Senior Cybersecurity Engineer
$165,000–$185,000 year
RemoteUnited States
Job Summary
Improve Indico's technical security posture across AWS, Kubernetes, CI/CD, product security, and incident response by partnering with the CISO and CTO to turn priorities into practical controls and operating processes. Review Engineering work against security standards, including IAM, networking, secrets management, and vulnerability controls, with authority to request changes. Define secure CI/CD patterns, oversee vulnerability management and incident response processes, and provide product security support through threat modeling and scanner tuning. Own day-to-day monitoring operations, coordinate technical containment during incidents, and create practical guidance, standards, and runbooks for security-sensitive work. Evaluate security tools and build automation to reduce manual effort while maintaining a lightweight, risk-based approach.
Required Qualifications
- 6+ years of relevant security experience
- ideally in a startup, SaaS, cloud-native, or enterprise software environment
- Strong hands-on experience with AWS security
- including IAM, networking, logging, monitoring, encryption, access controls, and production security
- Experience securing Kubernetes
- containers, CI/CD pipelines, infrastructure-as-code, and modern cloud deployment patterns
- Strong understanding of identity and access management
- least privilege, privileged access, workload identity, and service-to-service permissions
- Working knowledge of application and product security
- including authentication, authorization, secure coding, common web risks, and secure design review
- Experience defining or operating vulnerability management
- secrets management, secure development, access control, or incident response processes
- Experience with secrets management
- cloud key management, encryption design, data residency, threat modeling, or secure SDLC programs
- Experience with security monitoring
- alert triage, incident response coordination, and remediation tracking
- Experience with Python, Go, Bash, or other scripting languages for security automation
- Ability to review infrastructure, application, and operational changes for material security risk
- Ability to partner with Engineering and Platform while maintaining appropriate independence and oversight
- Strong written and verbal communication skills
- including clear technical guidance, standards, runbooks, and customer-facing security documentation
- Good judgment around risk prioritization
- compensating controls, exceptions, and startup-appropriate tradeoffs
- Ability to operate independently
- create structure, and drive work to completion
- East Coast hours
Desired Qualifications
- Experience as a first or early security hire at a startup
- Experience securing single-tenant SaaS or customer-dedicated cloud environments
- Experience with AWS EKS, Terraform, Helm, ArgoCD, GitHub Actions, or similar infrastructure tooling
- Experience with CrowdStrike
- Experience supporting SOC 2, ISO 27001, HIPAA, GDPR, customer audits, or enterprise security questionnaires
- Pragmatic, risk-based, comfortable with ambiguity, and focused on security practices people actually use
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.