/or other applicable incentive compensation plans. For additional information, visit: https://careers.linkedin.com/benefits.

Equal Opportunity Statement

We seek candidates with a wide range of perspectives and backgrounds and we are proud to be an equal opportunity employer. LinkedIn considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

LinkedIn is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. Our goal is to foster an inclusive and accessible workplace where everyone has the opportunity to be successful.

If you need a Reasonable Accommodation to search for a job opening, apply for a position, or participate in the interview process, connect with us and describe the specific Accommodation requested for a disability-related limitation.
Fill out an Accommodation request here: https://app.smartsheet.com/b/form/b660a0327d044969abfd7a4e73d15c36

Reasonable accommodations are modifications or adjustments to the application or hiring process that would enable you to fully participate in that process. Examples of reasonable accommodations include but are not limited to:

  • Documents in alternate formats or read aloud to you
  • Having interviews in an accessible location
  • Being accompanied by a service dog
  • Having a sign language interpreter present for the interview

A request for an accommodation will be responded to within three business days. However, non-disability related requests, such as following up on an application, will not receive a response.

LinkedIn will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by LinkedIn, or (c) consistent with LinkedIn's legal duty to furnish information.

San Francisco Fair Chance Ordinance

Pursuant to the San Francisco Fair Chance Ordinance, LinkedIn will consider for employment qualified applicants with arrest and conviction records.

Pay Transparency Policy Statement

As a federal contractor, LinkedIn follows the Pay Transparency and non-discrimination provisions described at this link: https://lnkd.in/paytransparency.

Global Data Privacy Notice and Compliance Posters for Job Candidates

Please use this link to access documents that provide information about how LinkedIn handles the personal data of employees and job applicants, as well as the E-Verify Participation Notice and the Department of Justice Immigrant and Employee Rights Section Right to Work posters: https://www.linkedin.com/legal/candidate-portal.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineering Manager, Information Security
Engineering Manager, Information Security

LinkedIn • California (MO)

Hybrid
USD 156,000 - 255,000
Bonus potential
Stock options
Benefits
Staff Information Security Engineer - Detection Engineering
Staff Information Security Engineer - Detection Engineering

LinkedIn • Mountain View (CA)

Hybrid
USD 156,000 - 255,000
Health and wellness programs
Annual performance bonus
Stock options
+1
Staff Security Engineer - Identity & Access Management
Staff Security Engineer - Identity & Access Management

LinkedIn • Mountain View (CA)

Hybrid
USD 156,000 - 255,000
Staff Software Engineer
Staff Software Engineer

LinkedIn • Mountain View (CA)

Hybrid
USD 152,000 - 248,000
Senior Staff Software Engineer, Risk and Compliance Infrastructure & Data Science
Senior Staff Software Engineer, Risk and Compliance Infrastructure & Data Science

LinkedIn • Mountain View (CA)

Hybrid
USD 181,000 - 297,000
Generous health and wellness programs
Time off for employees of all levels
Principal Staff Software Engineer, Regulatory & Compliance
Principal Staff Software Engineer, Regulatory & Compliance

LinkedIn • Mountain View (CA)

Hybrid
USD 215,000 - 352,000
Health and wellness programs
Competitive compensation
Stock and incentive plans
Sr. Technical Investigator, Trust Investigations Account Security
Sr. Technical Investigator, Trust Investigations Account Security

LinkedIn • California (MO)

Hybrid
USD 136,000 - 221,000
Health and wellness programs
Time off / generous leave
Engineering Director - Information Security
Engineering Director - Information Security

LinkedIn • Sunnyvale (CA)

Hybrid
USD 209,000 - 343,000
Competitive salary
Annual performance bonus
Stock options
+1
Senior Software Engineer - Applications
Senior Software Engineer - Applications

LinkedIn • California (MO)

Hybrid
USD 129,000 - 212,000
Stock options
Benefits
Performance bonus
Senior Software Engineer - Systems and Infrastructure
Senior Software Engineer - Systems and Infrastructure

LinkedIn • Mountain View (CA)

Hybrid
USD 144,000 - 236,000