Remote Jobs RockRemote Jobs Rock

Senior Staff Security Engineer

🕒 8 days ago
AWSGCPCloud SecurityNetwork Security

📜 Description

  • 6+ years of relevant experience
  • Candidates must demonstrate proficiency in cloud security, network security, URL filtering, common security frameworks, and CVE lifecycle management
  • Practical IaC and scripting for automation
  • Strong cross-functional and external communication
  • Experience mentoring junior staff
  • Hands-on cloud security for AWS and GCP: design secure architectures, perform threat modeling, apply platform-native controls, and build and validate secure IaC.

🛠️ Requirements

  • Hands-on cloud security for AWS and GCP: design secure architectures, perform threat modeling, apply platform-native controls, and build and validate secure IaC.
  • SIEM ownership and detection engineering: deploy, configure, tune, and maintain SIEM; author and test detection rules and playbooks; integrate data sources; and operate with SLA-driven alerting and incident workflows.
  • Vulnerability and incident lifecycle ownership: identify, triage, and remediate infrastructure and web vulnerabilities.
  • Drive CVE lifecycle management and patching: perform root cause analysis and measure MTTR and remediation rates.
  • Network, web, and endpoint protections: design and manage firewalls, WAFs, cloud network controls, URL and web filtering, with demonstrable operational experience.
  • Secure automation and tooling: author automation for detection, alert enrichment, and remediation; build or extend security tooling using scripting or languages such as Python, Go, or Bash.
  • Infrastructure as code and secure CI pipelines: implement guardrails and policy-as-code in CI/CD pipelines, perform static IaC scanning, and enforce security baselines before deployment.
  • Detection, telemetry, and observability: define logging and telemetry requirements, ensure coverage for critical assets, and validate detection efficacy and alert fidelity.
  • Security standards, playbooks, and enforcement: develop, document, and operationalise organisation-wide security standards, runbooks, and playbooks; partner with engineering teams to drive adoption.
  • Threat-informed defensive engineering: apply threat modeling and adversary-focused testing to guide controls, detection, and resilient designs.

Benefits

  • The Employee Assistance Program -- with counselors -- is available for non-work-related challenges.*
  • Subscription to Calm - sleep and meditation app.*
  • We organize ‘DisConnect’ days where Bloomreachers globally enjoy one additional day off each quarter, allowing us to unwind together and focus on activities away from the screen with our loved ones.
  • We facilitate sports
  • Meditation opportunities for each other
  • Extended parental leave up to 26 calendar weeks for Primary Caregivers.*
Sentilink

Principal Information Security Engineer

Sentilink👥 51 - 200 employees🏢 Computer Software
📅 May 28

You will partner closely with Engineering, Infrastructure, Product, Legal, and Compliance teams to design secure systems, improve detection and response capabilities, strengthen cloud security posture, and reduce organizational risk.

Security EngineeringSoftware EngineeringAWSGo
📅 Mar 25

As a principal engineer, you will set technical direction and drive execution on high-impact infrastructure security programs, partnering across various orgs at OpenAI to deliver durable controls that raise the security bar at OpenAI scale.

Security PrinciplesCloud SecurityAWSAzure
Pipedrive

Principal Security Engineer

Pipedrive👥 501 - 1000 employees🏢 Computer Software
📅 May 4

We’re looking for a Principal Security Engineer to join Pipedrive as a technical builder responsible for engineering the security architecture of our SaaS platform, corporate operations and the tools and methods the security team will use.

Security EngineeringCloud SecuritySecurity ArchitectureSaaS

Trusted by Remote Workers