Source Job

Europe

  • Participate in threat modeling exercises with engineering team members
  • Triage SCA/SAST/DAST/CSPM findings by eliminating false positives and providing well-vetted vulnerabilities to engineering teams
  • Support vulnerability management efforts for networks and infrastructure

Python AWS Linux Docker Terraform

20 jobs similar to Information Security Engineer

Jobs ranked by similarity.

Canada

  • Help scale NerdWallet’s application security program through automation, tooling, and developer enablement.
  • Partner with engineering and product teams to identify and remediate security gaps across multiple systems while balancing business priorities.
  • Build tools, processes, and automation that improve security posture visibility for engineers and leadership.

NerdWallet aims to bring clarity to life's financial decisions with a team of exceptional Nerds. They foster an inclusive, flexible, and candid culture where employees are empowered to grow and take risks, supporting well-being and development whether working remotely or in-office.

$106,500–$202,500/yr
US

  • Implementing and maintaining Application Security Testing (AST) tools to identify code and dependency vulnerabilities during the software development lifecycle.
  • Implementing and maintaining Application Security Posture Management (ASPM) tools to centralize findings from multiple solutions and integrate into software development processes.
  • Acting as the first line of support for users by helping resolve false positives, providing guidance on finding remediation, and evaluating security exception requests.

AbbVie discovers and delivers innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. They strive to have a remarkable impact on people's lives across several key therapeutic areas and products and services in their Allergan Aesthetics portfolio.

US

  • Assist in designing and maintaining secure infrastructure on EKS in our multi-cloud environment (AWS) using Infrastructure as Code (Terraform).
  • Write code (Python, Go, or Bash) to automate manual tasks, threat detection, and vulnerability management processes.
  • Integrate security tools (SAST, DAST, SCA) into our CI/CD pipelines, ensuring developers receive fast, actionable feedback on their code.

Smartsheet helps people and teams achieve anything with seamless work management and scalable solutions. They empower teams to automate the manual, uncover insights, and scale smarter, creating space for impactful work. The company values diverse perspectives and supports employee growth.

$101,405–$140,400/yr
US Unlimited PTO

  • Analyze security vulnerabilities and drive remediations.
  • Integrate security at every stage of the SDLC.
  • Deploy and manage security tooling.

Modern Health is a mental health benefits platform for employers, offering access to various resources for emotional, professional, social, financial, and physical well-being. They are the fastest entirely female-founded company in the U.S. to reach Unicorn status, with a unique culture centered around high empathy and accountability.

Global

  • Lead Application Security testing projects and drive remediation of identified vulnerabilities.
  • Design and run adversarial testing campaigns across the full Buildkite environment.
  • Build automation for both AppSec and adversarial testing workflows.

Buildkite's mission is to unblock every developer on the planet with their CI/CD platform. They are a remote-first company since 2013 with a small team, high standards, and real ownership distributed across 60+ cities, built around async communication and genuine autonomy.

US Canada Ireland UK Mexico Argentina

  • Perform infrastructure security reviews across cloud services, network design, IAM, and platform components.
  • Design and build internal security services, APIs, and tools that automate infrastructure vulnerability detection, triage, reporting, and remediation.
  • Develop security automation that integrates with CI/CD, cloud control planes, and developer workflows to shift detection and remediation earlier in the lifecycle.

Webflow is building the world’s leading AI-native Digital Experience Platform as a remote-first company. They empower teams to design, launch, and optimize for the web without barriers, from entrepreneurs to global enterprises, and believe the future of the web, and work, is more open, more creative, and more equitable.

US Unlimited PTO

  • Focus on automation, integrating security within the CI/CD pipeline, and DevOps toolchain.
  • Strong working knowledge of security fundamentals including OWASP Top10.
  • Experience with public cloud infrastructure (AWS or Azure) and cloud security fundamentals.

GuidePoint Security provides cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. They have grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serve as a trusted advisor to more than 6,200 customers.

$110,000–$120,000/yr
US Unlimited PTO 11w maternity 6w paternity

  • Design, implement, and manage application and cloud security tooling across AWS.
  • Lead the deployment and configuration of Wiz CSPM, collaborating with infrastructure and DevOps teams.
  • Manage secure code scanning processes, integrating SAST and DAST to identify and remediate vulnerabilities early in the SDLC.

Twin Health aims to empower people to improve and prevent chronic metabolic diseases with AI Digital Twin technology. It is recognized for innovation and culture, with recent funding to scale rapidly across the U.S. and globally.

$130,000–$185,000/yr
US

  • Work with development and product teams on security.
  • Review code and make decisions about secure coding.
  • Code solutions for preventative measures and alerts.

BetterHelp is the world’s largest online therapy service, providing affordable and convenient therapy across the globe. The company's network of over 30,000 licensed therapists has helped millions of people take ownership of their mental health. As a mental health company, they deeply invest in their team’s well-being and professional development.

