13 hours ago
Base Salary
$131k - $197k/yr
Responsibilities
- Advise an engineering team on security requirements during sprint planning, architecture reviews, design decisions, and active development.
- Build and maintain centralized automated SAST, DAST, SCA, secrets scanning, and IaC scanning in CI/CD pipelines.
- Manage cloud vulnerability and configuration monitoring, patching, and hardening operations.
- Audit application environments and development processes for compliance with internal, external, and security standards.
- Manage the company software development life cycle policy with Information Security leadership.
- Implement cloud detection and response monitoring and serve as an incident CIRT responder.
- Document security controls, configurations, and decisions.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent practical experience.
- At least 8 years of experience in DevOps, software engineering, or security engineering.
- Proficiency with GitHub Actions, GitLab CI, or Jenkins and infrastructure-as-code tools such as Terraform, CloudFormation, or Azure Bicep.
- Hands-on AWS and/or Azure cloud security experience covering identity and access management, containers, network security controls, encryption, logging, and monitoring.
- Experience implementing automated application and infrastructure security testing, secrets management, and policy-as-code enforcement.
- Familiarity with application penetration testing or experience conducting penetration testing engagements.
- Strong scripting skills in Python, Bash, or PowerShell.
- Experience supporting SOC 2 Type 2 and ISO 27001 attestations and audits, including evidence collection.
- Strong communication and governance skills for translating technical risk to technical and non-technical audiences.
Benefits
- Hybrid work with on-site presence at the Fairview office in Seattle.
- US-based employees have access to healthcare benefits, a 401(k) plan, and company match.
- Eligible roles may receive merit increases, annual bonuses, stock, and sales incentives depending on role and plan terms.
- Support for remote work, open paid time off, work/life balance, weekly executive Q&A sessions, and an inclusive workplace.
About Impinj
Impinj builds RAIN RFID tag chips, readers, antennas, and software that identify and track everyday items for retailers, logistics providers, manufacturers, and healthcare organizations. It sells hardware and platform software through partners and integrators to power inventory, asset tracking, and supply-chain visibility solutions. Founded in 2000 and headquartered in Seattle, Impinj is a public company listed on Nasdaq under the ticker PI.
