16 hours ago
New York, NY, USASenior / Staff+
Base Salary
$159k - $263k/yr
Responsibilities
- Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.
- Design and enforce least-privilege identity and access management across AWS and internal systems.
- Own secrets and credentials management, including policies, tooling, rotation, and developer workflows.
- Lead security incident response, including detection, containment, root cause analysis, post-mortems, and durable remediation.
- Manage AWS Organizations, account boundaries, service control policies, and security guardrails.
- Harden CI/CD pipelines by embedding security scanning and policy enforcement into software delivery.
- Drive compliance programs by owning evidence, controls, and remediation work.
- Build secure-by-default repository, pipeline, and infrastructure templates.
- Automate certificate issuance, secrets access, policy-as-code, and developer-facing security tooling.
- Provide practical security guidance and shape the DSO function as it scales, including contributing to hiring and team building.
Requirements
- 8+ years of experience in DevSecOps, platform security, or a closely related security engineering role.
- Deep hands-on AWS experience, including IAM, SCPs, Organizations, GuardDuty, Security Hub, and CloudTrail.
- Strong Terraform and infrastructure-as-code experience, including security controls and policy-as-code or continuous compliance tooling such as OPA, Checkov, tfsec, or AWS Config Rules.
- End-to-end production experience owning secrets management.
- Experience designing and hardening CI/CD pipelines, including GitHub Actions.
- Hands-on container security experience, including image scanning and runtime controls.
- Experience leading or meaningfully contributing to a compliance program; CMMC Level 2 or NIST SP 800-171 experience is strongly preferred.
- Experience running incident response, participating in on-call operations, leading post-mortems, and shipping remediation.
- Strong communication, judgment, ownership, and ability to drive security adoption through enablement.
- Experience growing a DSO or security engineering function, configuration management experience with Ansible or similar, familiarity with observability tooling, and experience building developer-facing security platforms are preferred.
- U.S. citizenship and eligibility to obtain and maintain a U.S. Government security clearance are required.
Benefits
- Onsite, full-time role in a controlled work environment.
- Medical, dental, vision, life, AD&D, and disability plan options.
- Paid parental leave, including 12 weeks for birthing parents, 4 weeks for non-birthing parents, and 6 weeks for adoptive, foster, or intended parents through surrogacy.
- Paid holidays and flexible PTO.
- 401(k) pre-tax and Roth options, HSA/FSA options, and dependent care FSA.