6 hours ago
Base Salary
$125k - $205k/yr
Responsibilities
- Assess and continuously improve security across applications, infrastructure, cloud environments, corporate systems, vendor tooling, and business workflows.
- Define and implement scalable security standards, guardrails, and automated controls supporting SOC 2 readiness and related compliance requirements.
- Build and maintain internal security tools, automation, and services for secure development, compliance workflows, vulnerability management, corporate security operations, and operational visibility.
- Integrate security scanning, dependency management, container scanning, and secret management into CI/CD pipelines.
- Perform application security work including secure design reviews, threat modeling, code review guidance, API security, microservices security patterns, and remediation planning.
- Improve cloud and corporate systems security through hardening, monitoring, configuration reviews, Infrastructure-as-Code scanning, access reviews, and secure operational patterns.
- Strengthen logging, alerting, detection engineering, incident response, and security observability.
- Partner with Engineering, Infrastructure, IT, Product, Legal, People, Finance, leadership, and other business teams to identify risks and drive remediation.
- Provide clear, pragmatic security guidance to technical and non-technical audiences.
- Support security awareness, secure operating practices, and company-wide adoption of security controls.
Requirements
- 5-7+ years of experience as a Security Engineer or Software Engineer with a strong security focus.
- Proven ability to build and operate production-quality software, automation, and internal tooling.
- Strong understanding of application security, infrastructure security, cloud security, secure CI/CD practices, and corporate security controls.
- Hands-on experience with vulnerability management, secure software development, threat modeling, remediation workflows, and operational security improvements.
- Experience with OWASP, NIST, CIS Controls, SOC 2, and ISO 27001 security frameworks and standards.
- Experience supporting SOC 2 compliance through practical, automated, and auditable controls.
- Familiarity with AWS Security Hub, Azure Security Center, or GCP Security Command Center.
- Experience with SIEM/SOAR tools, logging and monitoring platforms, detection workflows, and practical incident response processes.
- Experience with Infrastructure-as-Code security scanning using tools such as Terraform or CloudFormation.
- Ability to explain complex security concepts clearly to technical and non-technical audiences.
- Experience collaborating with engineering, IT, compliance, and business teams.
- Familiarity with C#, modern backend systems, cloud-native architecture, and SaaS business tooling.
Benefits
- Permanent team members are eligible for various benefits plans.
- The company has offices in Boston, Vancouver, BC, and Vancouver, WA, and select positions may be fully remote.
- Later is an equal opportunity employer committed to an inclusive and accessible workplace.
About Later
Later builds an influencer marketing and social media platform for brands to discover creators, run campaigns, analyze performance, and manage creator payments, with optional managed services. The company also offers a link-in-bio tool used by marketers and creators. Founded in 2014 and headquartered in Boston, it is privately held and used by enterprise customers such as Nike, Wayfair, Unilever, and Southwest Airlines.