Roofr

Senior Security Engineer

Roofr
Apply
12 hours ago
Remote, CanadaSenior

Responsibilities

  • Design and harden cloud security infrastructure including network segmentation, firewalls, IDS/IPS, VPNs, WAF, and EDR.
  • Lead vulnerability assessments, authenticated scans, prioritization, remediation SLAs, and vulnerability management end to end.
  • Build and tune SIEM/SOAR detection rules and alerting logic based on real attack techniques.
  • Serve as incident commander by containing and eradicating threats, conducting forensics, and documenting post-incident reviews.
  • Threat-model new features and infrastructure changes and integrate security requirements into the SDLC.
  • Own IAM hygiene, least privilege, secrets management, key management, and cloud security posture across production AWS accounts.
  • Maintain security policies and standards as living operational controls.
  • Own compliance activities for NIST CSF 2.0, SOC 2, and CCPA/CPRA, including audits, control mapping, remediation, and evidence collection.
  • Run tabletop exercises and incident playbook drills.
  • Promote secure-by-design practices through engineering design reviews and workflows.

Requirements

  • Bachelor’s degree in computer science, IT, cybersecurity, or equivalent hands-on experience.
  • 5–8+ years of experience in security engineering, incident response, or related infrastructure roles, including primary or senior responsibility during real incidents.
  • Deep knowledge of network security fundamentals including firewalls, VPNs, routing, segmentation, TLS, DNS, and network boundaries.
  • Hands-on AWS security experience with IAM policy design, VPC architecture, KMS, secrets management, CloudTrail, and GuardDuty or equivalent tools.
  • Real incident response experience covering triage, containment, forensics, and root-cause analysis.
  • Working knowledge of SIEM/SOAR tools and ability to write detection logic and tooling in Python or Bash.
  • Fluency with NIST CSF 2.0, SOC 2, and CCPA/CPRA and the ability to translate controls into practical policies.
  • Ability to read and write application code and remain hands-on as an individual contributor.
  • CISSP, OSCP, GCIH, or CEH certification is strongly preferred.
  • Experience with AI/LLM tooling for threat intelligence, familiarity with GDPR, PHP/Laravel experience, and Postgres familiarity are preferred.

Benefits

  • Remote-first culture for US and Canada employees.
  • The first week of employment is mandatory PTO, with regular flexible time off, one Friday off per month, and a company-wide shutdown between Christmas and New Year’s.
  • Roofr pays 80% of US benefits and 100% of Canadian Extended Healthcare and Dental premiums.
  • RRSP/401k match and generous parental leave.
  • Annual company retreat and learning and development opportunities.
  • Home office setup stipend plus internet and phone allowance.
  • Weekly Friday paydays.

Tech Stack

AWSBashLaravelPHPPostgreSQLPython

Categories

Roofr

About Roofr

201-500 employees

Roofr builds a SaaS platform for roofing contractors to run sales and operations. The product combines aerial roof measurements, digital proposals, CRM, invoicing, payments, and material ordering in a single system. Founded in 2015 and headquartered in San Francisco, the privately held company sells subscriptions to contractors in the roofing trade.

Contact me