Senior Security Engineer (FedRAMP)

Veeamsoftware · San Jose, CA, USA · Engineering

Posted 2026-08-05

Apply for this role →

About the Role

We’re looking for a Senior Security Engineer to support the development and growth of Veeam Data Cloud (VDC), our cloud-native SaaS platform. This role owns hands-on security engineering for VDC’s regulated environments, starting with our FedRAMP boundary but extending to the broader set of regulated customer needs we will take on as our platform grows. VDC delivers high-trust, secure data protection services on Microsoft Azure and AWS for customers in regulated industries.

You’ll partner closely with product, platform engineering, and SRE to embed compliant, secure-by-design patterns into everything we ship — designing controls that satisfy NIST 800-53 today but will adapt to other frameworks as we expand.

This is a role with room to shape how security engineering scales across VDC’s regulated footprint: you will own the domain end to end, work independently on complex, ambiguous problems, and set baselines, review practices, and remediation standards to keep VDC compliant and secure at scale.

Due to the fact that this position will deal with highly sensitive data and will support federal customers, we are only considering US citizens at this time. Security clearance is not required, but there is a slight chance it maybe requested in the future

What You’ll Do

Champion secure design patterns that enable compliance-driven engineering across VDC’s Cloud environments, including VDC-wide standards such as supply chain security

Support the design and onboarding of new workloads into regulated environments from a security compliance perspective

Partner with VDC Engineering to harden shared infrastructure (e.g. VMs, containers, and operating systems) against secure baselines such as STIGs and CIS benchmarks

Oversee and support vulnerability scanning alongside the Platform team, providing remediation guidance and tracking fixes against SLAs

Support configuration management change control and configuration baseline compliance with Platform Engineering and SRE

Review significant architecture changes across our regulated environments and provide security input on approvals

Build reusable, framework-agnostic guardrails and evidence so security controls scale across FedRAMP, sovereign cloud, and emerging regulatory requirements

Review application and platform code and identify security deficiencies

Align commercial, government, and other product roadmaps so controls and standards carry cleanly across environments and frameworks

Participate in an on-call rotation shared across the Security Engineering team to respond, triage, and resolve alerts to closing

What You’ll Bring

8+ years in security engineering, with hands-on experience securing cloud environments (strong preference for experience in Azure and/or AWS)

Experience delivering cloud products to meet regulated compliance requirements such as government (FedRAMP, CMMC, IL2/IL4/IL5, sovereign cloud), financial services (PCI-DSS), and/or healthcare (HIPAA, HITRUST)

Ability to translate specific compliance controls into concrete architecture and operational decisions (e.g., how an audit logging requirement drives log retention design, or how boundary protection requirements shape network segmentation)

Working knowledge of NIST 800-53, including continuous monitoring, vulnerability management, and configuration management standards

Experience hardening infrastructure to secure baselines such as STIGs or CIS benchmarks

Strong understanding of cloud security fundamentals in identity, network boundaries, encryption, and vulnerability remediation domains

Ability to learn large, complex platforms quickly with limited guidance: Being comfortable building understanding from code, docs, and architecture artifacts

A collaborative, hands-on approach to partnering across engineering, product, security, compliance, and SRE

Deep partner mindset: Ability to take a hands-on approach to enable engineering teams rather than serving as gatekeepers

AI as a force multiplier: AI tools are woven into how we work, and we build security at AI-speed using these tools. We want engineers who treat AI as a force multiplier, not an afterthought

Bonus Skills

Experience designing and working with controls to satisfy requirements across multiple compliance frameworks

Hands-on experience with vulnerability scanning tools (e.g. Wiz, Nessus)

Experience with IaC tools (e.g. Terraform)

Experience using GitHub for configuration management and change control

Exposure to supply chain security standards and secure-by-design practices

Relevant certifications (e.g., CISSP, CCSP, or cloud provider security certs)

What You’ll Get

Unlimited paid time off, plus 3 global VeeaMe Days for self-care

Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents

Medical, dental, and vision coverage from day one

Mental health support, therapy sessions, and digital wellness tools via SupportLinc EAP

401(k) retirement plan with matching contributions up to annual limits

Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time

AirVet: 24/7 virtual veterinary care at no cost

Legal services, identity protection, and supplemental health insurance options

Tax-advantaged spending accounts for healthcare, dependent care, and commuting

Professional training and education, including courses and workshops, internal meetups, and unlimited access to our online learning platforms (LinkedIn Learning, Athena, O’Reilly) and mentoring through our MentorLab program

#LI-SO2

What you'll get

Unlimited paid time off, 12 paid holidays including 4 global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares

Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents

Medical, dental, and vision coverage starting on your first day

Mental health support, therapy sessions, and digital wellness tools via our Employee Assistance Program

401(k) retirement plan with company matching contributions

Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time

AirVet: 24/7 virtual veterinary care at no cost

Legal services, identity protection, and supplemental health insurance options

Tax-advantaged spending accounts for healthcare, dependent care, and commuting

Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning

Pay Transparency

Veeam is committed to pay transparency and equitable compensation. For this role, the compensation range below reflects the expected total target compensation (TTC), inclusive of base pay and a competitive performance-based bonus. For roles with a commission plan, the compensation range represents On Target Earnings (OTE), which includes base salary plus variable commission. When determining compensation, Veeam takes into consideration factors such as experience, education, skills, and geographic zone. Offers are typically made below the midpoint of the range.

In addition to compensation, Veeam provides a comprehensive benefits package, including health coverage, retirement plans, and unlimited time off.

Compensation Range (TTC / OTE)

$237,800—$441,500 USD

Apply for this role →

← Back to all jobs