Security Engineer

Jobgether — United States · Posted ~2 hours ago

Senior Full-time Remote

Skills

Cloud Security AWS Security Vulnerability Management Application Security Incident Response SIEM Security Engineering AWS Cloud Infrastructure

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A global technology organization is looking for a security engineer to protect cloud infrastructure and applications. The role combines vulnerability remediation, security monitoring, cloud protection, and incident response in a collaborative engineering environment.

Highlights

Remote role within a senior security team with hands-on responsibility for protecting cloud environments, improving security controls, and responding to real incidents.

Description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer based in United States. As a Security Engineer, you will take a hands-on role in protecting cloud infrastructure, applications, and customer data across a modern technology environment. You will identify and remediate vulnerabilities directly in application repositories and infrastructure code rather than simply documenting security findings. The role combines vulnerability management, detection engineering, cloud security, application security, and incident response. You will build and tune SIEM detections, strengthen AWS security controls, and respond directly to security incidents from investigation through remediation. Working within a small, senior, globally distributed security team, you will collaborate with engineering and business stakeholders across the organization. This remote U.S. opportunity is designed for an engineer who enjoys automation, solving complex security problems, and turning findings into measurable improvements. Accountabilities Identify and remediate vulnerabilities across applications, infrastructure, and cloud environments by contributing directly to application repositories and Terraform code and driving fixes through deployment.Build, maintain, and tune security detections within a SIEM, reducing false positives and improving detection coverage while mapping capabilities to MITRE ATT&CK.Lead security incident response activities, including investigation, containment, evidence handling, root-cause analysis, and tracking remediation through completion.Harden AWS environments using services and controls including IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, Secrets Manager, VPC controls, and least-privilege access.Strengthen security throughout the software delivery pipeline through code scanning, dependency management, secret scanning, container and image scanning, and Kubernetes admission controls.Automate repetitive security operations by developing workflows and scripts that support alert triage, enrichment, investigation, and remediation.Develop and maintain security runbooks, standards, detection documentation, and technical evidence supporting compliance requirements.Collaborate with engineering, sales, executive, and other cross-functional stakeholders to communicate security risks and drive practical remediation.Contribute to security programs supporting PCI DSS Level 1, GDPR, and SOC 2 requirements. Requirements Bachelor's degree in a relevant field with 4 years of experience, or at least 6 years of practical experience in security engineering, detection engineering, or incident response.Strong programming skills and the ability to investigate unfamiliar application code, understand vulnerabilities, and implement fixes through pull requests.Deep hands-on AWS security experience, including IAM and least-privilege design, GuardDuty, CloudTrail, KMS, VPC controls, and securing containerized and serverless workloads.Practical experience with security detection engineering in a SIEM, including writing detection rules, tuning alerts, managing false positives, and evaluating detection coverage.Proven cloud incident response experience covering investigation, containment, evidence handling, root-cause analysis, and post-incident documentation.Strong application security fundamentals, including the OWASP Top 10, dependency and secrets management, and CI/CD security practices such as SAST, DAST, SCA, and infrastructure-as-code scanning.Strong written and verbal communication skills, with the ability to explain technical risks clearly and influence stakeholders through evidence and sound reasoning.Experience with Datadog Cloud SIEM, CrowdStrike, Okta, or GitHub Advanced Security is a plus.Experience supporting PCI DSS Level 1 or SOC 2 audits from an engineering perspective is a plus.Experience with Kubernetes, ArgoCD, policy-as-code, Python automation, or Terraform is a plus.Must be currently authorized to work in the United States without requiring employer sponsorship for a work visa. Benefits Annual compensation range of $120,000–$150,000 USD, with flexibility to consider packages above this range based on skills and experience.Remote-first, remote-always working environment for U.S.-based employees.PTO in accordance with local labor requirements.Fully paid parental leave.Home office stipend based on country of residency.Professional development courses through Cloudbeds University.Access to professional development opportunities, including manager training, upskilling, and knowledge-sharing programs.Opportunity to work with a globally distributed team across 40+ countries.Hands-on exposure to modern cloud security, application security, detection engineering, and incident response practices. How Jobgether Works We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.