Source Job

US Unlimited PTO

  • Lead security architecture and design reviews across applications, infrastructure, and integrations.
  • Conduct and coordinate penetration testing, threat modeling, and security reviews.
  • Design and implement security automation within CI/CD pipelines.

AWS Security Python Typescript DevSecOps

20 jobs similar to Staff Security Engineer

Jobs ranked by similarity.

US Canada Ireland UK Mexico Argentina

  • Perform infrastructure security reviews across cloud services, network design, IAM, and platform components.
  • Design and build internal security services, APIs, and tools that automate infrastructure vulnerability detection, triage, reporting, and remediation.
  • Develop security automation that integrates with CI/CD, cloud control planes, and developer workflows to shift detection and remediation earlier in the lifecycle.

Webflow is building the world’s leading AI-native Digital Experience Platform as a remote-first company. They empower teams to design, launch, and optimize for the web without barriers, from entrepreneurs to global enterprises, and believe the future of the web, and work, is more open, more creative, and more equitable.

Global

  • Design and implement security controls across cloud infrastructure, applications, and data systems.
  • Identify, assess, and mitigate security risks through threat modeling, reviews, and testing.
  • Build and maintain monitoring, alerting, and incident response capabilities.

BlockchainUnmasked aims to streamline cryptocurrency forensic investigations through advanced automation combined with cutting-edge solutions. They work with investigative partners to dramatically accelerate investigation times and boost success rates in interdiction, recovery, and deterrence.

$140,000–$150,000/yr
US Global

  • Partner with engineering teams to conduct threat modeling.
  • Build and maintain automated scanning, penetration testing frameworks, and monitoring tools within our AWS CI/CD pipelines.
  • Champion a "security-first" mindset and host workshops that empower developers to write secure code.

Panopto is a customer-centric learning technology company and the leader in visual and audio-based learning. They empower organizations to share knowledge effortlessly. Panopto has been adopted by more than 1,600 companies and universities worldwide with over 11 million end users.

US

  • Design, develop, and implement cloud-based infrastructure and programs.
  • Analyze and identify potential security threats and assess risks.
  • Partner with architects, engineers, and data scientists to develop and implement cloud security strategies.

Sift Healthcare is a data science company working to improve payments operations and outcomes in the healthcare industry. They are a growing and dynamic team based in Milwaukee, Wisconsin, that is serious about AI and thriving, looking for motivated team members who will help shape their culture.

$153,986–$192,482/yr
US

  • Design, develop, and implement cloud security architecture solutions in Microsoft Azure.
  • Build and maintain security automation using Infrastructure as Code (IaC) tools.
  • Collaborate with development and platform engineering teams to embed security into CI/CD pipelines.

Hanger, Inc. is the world's premier provider of orthotic and prosthetic (O&P) services and products, offering the most advanced O&P solutions, clinically differentiated programs and unsurpassed customer service. With 160 years of clinical excellence and innovation, Hanger's vision is to lead the orthotic and prosthetic markets by providing superior patient care, outcomes, services and value.

US Unlimited PTO

  • Focus on automation, integrating security within the CI/CD pipeline, and DevOps toolchain.
  • Strong working knowledge of security fundamentals including OWASP Top10.
  • Experience with public cloud infrastructure (AWS or Azure) and cloud security fundamentals.

GuidePoint Security provides cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. They have grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serve as a trusted advisor to more than 6,200 customers.

$110,000–$120,000/yr
US Unlimited PTO 11w maternity 6w paternity

  • Design, implement, and manage application and cloud security tooling across AWS.
  • Lead the deployment and configuration of Wiz CSPM, collaborating with infrastructure and DevOps teams.
  • Manage secure code scanning processes, integrating SAST and DAST to identify and remediate vulnerabilities early in the SDLC.

Twin Health aims to empower people to improve and prevent chronic metabolic diseases with AI Digital Twin technology. It is recognized for innovation and culture, with recent funding to scale rapidly across the U.S. and globally.

US

  • Design and implement security controls across cloud, infrastructure, and internal platforms
  • Partner with engineering to harden cloud architecture, IAM, and infrastructure
  • Own product security reviews for new features, services, and major architecture changes

XBOW is redefining the future of cybersecurity by building the world's first autonomous pentester, powered by AI. They are backed by Sequoia Capital and Altimeter, and a team that includes the creators of GitHub Copilot and GitHub Advanced Security.

US

  • Design and implement cloud security guardrails across AWS and GCP
  • Embed policy enforcement and compliance checks directly into Terraform modules
  • Conduct architecture reviews and continuously harden multi-cloud environments

Beast Industries is a multifaceted media and entertainment company founded by Jimmy Donaldson, popularly known as MrBeast. We are known for revolutionizing digital content creation, encompassing ventures that extend far beyond YouTube.

US

  • Assist in designing and maintaining secure infrastructure on EKS in our multi-cloud environment (AWS) using Infrastructure as Code (Terraform).
  • Write code (Python, Go, or Bash) to automate manual tasks, threat detection, and vulnerability management processes.
  • Integrate security tools (SAST, DAST, SCA) into our CI/CD pipelines, ensuring developers receive fast, actionable feedback on their code.

