Back to Jobs

Staff Security Engineer

β€’

TrulyRemote Verified

Hand-curated global remote job with direct application link

Technical Requirements

PythonTypeScriptAWSKubernetesTerraformSIEMSASTDAST

You Will…

  • πŸ›‘οΈ Lead security architecture and design reviews across applications, infrastructure, and integrations to ensure secure patterns are embedded early in the development lifecycle.
  • πŸ”Ž Conduct and coordinate penetration testing, threat modeling, and security reviews for critical services, new features, and third-party integrations.
  • βš™οΈ Design and implement security automation within CI/CD pipelines to ensure secure coding practices and infrastructure policies are enforced at scale.
  • ☁️ Partner with infrastructure and DevOps teams to secure cloud platforms (AWS) and improve identity, network, and workload security.
  • πŸ“Š Build security observability and detection capabilities, including security data pipelines, SIEM integrations, and threat intelligence signals.
  • 🧠 Think like an attackerβ€”identify systemic weaknesses and design controls that protect against entire classes of attacks, not just individual vulnerabilities.
  • πŸ§‘β€πŸ’» Work closely with developers to improve security practices through secure architecture guidance, code review support, and developer enablement.
  • 🚨 Lead incident response investigations and help build processes for identifying, analyzing, and mitigating security incidents.
  • 🐞 Own and evolve the bug bounty program, including triage, response processes, and improvements to vulnerability management workflows.
  • πŸ“š Develop security standards, playbooks, and training programs that make security practices easier for engineering teams to adopt.
  • πŸ“ˆ Help define the security roadmap, identifying initiatives that improve both risk posture and operational efficiency.

You Have…

  • πŸ” Deep understanding of application security, cloud security, and modern threat landscapes, including common vulnerabilities and attack techniques (OWASP Top 10, MITRE ATT&CK, etc.).
  • πŸ’» Strong software engineering background with experience writing production-grade code or automation (Python, Typescript, or similar).
  • ☁️ Hands-on experience securing cloud-native infrastructure, especially AWS, including IAM, networking, and containerized workloads.
  • βš™οΈ Experience building or integrating DevSecOps pipelines, including SAST, DAST, IaC scanning, and container security tooling.
  • πŸ“Š Experience designing security telemetry pipelines using tools such as SIEM platforms, observability systems, or data lakes.
  • πŸ§ͺ Experience running or participating in penetration testing, threat modeling, or architectural security reviews.
  • 🀝 Proven ability to collaborate effectively with engineering, DevOps, and product teams to drive secure design decisions.
  • πŸ“’ Excellent communication skills and the ability to clearly explain complex security risks and trade-offs to both technical and non-technical stakeholders.
  • πŸ“‘ Strong understanding of SaaS architectures, distributed systems, and internet-facing platforms.
  • 🧱 Experience developing security frameworks aligned with CIS benchmarks, NIST, or SOC2 / PCI / HIPAA compliance requirements.
  • 🧠 Experience building security detections, threat intelligence pipelines, or runtime protection mechanisms.
  • 🐳 Hands-on experience with Kubernetes, container security, and infrastructure-as-code (Terraform, Ansible).

Benefits:

  • πŸ€‘ Competitive Compensation: Competitive salary and equity packages for all employees
  • πŸ₯ Healthcare Plan: Platinum medical, dental, and vision
  • πŸ›‘οΈ Free life insurance: Including long-term disability & short-term disability
  • πŸ„ Unlimited PTO: Uncapped vacation days & paid holidays
  • πŸ‘Ά Family Leave: Maternity & paternity
  • πŸ“ˆ 401(k) Contribution: Assured contributes 3% of your income, even if you don't contribute
  • 🏠 WFH Benefits: Lunch on us 2x/week, monthly phone stipend & other home office perks
  • πŸ‘ͺ Health FSAs & HSAs: Pre-tax accounts for out-of-pocket medical expenses
  • 🀝 Team events & Offsites: We're remote, but we regularly get together
Staff Security Engineer
Assured
Apply