Senior Security Engineer
sift · Seattle
Job description
About the role
The Security Engineering team at Sift protects products, infrastructure, and data while enabling rapid, safe delivery of features. As a Senior Security Engineer you will be a technical leader, designing and operating security controls across the entire stack.
Key responsibilities
- Design, implement, and operate security controls and tooling such as IAM policies, network controls, secrets management, endpoint protection, and container security.
- Embed with product and platform teams to conduct security design reviews, threat modeling, and code or configuration reviews for new services.
- Integrate AI‑powered scanning tools, SAST/DAST, dependency and container scanning into CI/CD pipelines and create guardrails and templates for engineers.
- Own vulnerability management workflows from discovery through remediation, defining SLAs and tracking closure.
- Develop automation scripts and services to detect misconfigurations, anomalous activity, or policy violations.
- Participate in security incident response, including investigation, containment, root‑cause analysis, and long‑term fixes.
- Contribute to security documentation, standards, and guidance on authentication, authorization, encryption, and key management.
- Support audits and assessments such as SOC 2 by providing technical evidence of control design and effectiveness.
Required profile
- 5+ years of experience in security engineering, infrastructure engineering, or application security, preferably in a B2B SaaS or cloud‑native environment.
- Hands‑on experience with at least one major public cloud platform (AWS or GCP) including IAM, networking, logging, and security services.
- Strong proficiency in a programming or scripting language (Python, Go, Java, or similar) and experience automating security controls.
- Direct experience with AI/LLM‑specific security risks such as prompt injection and model supply‑chain threats.
- Deep knowledge of secure design principles, authentication/authorization, encryption, least‑privilege access, and secrets management.
- Experience with security tooling such as vulnerability scanners, SAST/DAST tools, SIEM, endpoint protection, or cloud security posture management.
Required skills
- Python
- Go
- Java
- AWS
- GCP
- IAM
- CI/CD
- SAST
- DAST
- Container scanning
- Vulnerability scanning
- SIEM
- Cloud security posture management
- Secrets management
- Network controls
- Endpoint protection
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United States.
Salary: Senior Software Engineer Based on 29 job offers in the United StatesSalaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 13 hours ago
Expires 1 month from now
4 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
sift
Seattle