Remote Jobs RockRemote Jobs Rock

Staff Security Engineer

๐Ÿ•’ 6 days ago
AWS SecurityAzure SecurityZero Trust ArchitectureIAM

๐Ÿ“œ Description

  • Architect and maintain hardened, isolated security stacks (SIEM, EDR, XDR) for multiple client environments.
  • Serve as the technical lead for vendor evaluations, testing emerging technologies for global standards.
  • Engineer automated deployment templates based on CIS and NIST frameworks for secure onboarding.
  • Lead the response to sophisticated APTs and complex breaches as the ultimate technical escalation point.
  • Build automation using Python, PowerShell, and Terraform for threat containment and patch management.

๐Ÿ› ๏ธ Requirements

  • 8โ€“12+ Years in Information Security, with a significant background (3+ years) in multi-client consulting or MSP environments.
  • Force Multiplier: Proven track record of leading cross-functional projects and mentoring senior engineers without direct-report authority.
  • Bilingual Communication: The rare ability to pivot from a deep-dive technical audit with an engineer to a risk-based ROI presentation for a CEO.
Full job description

We are seeking a Staff Security Engineer who operates at the nexus of high-level strategy and multi-tenant operational excellence. While a traditional internal role secures a single enterprise perimeter, you are responsible for the integrated defense fabric of a vast portfolio of diverse client environments.

You will navigate the complexities of varied compliance needs and legacy technical debt, transforming them into a unified, scalable security posture. This is a technical leadership role designed for an expert who prefers the keyboard and the whiteboard over a people-management track, focusing on the "big picture" of our global security product stack.

Core Responsibilities

1. Strategic Security Architecture & Product Strategy

  • Scalable Multi-tenancy: Architect and maintain hardened, isolated security stacks (SIEM, EDR, XDR) designed to scale across hundreds of distinct client environments.
  • Product Vetting: Serve as the technical lead for vendor evaluations, "battle-testing" emerging tech to define our global standard offerings.
  • Global Standardization: Engineer "Gold Image" baselines and automated deployment templates based on CIS and NIST frameworks to ensure rapid, secure onboarding.

2. Tier 4 Escalation & Forensic Mastery

  • Final Authority: Serve as the ultimate technical escalation point for the SOC, leading the response to sophisticated APTs and complex breaches.
  • Post-Mortem Leadership: Conduct deep-dive Root Cause Analysis (RCA) and translate incident findings into systemic, fleet-wide preventative measures.

3. Security Engineering & Hyper-Automation

  • Security as Code: Build the automation tissue that connects our stack, utilizing Python, PowerShell, and Terraform to automate threat containment and patch management.
  • Integration Engineering: Develop custom API integrations to bridge gaps between vulnerability scanners, RMM tools, and ticketing systems for seamless auto-remediation.

4. High-Stakes Advisory & Governance

  • Strategic vCISO: Act as a high-level advisor for key accounts, translating abstract risk into actionable business roadmaps for C-suite stakeholders.
  • Compliance Orchestration: Oversee technical evidence collection and governance for HIPAA, SOC 2, and CMMC, ensuring our clients remain audit-ready.

Technical Profile

CategoryCompetencies
Cloud & IdentityExpert-level AWS/Azure security; Zero Trust Architecture (ZTA); Advanced IAM/Entra ID.
SecOps & IntelligenceAdvanced SOAR/SIEM engineering (Sentinel, Splunk, CrowdStrike); MITRE ATT&CK mapping.
Network DefenseDeep-packet inspection; BGP security; SD-WAN; SASE; Micro-segmentation.
Automation / IaCProficiency in Python, Terraform, or Ansible for infrastructure-as-code.
CertificationsCISSP (Highly Preferred), CISM, CCSP, or specialized GIAC (GCIH/GCFA).

Experience & Qualifications

  • 8โ€“12+ Years in Information Security, with a significant background (3+ years) in multi-client consulting or MSP environments.
  • Force Multiplier: Proven track record of leading cross-functional projects and mentoring senior engineers without direct-report authority.
  • Bilingual Communication: The rare ability to pivot from a deep-dive technical audit with an engineer to a risk-based ROI presentation for a CEO.
Upside

Staff Application Security Engineer

Upside๐Ÿ‘ฅ 201 - 500 employees๐Ÿข Retail
๐Ÿ•’ 10 days ago

As a Staff Application Security Engineer, you will own the application security program, driving vulnerability management and building engineering guardrails to enhance secure software delivery.

Application SecurityVulnerability ManagementPythonThreat Modeling
Sutherland

Cyber Ark transformation lead

Sutherland๐Ÿ‘ฅ 10,000+ employees๐Ÿข Information Technology And Services
๐Ÿ•’ 17 days ago

The CyberArk Transformation Lead will spearhead enterprise-wide Privileged Access Management initiatives, defining strategy, architecture, and governance for security transformation programs.

Cyberark PAMPVWACPMPSM
Docker

Senior Security Engineer, Offensive Security

Docker๐Ÿ‘ฅ 501 - 1000 employees๐Ÿข Computer Software
๐Ÿ•’ 3 days ago

Drive offensive security at Docker by conducting penetration tests and collaborating with teams to enhance security across products and infrastructure.

Penetration TestingOffensive SecurityPythonGolang
Anthropic

Security Engineer, Offensive Security

Anthropic๐Ÿ‘ฅ 10,000+ employees๐Ÿข Research Services๐Ÿค B2B
๐Ÿ•’ 4 days ago

As a Security Engineer focused on Offensive Security, you will conduct red and purple team engagements, penetration tests, and collaborate on AI-specific security challenges.

Red TeamingOffensive SecuritymacOS SecurityLinux Security
Nbcuniversal3

Staff Cyber Security Engineer

Nbcuniversal3๐Ÿ‘ฅ 10,000+ employees๐Ÿข Entertainment
๐Ÿ•’ 4 days ago

The Staff Cyber Security Engineer will conduct comprehensive security and threat analysis for enterprise initiatives, ensuring secure technology deployment aligned with Cyber Security strategies.

Cyber SecurityThreat AnalysisNetwork SecurityApplication Security

Trusted by Remote Workers