← Back to job listings
RE
Security Engineer (Vuln Management, Infra)
Replit · United States
About The Role
Join our team as a mid-level Infrastructure Vulnerability Management Engineer. In this role, you will bridge the gap between security, compliance, DevOps, and Platform engineering teams. You will identify infrastructure misconfigurations, secure multi-cloud environments, and manage continuous vulnerability lifecycles. You will also serve as a technical infrastructure responder during security incidents. This is a remote-first position with flexible work hours and a comprehensive benefits package.
- Identifying infrastructure misconfigurations, securing multi-cloud environments, and managing continuous vulnerability lifecycles across cloud workloads.
- Performing continuous security scanning across cloud posture and workloads, reviewing, validating, and prioritizing flaws and misconfigurations.
- Owning and optimizing Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), and Data Security Posture Management (DSPM) tools.
- Experience: 5 years of experience in Cloud Security, DevSecOps, or Systems Engineering roles
- Compliance Awareness: Understanding of how infrastructure configurations and vulnerability management map to security compliance frameworks like SOC 2, ISO 27001, CIS Benchmarks, or NIST
- Containerization & Orchestration: Deep understanding of Docker/container security and Kubernetes architectures (e.g., GKE, EKS), including runtime security, network policies, and workload identity
- Posture Management & Scanning Tooling: Hands-on experience operating modern infrastructure security platforms such as Wiz, Orca, Prisma Cloud, Lacework, or cloud-native options (GCP Security Command Center)
- Cloud Infrastructure Depth: Strong foundational experience working with multi-cloud environments (Deep GCP expertise preferred, with working knowledge of AWS or Azure)
- IaC and Automation Fluency: Strong proficiency with Infrastructure as Code platforms (Terraform, Pulumi) and GitOps deployment workflows. Ability to evaluate and configure IaC scanners like Checkov, Tfsec, or KICS
- Problem-Solving Mindset: A passion for breaking down complex security challenges into elegant, scalable engineering solutions
- Systems Thinking: The ability to see the "big picture" and understand how security decisions impact the entire stack
- Autonomy: Comfortable leading major technical initiatives and driving outcomes with minimal oversight
- Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority
- We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring