Senior Security Engineer
Get alerts for roles like this
More Senior Security Engineer roles in United States — straight to your inbox. No account needed.
Applying to this role? Tailor your résumé to this job description in one click, then download it clean — no watermark, no subscription.
Job Description
The Senior Security Engineer is a hands-on, high-impact technical role responsible for designing, implementing, and automating robust security controls across our application stack and cloud environments (primarily AWS, with GCP considerations).
You will strengthen our end-to-end security posture by proactively identifying and remediating vulnerabilities, developing advanced security solutions across the SDLC through production, and building scalable automation using Python, Go, Terraform, and Tines.
Your work will directly contribute to the prevention of unauthorized PHI access and exfiltration, helping us evolve toward a proactive defense model. This is a remote role reporting to the Senior Manager, Security Engineering and plays a critical role in advancing our overall security maturity and resilience.
Responsibilities
Design, build, and implement Just-in-Time (JIT) access controls and Privileged Access Management (PAM) workflows to eliminate standing privileged accounts in production. Conduct platform permission reviews and implement a least-privilege access model for cloud and application roles.
Ensure 100% of production access requests and approvals are captured in audit logs. Lead the implementation, tuning, and operation of security tools in the CI/CD pipeline, including SAST, DAST, SCA, and secrets scanning.
Develop custom SAST rules to detect specific, high-risk flaw patterns, such as authorization bypasses or insecure PII/PHI handling. Partner with engineering to deploy IDE plugins and automated PR checks that block sensitive data exposure before deployment.
Conduct manual security code reviews for high-risk features and cryptographic implementations. Design, build, and maintain automation for the end-to-end vulnerability management lifecycle.
Engineer automated workflows to triage, validate, and assign new vulnerabilities Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations and complianc
Required Skills
Prepare to Win This Role
Everything you need to ace the interview and negotiate top-of-band compensation.