Senior Security – Infrastructure Engineer

Posted 53ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Security Engineer responsible for building platform security for AI solutions at a fast-growing startup. Collaborating with teams to ensure rigorous compliance and security measures are met.

Responsibilities:

  • Own end-to-end platform security architecture for our AI solutions platform, including identity management, access controls, encryption, and network security.
  • Design and implement enterprise-grade RBAC (Role-Based Access Control) systems, including integration with client identity providers (Azure Active Directory, Okta, etc.).
  • Lead our multi-cloud security strategy across AWS (current) and Azure (expansion), ensuring consistent security posture as we scale.
  • Build and maintain secure infrastructure using Terraform CDK, Kubernetes (EKS/AKS), and modern IaC practices.
  • Implement secrets management, encryption at rest and in transit, and secure CI/CD pipelines.
  • Maintain and enhance our SOC 2 Type II compliance program, working with Vanta for continuous monitoring and audit readiness.
  • Drive ISO 27001 alignment and prepare for certification as enterprise clients require it.
  • Conduct security reviews of new features, integrations, and client deployments. Establish SLAs and reporting cadences.
  • Create and maintain security documentation, policies, and runbooks that satisfy enterprise procurement requirements.
  • Partner with legal and operations on vendor security assessments, client security questionnaires, and DPAs.
  • Establish security monitoring, alerting, and incident response procedures. Be a key member of the on-call rotation for security incidents.
  • Lead vulnerability management, including regular scanning, prioritization, and remediation tracking.
  • Provide weekly security status updates to engineering leadership and contribute to client-facing security communications.
  • Mentor engineers on secure development practices and conduct security-focused code reviews.

Requirements:

  • 5+ years of experience in security engineering, DevSecOps, or infrastructure security roles, with at least 2 years at a senior level.
  • Proven experience building security programs from scratch or significantly maturing existing programs at a growth-stage company.
  • Deep expertise with AWS security services (IAM, KMS, Security Hub, GuardDuty, etc.) and infrastructure-as-code (Terraform strongly preferred).
  • Hands-on experience with Kubernetes security (network policies, RBAC, secrets management, service mesh).
  • Track record of achieving and maintaining compliance certifications (SOC 2, ISO 27001, HIPAA, or similar).

Benefits:

  • Remote-first culture with a global team
  • Flexibility in work hours