Smartsheet helps people and teams achieve anything with seamless work management and scalable solutions. They empower teams to automate the manual, uncover insights, and scale smarter, creating space for impactful work. The company values diverse perspectives and supports employee growth.

$250,000–$320,000/yr
US

  • Actively partner on the Cloud Security strategy and implementation.
  • Evolve and expand our current Cloud Security posture across multiple platforms.
  • Recommend and validate Security controls and improvements across our infrastructure stack

Circle is a global financial technology firm building the foundation for a more open financial system through digital assets, payment applications, and blockchain infrastructure. They value their employees and foster a culture of collaboration and excellence, with a flexible work enviornment.

Global

  • Lead Application Security testing projects and drive remediation of identified vulnerabilities.
  • Design and run adversarial testing campaigns across the full Buildkite environment.
  • Build automation for both AppSec and adversarial testing workflows.

Buildkite's mission is to unblock every developer on the planet with their CI/CD platform. They are a remote-first company since 2013 with a small team, high standards, and real ownership distributed across 60+ cities, built around async communication and genuine autonomy.

6w PTO 26w maternity 26w paternity

  • Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues
  • Lead security operation functions – including vulnerability management, SAST, DAST, detection engineering, and incident response – in CI/CD and cloud-native production environments
  • Integrate security into our applications throughout the software development lifecycle

They are scaling intelligence to serve humanity by training and deploying frontier models for developers and enterprises, building AI systems to power magical experiences. Cohere is composed of researchers, engineers, and designers who are passionate about their craft, and believes that a diverse range of perspectives is a requirement for building great products.

$140,000–$160,000/yr
US

  • Plays a key role in safeguarding the company’s cloud-based healthcare SaaS platforms, infrastructure, and customer data.
  • Responsible for designing, implementing, and managing enterprise-grade security solutions that align with regulatory frameworks such as HIPAA, HITRUST, SOC 2, and NIST 800-53.
  • Hands-on technologist with deep knowledge of cloud security (AWS/Azure), DevSecOps practices, endpoint protection, identity management, and security automation.

Reveleer provides cloud-based healthcare SaaS platforms. Reveleer is an equal opportunity employer and E-Verifies all new hires.

$239,000–$275,000/yr
Unlimited PTO

  • Own the technical design and review process for security-critical systems.
  • Maintain mastery of technical security domains to solve complex business challenges.
  • Create and implement advanced tools and automation to increase security monitoring.

Garner Health aims to transform the healthcare economy, delivering high-quality and affordable care for all. They partner with employers to redesign healthcare benefits using clear incentives and data-driven insights. Garner Health is one of the fastest-growing healthcare technology companies.

$178,500–$203,500/yr
US

  • Own the strategy and execution for the Cloudflare ecosystem to secure the network edge.
  • Lead the design of security controls within Google Cloud Platform, specifically for Vertex AI, BigQuery, VPC Service Controls, IAM, and Security Command Center.
  • Embed security into CI/CD pipelines (Cloud Build, GitHub Actions) using Infrastructure as Code (Terraform).

Kareo and PatientPop joined forces to become Tebra, the digital backbone for practice well-being, helping independent practices bring modernized care to patients everywhere. Well over 100,000 providers trust them to elevate their patient experience and grow their practice.

Global

  • Lead and grow a high-performing security engineering team.
  • Own cloud security architecture for AWS.
  • Embed security into the SDLC: threat modeling, secure coding guidance, code scanning, dependency controls, build-time checks, and release gates.

Keyrock is a leading change-maker in the digital asset space, known for partnerships and innovation. They have over 180 team members around the world from 42 nationalities, with backgrounds ranging from DeFi natives to PhDs, with hubs in London, Brussels, Singapore and Paris.

US Unlimited PTO

  • Conducting a comprehensive threat model of our application and infrastructure layers.
  • Hardening our AWS infrastructure while keeping developer workflows frictionless.
  • Integrating security tooling into our CI/CD pipeline.

Loancrate simplifies home-buying for lenders and borrowers by building AI-native tooling to automate mortgage workflows. Since 2020, their remote team has enabled customers to power >$85 billion in new home loans and they value collaboration and open communication.

US Unlimited PTO

  • In collaboration, develop and maintain the Security Architecture roadmap that preserves a strong security posture and aligns with corporate objectives.
  • Lead the development and implementation of automation for established and new security processes to increase operational efficiency and reduce manual intervention.
  • Develop the architectural framework for the secure deployment of AI, designing foundational layers for Model Security, Data Privacy, and Autonomous Agent orchestration.

Bestow is a leading vertical technology platform serving some of the largest and most innovative life insurers. Their platform unifies the fragmented, legacy value chain, enabling carriers to launch products in weeks instead of years.

Europe

  • Drive adoption of a Secure Software Development Lifecycle (SSDLC) across engineering teams.
  • Implement and integrate application security tooling into CI/CD pipelines, improving vulnerability detection and remediation.
  • Establish consistent threat modelling and secure design practices across new features and products.

Neko Health's mission is to deliver proactive healthcare for all, empowering members to take control of their health via technology and compassionate care. They have nearly 100 full-time engineers working across Berlin, Chamonix, Hamburg, Lisbon, Marseille, Vilnius, and Stockholm and they support a flexible workplace that prioritizes work-life balance.