Source Job

$170,000–$230,000/yr
US

  • Build secure-by-default infrastructure and automation to eliminate entire vulnerability classes across money-moving systems.
  • Own application security, threat modeling, and vulnerability disclosure from design review to production.
  • Partner with engineering to set security standards, make risk-based decisions, and ship fast without compromising safety.

Software Engineering Security Threat Modeling Terraform

20 jobs similar to Senior Software Engineer, Security

Jobs ranked by similarity.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.

$120,000–$140,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
  • Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
  • Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.

GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.

$138,677–$182,296/yr
US

  • Integrate security into the SDLC through automation, testing, and continuous improvement.
  • Identify, investigate, and remediate application and infrastructure vulnerabilities.
  • Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.

Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.

$172,279–$249,640/yr
US Canada

  • Partner with engineering teams to review cloud and compute architecture design changes.
  • Establish threat models for cloud and compute paved roads to identify security risks.
  • Write code for automations that support security requirements like threat detection and incident containment.

Quora operates two platforms: a global knowledge sharing platform with over 300 million monthly unique visitors, and Poe, a platform for AI language models. The company is remote-first with a culture rooted in transparency, idea-sharing, and experimentation.

$180,000–$210,000/yr
US Canada Unlimited PTO 12w maternity 12w paternity

  • Threat model new product features and integrations, hardening systems with effective controls.
  • Operate and evolve the application security toolchain, keeping it high-signal for developers.
  • Own day-to-day security operations across the detection stack, triaging and resolving incidents.

Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.

Canada Unlimited PTO

  • Own cloud and platform security end to end across AWS and Azure, including architecture, detection, and response.
  • Build self-serve security tooling and guardrails to replace manual processes and reduce risk.
  • Partner with engineering teams to embed security into CI/CD pipelines and product development.

Ada is an AI customer service platform that enables enterprise companies to deliver instant, proactive, and personalized customer experiences. Established in 2016, the Canadian company has powered over 5.5 billion interactions for brands like Square and YETI, backed by over $250M in funding from top-tier investors.

$160,000–$195,000/yr

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
  • Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
  • Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.

Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.

US Unlimited PTO

  • Build and maintain security infrastructure across AWS and Kubernetes, including telemetry pipelines, cryptographic material lifecycle, and compliance automation.
  • Engineer agentic AI workflows using tools like Claude Code and MCP integrations to automate security tasks such as code review and drift detection.
  • Develop threat models and embed security controls into deployment pipelines to prevent vulnerabilities at build time.

Lumin Digital provides cloud-native digital banking solutions for credit unions and banks. The company fosters a culture of trust, respect, and boldness, encouraging innovation and collaboration in a fully remote, async-first environment.

US

  • Own threat modeling and secure code reviews for new products and features.
  • Maintain and tune AppSec tooling, and run the bug bounty program.
  • Design and evolve the secure SDLC, and partner with engineering teams to implement secure-by-default patterns.

Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. The company operates at the intersection of traditional finance and on-chain systems, with a focus on security and innovation.

Canada Unlimited PTO

  • Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
  • Partner with engineering to embed security controls into production.
  • Lead vulnerability management and incident response activities.

Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.

Global

  • Act as the primary security partner for the Walrus team, providing architectural guidance and embedding security practices throughout the development lifecycle.
  • Lead security assessments for new features and contribute to ecosystem-wide security initiatives, identifying systemic risks and actionable remediation plans.
  • Drive a security-by-design culture, leveraging AI and automation to focus on high-impact, complex security research and mentor engineers.

Mysten Labs builds foundational infrastructure to accelerate the adoption of decentralized protocols based on blockchain technologies. They are a well-funded, remote-first team with over $300M in Series B funding from top venture firms, fostering a culture of innovation and growth.

$250,000–$330,000/yr
Americas

  • Own Tremendous' security posture end-to-end, partnering with our engineering team on production infrastructure and code security.
  • Assess where we have gaps, prioritize them, and tackle our highest-leverage gaps first.
  • Treat incident response as core, not afterthought.

