Guidewire Software

Senior Security Engineer

Guidewire Software
Apply
1 day ago
Remote, United StatesSenior
H1B sponsor

Base Salary

$133k - $199k/yr

Responsibilities

  • Lead complex infrastructure security initiatives across AWS environments and CI/CD pipelines.
  • Design, implement, and operate cloud security controls, governance, access management, logging, monitoring, data protection, network security, and account lifecycle capabilities.
  • Build secure-by-default solutions using infrastructure as code, policy as code, CI/CD, and automation.
  • Define security baselines for cloud accounts, operating systems, containers, AMIs, Kubernetes, networks, and supporting infrastructure.
  • Manage cloud account onboarding, offboarding, inventory, configuration drift, exceptions, and control validation.
  • Design and improve network segmentation, traffic visibility, ingress and egress controls, DNS, firewalls, routing, private connectivity, and related monitoring.
  • Secure CI/CD and software supply chains, including dependencies, artifacts, containers, registries, third-party actions, secrets, and runner environments.
  • Support asset and identity governance for applications, infrastructure, containers, service accounts, workload identities, API keys, AI agents, and MCP tools.
  • Contribute to AI security initiatives covering threat modeling, prompt-injection defenses, data egress protection, guardrails, human-in-the-loop controls, monitoring, and AI-enabled security operations.
  • Evaluate risks using reachability, attack paths, asset criticality, exploitability, and business impact, and improve the quality and remediation of security findings.
  • Represent Security in architecture, change management, design review, and operational forums.
  • Create standards, runbooks, architecture decision records, dashboards, documentation, and enablement materials.
  • Mentor engineers and help partner teams adopt secure patterns without direct management responsibility.
  • Participate in on-call rotations and incident response for cloud and infrastructure security incidents.

Requirements

  • Typically 5+ years of experience in security engineering, cloud security, infrastructure security, DevSecOps, or equivalent practical experience.
  • Hands-on experience designing and operating secure AWS environments; Google Cloud Platform experience is strongly preferred.
  • Experience with cloud governance, access management, policy enforcement, logging and monitoring, data protection, network security, configuration management, and cloud account lifecycle controls.
  • Hands-on experience with infrastructure as code using Terraform, CloudFormation, or comparable technologies.
  • Experience building, securing, testing, and operating CI/CD pipelines, preferably with GitHub Actions, including automation, secrets management, artifact handling, and runner security.
  • Hands-on scripting or programming experience with Python, Go, or another appropriate language.
  • Practical knowledge of cloud and infrastructure networking, including segmentation, routing, DNS, firewalls, ingress and egress controls, private connectivity, and network telemetry.
  • Experience securing containers and Kubernetes platforms, preferably EKS or an equivalent platform.
  • Knowledge of threat modeling, secure design, vulnerability management, security testing, risk assessment, monitoring, and incident response.
  • Experience building or contributing to security measurement and analysis capabilities such as asset inventories, control-coverage reporting, configuration-drift analysis, attack-path analysis, or security data platforms.
  • Working knowledge of identity and access-control concepts, software supply-chain security, SBOMs, artifact signing, provenance, dependency management, secure registries, and CI/CD runner hardening.
  • Working knowledge of foundational AI security concepts, including LLM risks and prompt safety.
  • Preferred experience with AI-security risks and controls involving LLMs, AI agents, MCP, AI gateways, prompt-injection defense, sensitive-data leakage, and AI-enabled security operations.
  • Familiarity with NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, ISO/IEC 42001, or comparable frameworks is preferred.
  • Relevant certifications such as AWS Security Specialty, CISSP, or GIAC are preferred.
  • Ability to own complex work, manage ambiguity, make trade-offs, communicate risks clearly, and deliver outcomes across multiple teams.

Benefits

  • Health, dental, and vision insurance are available for eligible full-time employees and part-time employees working 30 or more hours per week.
  • Eligible employees receive paid time off and a company-sponsored retirement plan.
  • Some roles may be eligible for annual bonuses, commissions, and/or long-term incentive awards.
  • The position is full-time; work arrangement and location details are not specified.
  • Guidewire provides disability accommodations and an appeals process for hiring decisions.
Guidewire Software

About Guidewire Software

1,001-5,000 employees

Guidewire is the platform P&C insurers trust to engage, innovate, and grow efficiently. More than 570 insurers in 43 countries, from new ventures to the largest and most complex in the world, rely on Guidewire products. With core systems leveraging data and analytics, digital, and artificial intelligence, Guidewire defines cloud platform excellence for P&C insurers. We are proud of our unparalleled implementation record, with 1,700+ successful projects supported by the industry’s largest R&D team and SI partner ecosystem. Our marketplace represents the largest partner community in P&C, where customers can access hundreds of applications to accelerate integration, localization, and innovation. For more information, please visit https://www.guidewire.com/.

Contact me