Staff Security Operations Engineer

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Staff Security Operations Engineer enhancing security practices at Apollo. Collaborating with engineering teams to conduct threat modeling and drive secure software development.

Responsibilities:

  • Partner with engineering teams to conduct threat modeling and security reviews on new features and architecture changes
  • Establish and evolve Apollo's application security program including SAST/DAST tooling, dependency scanning, and secure coding standards
  • Drive security requirements into the SDLC, embedding security gates into CI/CD pipelines
  • Identify and remediate vulnerabilities in Apollo's products and APIs, with a focus on reducing systemic risk rather than one-off fixes
  • Act as a security advisor for product teams building customer-facing features, particularly those involving authentication, authorization, and data handling
  • Advance Apollo’s detection and response strategy in partnership with engineering and IT leadership
  • Implement and maintain adherence to SOC 2 and other cloud security frameworks
  • Handle escalations from Sales and Customer Success
  • Build and tune monitoring, logging, and alerting systems to improve visibility while reducing noise
  • Drive automation of SecOps workflows to speed up investigation and response
  • Guide secure adoption of AI across Apollo - from internal use by engineers to AI-powered product features
  • Participate in our on-call rotation (we keep this lightweight and reasonable)

Requirements:

  • 6+ years in security engineering, spanning both application security and security operations
  • Strong foundation in AppSec: threat modeling, SAST/DAST, dependency management, secure SDLC practices
  • Deep expertise with detection and response in cloud-native environments
  • Experience building and automating security tooling (scripting/programming language, SIEM, SOAR, or AppSec tooling)
  • Proven ability to partner with engineering teams to improve security posture with while minimizing the impact on delivery times
  • Track record of influencing security culture across an engineering organization
  • Strong knowledge of SOC 2, ISO 27001, or similar security frameworks
  • Proven ability to lead or coordinate incident response across multiple teams
  • Track record of influencing operational security culture and practices without direct authority

Benefits:

  • Health insurance
  • Dental and Vision benefits
  • 401(k)
  • Flexible working hours
  • Professional development opportunities