Tremendous is a global platform for businesses to send payouts like gift cards and money to anyone, anywhere, instantly. Trusted by 20,000+ organizations, they are profitable and fully remote with a high-documentation, low-meeting culture and an employee NPS in the high 80s.

Global

  • Own production security across a multi-cloud footprint (AWS, GCP, Azure, Vercel) and secure multi-tenant SaaS, dedicated VPC, and air-gapped deployments.
  • Secure the Hermes Agent platform with sandboxing, kernel-level isolation, and agent identity controls, and lead SOC 2 compliance.
  • Harden identity management, vulnerability management, incident response, and secure software development lifecycle practices.

Nous Research builds open-source AI language models and agents, including Hermes Agent, used by consumers and Fortune 500 enterprises across various deployment environments. The company is a fast-growing startup with a high-velocity, open-source-native engineering culture that values security and pragmatism.

$129,500–$144,300/yr
Canada Unlimited PTO

  • Lead security architecture across AWS and colocation, defining secure patterns and controls.
  • Partner with engineering teams to threat model, review designs, and promote secure-by-design.
  • Develop automated security tooling and guardrails using infrastructure-as-code and AI-assisted workflows.

NMI enables partners with choice, challenging the one-size-fits-all approach to payments. We're a global company with a remote-first culture, fostering diversity and inclusion through initiatives like affinity groups and DEI action teams.

Canada Unlimited PTO 18w maternity 12w paternity

  • Build and harden secure CI/CD pipelines with security gates to catch issues before production.
  • Lead security architecture reviews and threat models for Kubernetes-based workloads on GCP and AWS.
  • Harden container images, Kubernetes configurations, and cloud IAM to minimize attack surface.

Chainguard is the trusted source for open source, delivering hardened, secure, and production-ready builds of open source software. The company is venture-backed by leading investors and serves Fortune 500 enterprises, with a culture that values customer obsession, intentional action, and trust.

Germany

  • Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
  • Build automation, policy-as-code, and security tooling to enable development teams to shift left and integrate security into workflows.
  • Design and implement secure baselines for cloud resources and Kubernetes-based infrastructure, and drive vulnerability management efforts.

Wiz is a cloud security company enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime. As one of the fastest-growing startups, trusted by over 65% of the Fortune 100, Wiz values world-class talent and creativity.

$110,000–$160,000/yr
North America

  • Own identity and access management across Later’s platform, including authentication, authorization, and secure machine-to-machine processes.
  • Design, implement, and maintain secure authentication systems for both internal tools and customer-facing experiences.
  • Partner with engineering teams to identify vulnerabilities, clearly communicate risk and impact, and drive effective remediation.

Later is the world’s most intelligent influencer marketing company, built to give brands the confidence to create unforgettable campaigns. Trusted by leading enterprise brands including Nike, Wayfair, Unilever, and Southwest Airlines, Later is a mid-to-large company with a culture of inclusion and innovation.

$88,800–$125,800/yr
Canada 3w PTO 12w maternity 12w paternity

  • Proactively identify and drive security improvements across the product and platform.
  • Partner with engineering teams to threat model new features and review designs early in development.
  • Build and improve security tooling, libraries, and workflows to make secure development the default path.

Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.

$105,000–$123,000/yr
US Unlimited PTO 18w maternity 12w paternity

  • Operate and sustain Chainguard’s technology platforms (cloud, IAM, and AI) and help implement access controls and identity policies.
  • Support the hardening and monitoring of cloud infrastructure, assist in securing AI/ML pipelines, and troubleshoot systems.
  • Document processes, contribute to runbooks, and adapt to shifting priorities while learning security best practices.

Chainguard delivers hardened, secure, and production-ready builds of open source software. It is a venture-backed late-stage startup with Fortune 500 customers including Anduril, Canva, and OpenAI.