Security Engineer II -SAAS
On-siteSeattle, Washington, United States
Job Summary
Build Java-based services that ingest, validate, normalize, and enrich high-volume security telemetry from SaaS vendors. Design and operate event processing pipelines with strong correctness properties, including deduplication, idempotency, retries, and schema evolution. Develop platform authentication and authorization capabilities covering service identity, token lifecycle, least privilege, and policy enforcement. Partner with security and engineering teams to deliver actionable detections and posture insights while onboarding new SaaS integrations efficiently. Drive operational excellence through observability, performance, reliability, and incident readiness. Establish portfolio-level guardrails for AI-assisted workflows to ensure traceability and alignment with security expectations. Lead safe adoption of enterprise-authorized AI capabilities within cybersecurity architecture workflows, including human-in-the-loop validation and sensitive data handling.
Required Qualifications
- Formal training or certification with 1-3 years building production backend systems
- strong proficiency in Java
- Experience building streaming / event-driven architectures at scale and handling large data volumes
- Proven track record developing secure software end-to-end (secure coding, threat modeling, dependency hygiene, vulnerability remediation)
- Solid fundamentals in designing/building systems that are security focused (e.g. implementing authentication/authorization, least privilege, and auditability)
- Strong ownership mindset and ability to collaborate across engineering and security stakeholders
- Demonstrated experience leading safe adoption of enterprise-authorized AI capabilities within the work environment across cybersecurity architecture workflows, including validation practices and awareness of data sensitivity
- Ability to assess and validate AI-assisted security recommendations and AI-enabled architecture patterns before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations
Desired Qualifications
- Experience with authentication services and modern identity patterns (OIDC/OAuth2 concepts, JWT handling, mTLS, key/cert rotation)
- Streaming platform expertise (Kafka-like systems, consumer group patterns, DLQs, processing guarantees tradeoffs)
- SaaS vendor security integrations (audit log/admin APIs, rate limits, connector frameworks)
- Cloud infrastructure experience (containers, infrastructure-as-code) and secure deployment patterns
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.