$140,000–$150,000/yr
US Global

  • Partner with engineering teams to conduct threat modeling.
  • Build and maintain automated scanning, penetration testing frameworks, and monitoring tools within our AWS CI/CD pipelines.
  • Champion a "security-first" mindset and host workshops that empower developers to write secure code.

Panopto is a customer-centric learning technology company and the leader in visual and audio-based learning. They empower organizations to share knowledge effortlessly. Panopto has been adopted by more than 1,600 companies and universities worldwide with over 11 million end users.

US Unlimited PTO

  • Lead security architecture and design reviews across applications, infrastructure, and integrations.
  • Conduct and coordinate penetration testing, threat modeling, and security reviews.
  • Design and implement security automation within CI/CD pipelines.

Assured modernizes insurance by providing software solutions to large insurers that help them win in a technology-driven world. Their products include self-service claim-filing software to backend fraud detection and are dynamic, collaborative, and rewarding.

Europe

  • Collaborate closely with DevOps, CI/CD engineers, and Architecture team to implement and maintain security best practices across our infrastructure.
  • Leverage your expertise in security architecture to help engineers build and securely operate products and services from the ground up.
  • Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements

LastPass is a leader in password and identity management, making it easier to log into life and work. Trusted by 100,000 businesses and millions of users, LastPass combines advanced security with effortless access for individuals, families, small business owners, and enterprise professionals.

US 4w PTO

  • Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities
  • Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders
  • Leading and enhancing incident / issues response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues

Aledade, a public benefit corporation, empowers independent primary care practices. Founded in 2014, they've become the largest network of independent primary care in the country with a collaborative, inclusive and remote-first culture.

Europe

  • Improve AWS security configurations.
  • Manage and maintain security tools.
  • Perform vulnerability management and coordinate patching.

Swapcard is the leading AI-powered event platform designed to drive revenue growth and foster meaningful connections at in-person and hybrid events. With 42 nationalities represented among their 180+ team members, they champion diversity as a catalyst for creativity, collaboration, and unparalleled innovation.

Global

  • Design and implement security controls across cloud infrastructure, applications, and data systems.
  • Identify, assess, and mitigate security risks through threat modeling, reviews, and testing.
  • Build and maintain monitoring, alerting, and incident response capabilities.

BlockchainUnmasked aims to streamline cryptocurrency forensic investigations through advanced automation combined with cutting-edge solutions. They work with investigative partners to dramatically accelerate investigation times and boost success rates in interdiction, recovery, and deterrence.

Europe

  • Drive adoption of a Secure Software Development Lifecycle (SSDLC) across engineering teams.
  • Implement and integrate application security tooling into CI/CD pipelines, improving vulnerability detection and remediation.
  • Establish consistent threat modelling and secure design practices across new features and products.

Neko Health's mission is to deliver proactive healthcare for all, empowering members to take control of their health via technology and compassionate care. They have nearly 100 full-time engineers working across Berlin, Chamonix, Hamburg, Lisbon, Marseille, Vilnius, and Stockholm and they support a flexible workplace that prioritizes work-life balance.

US Unlimited PTO

  • Conducting a comprehensive threat model of our application and infrastructure layers.
  • Hardening our AWS infrastructure while keeping developer workflows frictionless.
  • Integrating security tooling into our CI/CD pipeline.

Loancrate simplifies home-buying for lenders and borrowers by building AI-native tooling to automate mortgage workflows. Since 2020, their remote team has enabled customers to power >$85 billion in new home loans and they value collaboration and open communication.

$215,000–$230,000/yr
US

  • Lead application security reviews and threat modeling.
  • Develop automated testing and mature our Secure SDLC.
  • Own and perform application security vulnerability management.

TRM Labs provides blockchain analytics and AI solutions to help law enforcement, national security agencies, financial institutions, and cryptocurrency businesses detect and disrupt crypto-related fraud and financial crime. They are a Series C company with $220M in funding and operate as a distributed-first company.

$117,000–$130,000/yr
US

  • Build proactive security automation aimed at decreasing manual remediation work.
  • Research new and novel ways to accomplish security work and publish your findings on our blog.
  • Participate in a monthly security on-call rotation for critical escalations.

Automox is a cloud-native IT operations platform that helps modern organizations keep every endpoint automatically configured, patched, and secured – anywhere in the world. They are trusted by more than 2,500 leading companies and MSPs worldwide and value a ‘one team’ mentality where everyone’s unique skills contribute to an environment that encourages collaboration and ownership.

Global

  • Integrate security activities across all SDLC phases.
  • Partner closely with engineering teams to ensure secure development practices.
  • Review security controls for new features, services, and architectural changes.

Infiterra simplifies subscription service delivery, enabling IT distributors, Managed Service Providers (MSPs), and telcos to succeed in the subscription economy. They are recognized as a global leader in subscription commerce, combining innovation, performance excellence, and trusted expertise to help partners transform and grow.