Senior Security Engineer
We're looking for a hands-on Security Engineer who can take full ownership of the vulnerability management lifecycle—from discovery and risk assessment through remediation tracking and verification. You'll be the driving force behind reducing security risk across a cloud-native AWS environment, partnering closely with DevSecOps and engineering teams. The ideal candidate has experience owning and tuning SIEM platforms, distinguishing real threats from noise, and leveraging scripting to automate security operations and integrate security tooling.
Required Qualifications:
- Experience in security engineering, system administration, or related roles.
- Hands-on, production-level AWS security experience (100% cloud-native environment)—not just familiarity, but deep, applied knowledge in securing AWS workloads at scale.
- End-to-end ownership of the vulnerability management lifecycle: discovery, prioritization, risk and criticality assessment, timeline assignment, progress tracking, and closure driving (excluding code fixes, which you coordinate with development teams).
- Demonstrated experience owning security incident investigations
- Proven experience owning and fine-tuning a SIEM solution in production, with the judgment to separate real security signals from noise and false positives.
- Strong scripting skills in Python, Bash, or PowerShell for automation and tooling.
- Solid understanding of network security concepts (firewalls, IDS/IPS, proxies, VPNs).
- Hands-on experience with endpoint security tools and monitoring solutions.
- Strong analytical and problem-solving skills with the ability to think like an attacker.
Preferred Qualifications (Nice-to-Haves): Experience securing containerized workloads (Docker, Kubernetes); knowledge of compliance frameworks (PCI-DSS, SOC 2, NIST, ISO 27001); and experience with Infrastructure as Code (Terraform, CloudFormation).
Join us!