Senior Security Engineer
Beyond Finance · Chicago, United States
About The Role
Join our team as a Senior Security Engineer, where you'll play a crucial role in enhancing the security of our AWS environment and software development pipeline. You'll work closely with DevOps, Engineering, and our Application Security Engineer to implement preventative controls across infrastructure, identity, and CI/CD. Your responsibilities will include managing cloud security posture, establishing secure defaults in Infrastructure as Code, hardening CI/CD pipelines, and running vulnerability management. You'll also have the opportunity to build automation that scales the program and operate and tune our WAF. Enjoy generous PTO, competitive health care plans, 401(k) matching, paid parental leave, and more.
- Harden the security posture of the AWS environment and software development pipeline, focusing on cloud security and vulnerability management.
- Partner with DevOps, Engineering, and Application Security Engineer to build preventative controls across infrastructure, identity, and CI/CD.
- Own cloud security posture across the AWS environment using Wiz and AWS-native services, reducing risk across IAM, network segmentation, container security, secrets, and data exposure.
- Experience running or substantially contributing to a vulnerability management program
- 5+ years of hands-on security engineering across cloud security and vulnerability management
- Hands-on experience securing CI/CD pipelines and Infrastructure as Code; Terraform required
- Operates independently and drives projects without day-to-day oversight
- Strong AWS security background: IAM, networking, container orchestration, and logging and audit
- Working knowledge of OWASP Top 10 and threat modeling
- Familiarity with Ruby on Rails, Python, or Go
- They think like an attacker but bring a developer mindset to their partnership with engineering, connecting the dots across cloud, identity, and pipeline rather than treating each as a separate domain
- The ideal candidate measures success by reduced risk, not tickets closed, and reaches for secure design and simplicity before another control
- Secrets management platforms (AWS Secrets Manager, Keeper, Infisical)
- Hands-on WAF experience in production: writing and tuning rules, managing false positives, responding when something gets through
- PCI-regulated or financial services environment
- AI/ML security exposure: prompt injection, data poisoning, model abuse, and the controls that mitigate them
- Experience with our stack: Wiz, Cloudflare (WAF, Gateway, Zero Trust), GitHub Advanced Security, Spacelift, and AWS-native services
- Engineers trust their technical judgment, and when something is blocked, they come with a proposed path forward
- Identity security across human and non-human identities
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring