Wpromote logo
WpromotePosted 3 weeks ago

Senior Security Engineer

$145,000–$170,000 year

RemoteUnited States

Part TimeSenior LevelMedium

Job Summary

Design and advance the security engineering program by owning the tooling portfolio, identity architecture, and cloud security posture across GCP. Lead incident response and forensic investigations while driving authentication, secrets management, and OAuth governance. Implement detection-as-code and security automation via Terraform, partnering with platform engineering to enforce policy and controls. Mentor team members and elevate security decisions for the organization. This role requires 5+ years of hands-on security engineering experience with a strong GCP background and is eligible for remote work within the US.

Required Qualifications

  • 5+ years of hands-on security engineering experience in a professional environment, with a track record of owning security architecture and projects end to end
  • Detection engineering experience, including selecting, building, and operating a SIEM, writing and tuning detections, and owning log pipelines, alerting, and monitoring
  • 4+ years of hands-on security cloud engineering, GCP strongly preferred, including Cloud IAM, organization policy, service account governance, and audit logging
  • Deep identity and access management expertise, including federation (SAML SSO) and SCIM provisioning and deprovisioning
  • SaaS identity security depth, including phishing-resistant MFA (passkeys, hardware keys), secrets-management architecture, and OAuth app governance, token lifecycle, and third-party application risk
  • Hands-on incident response and forensic methodology, including sound evidence handling
  • Endpoint security posture experience, including EDR operations (CrowdStrike Falcon or equivalent) and device-trust or conditional-access design
  • Experience operating vulnerability management or exposure management programs, including prioritization by exploitability, asset criticality, and business risk
  • Security automation and infrastructure-as-code fluency, including detection-as-code and a tool such as Terraform, at a level beyond ad hoc scripting
  • Valid work authorization in the U.S. (E-Verify participation required)
  • Ability to work remotely in most states within the US

Desired Qualifications

  • A background in infrastructure, cloud platform, DevOps, SRE, or systems engineering before moving into security, bringing an automation-first foundation to detection and governance work
  • Experience scaling or maturing a security program in a fast-growing environment
  • Industry certifications (GCP Professional Cloud Security Engineer, GIAC such as GCIH, GCDA, or GDAT, CISSP, OSCP)
  • Experience managing least-privilege access across many vendor systems, including those that do not support SSO
  • Player-coach or mentoring experience: while this role is scoped as a senior individual contributor, candidates who can develop internal talent will be considered for expanded scope
  • Exposure to SOC 2 or similar compliance frameworks, partnering with GRC on audit readiness
  • Scripting and automation experience (Python, Bash) for security tooling and workflow optimization

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce