3 months ago
Base Salary
$145k - $200k/yr
Responsibilities
- Design and implement security controls and tooling for Sift’s infrastructure and applications, including IAM policies, network controls, secrets management, endpoint protection, and container and workload security.
- Embed with product and platform teams to conduct security design reviews, threat modeling, and code or configuration reviews.
- Improve the secure SDLC by integrating AI-powered scanning, SAST/DAST, dependency scanning, and container scanning into CI/CD.
- Develop guardrails, templates, and secure engineering best practices.
- Own or co-own vulnerability management from discovery and triage through remediation, including SLAs, service-owner coordination, and closure tracking.
- Develop scripts, services, and integrations to detect misconfigurations, anomalous activity, and policy violations and reduce manual work.
- Participate in security incident response, including investigation, containment, root cause analysis, and long-term remediation.
- Create security documentation and standards covering authentication, authorization, encryption, and key management.
- Support SOC 2 audits and customer security questionnaires by providing technical details and control evidence.
- Mentor engineers through pairing, reviews, training sessions, and written guidance on secure design and implementation.
Requirements
- At least 5 years of experience in security engineering, infrastructure engineering, or application security, ideally in a B2B SaaS or cloud-native environment.
- Hands-on experience with at least one major public cloud platform, including IAM, networking, logging and monitoring, and security services.
- Strong proficiency in at least one programming or scripting language such as Python, Go, or Java, with experience automating security controls or detection.
- Direct experience with AI/LLM-specific security risks, including prompt injection and model supply-chain risks.
- Knowledge of secure application and system design, authentication and authorization, encryption in transit and at rest, least-privilege access, and secrets management.
- Experience with vulnerability scanners, SAST/DAST tools, SIEM or centralized logging, endpoint protection, or cloud security posture management.
- Understanding of common vulnerabilities and attack patterns, including OWASP Top 10, misconfigurations, and supply-chain risks.
- Ability to collaborate with engineering, IT, compliance, and legal teams and translate security requirements into practical implementation details.
- Clear written and verbal communication skills, including the ability to document designs and educate others on security practices.
- Collaborative and pragmatic approach to risk-based decision-making and implementation of secure, scalable solutions.
About Sift
Sift builds a cloud-based fraud prevention and risk scoring platform for online businesses, using machine learning to stop payment fraud, account abuse, and chargebacks. The privately held company was founded in 2011 and is headquartered in San Francisco. Its software is used by brands including Hertz, Yelp, and Poshmark, and is sold as a B2B SaaS suite integrated into commerce, payments, and identity workflows.
