Senior Security Engineer II
$176,000–$196,000 year
On-siteBoston, Massachusetts, United States
Job Summary
Empower engineers with safe-by-default tooling by automating security requirements and building robust guardrails for web and mobile applications. Design and implement scalable systems to secure cloud infrastructure on AWS and Azure, collaborating with engineering teams to deploy critical security enhancements. Conduct security assessments for third-party integrations and emerging AI tools while investigating and responding to security events to guide team improvements. Lead efforts to build security as a service, ensuring safe-by-default environments that drive customer trust. Leverage automation to identify weaknesses and remediate risks across diverse platforms.
Required Qualifications
- At least 5+ years of experience in a security-related role
- At least 2+ years specifically focused on cloud security
- Strong understanding of cloud platforms and security features, particularly AWS (IAM, EC2, VPC, container services like ECR, ECS, and EKS)
- Foundational knowledge of Azure and/or GCP
- Strong understanding of Azure services and how to secure them
- Proven experience with a CNAPP or similar cloud security tool (e.g., Wiz, Orca Security, Lacework, Upwind)
- Proficiency in at least one programming language (e.g., Python, Go) for automation
- Knowledge of core security principles such as the principle of least privilege, defense-in-depth, and security monitoring
- Familiarity with containerization technologies (Docker) and orchestration platforms (Kubernetes)
- Experience with threat modeling and architectural review processes
- Track record of identifying potential attack vectors early in the development lifecycle
- Automation is your default approach to security
- You understand the unique challenges of securing systems at scale
- Consistently leverage automation to solve them
- You possess a proactive mindset
- Adept at identifying and resolving security gaps or inefficiencies through innovative automation and tooling
- Strong analytical and problem-solving skills
- Ability to critically and objectively assess complex security risks
- You can clearly communicate complex security vulnerabilities and remediation techniques to diverse audiences
- You are comfortable guiding and educating development teams to achieve stronger security outcomes
- Must be available for weekend shifts
Desired Qualifications
- Experience with GCP, OCI and multi-cloud networks and infrastructure, especially when designing cloud-agnostic systems
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.