Skip to content
← Back to job listings

Senior Security Engineer

Sift · United States

External listingfull-timeabout 1 month ago

About The Role

Join Sift, a leading company in fraud prevention and digital trust. As a Senior Security Engineer, you will play a crucial role in protecting Sift's products, infrastructure, and data while enabling the engineering organization to ship quickly and safely. You will design, implement, and operate security controls and tooling across Sift's stack, work closely with various teams, and contribute to audits and compliance efforts.

  • Design, implement, and operate security controls and tooling across Sift’s infrastructure and applications.
  • Embed with product and platform teams to perform security design reviews, threat modeling, and code or configuration reviews for new features and services.
  • Own or co‑own vulnerability management workflows, from discovery and triage through remediation, including defining SLAs, coordinating with service owners, and tracking closure.
  • Clear written and verbal communication skills, including the ability to document designs and decisions and to educate others on security best practices
  • Direct experience with AI/LLM-specific security risks (prompt injection, model supply chain, etc.)
  • Hands‑on experience with at least one major public cloud platform (e.g., GCP, AWS), including IAM, networking, logging/monitoring, and security services
  • Ability to work cross‑functionally with engineering, IT, and compliance/legal teams, and to translate security requirements into practical implementation details
  • A collaborative, pragmatic approach: you’re comfortable making risk‑based decisions, proposing options, and supporting teams in implementing secure, scalable solutions
  • Strong proficiency in at least one programming or scripting language (e.g., Python, Go, Java, or similar) and experience using code to automate security controls or detection
  • Demonstrated knowledge of secure application and system design, including topics like authentication/authorization, encryption in transit and at rest, least‑privilege access, and secrets management
  • Solid understanding of common vulnerabilities and attack patterns (e.g., OWASP Top 10, misconfigurations, supply‑chain risks) and how to mitigate them in practice
  • 5+ years of experience in security engineering, infrastructure engineering, or application security, ideally in a B2B SaaS or cloud‑native environment
  • Experience with security tooling such as vulnerability scanners, SAST/DAST tools, SIEM/centralized logging, endpoint protection, or cloud security posture management

This is an external listing. JobSpring does not represent or verify the employer. Report this listing