USA - Remote
Remote
Mid Level
Full Time
💰$ 150,000 - $ 245,000
Security EngineerRemoteAI-first mindsetSOC 2PCI DSSISO 27001GitHub ActionsAnsibleDockerVulnerability Management
Requirements
- •Solid experience in security or infrastructure engineering with security focus
- •Deep Linux knowledge including hardening, debugging, and managing large fleet of Linux hosts
- •Experience with Ansible at fleet scale for automation
- •Strong scripting skills in Python and/or Go plus shell competence
- •Production experience securing Docker containers and build pipelines
- •Hands-on experience securing GitHub and GitHub Actions
- •Experience running vulnerability and patch management as ongoing program
- •Experience managing third-party penetration tests from inside
- •Hands-on involvement in at least one formal audit (ISO 27001, PCI DSS, or SOC 2) producing and defending evidence
- •Comfortable using AI coding and agentic tools with awareness of risks
- •Pragmatic approach to security controls and risk trade-offs
What You'll Do
- •Build, deploy, and maintain security controls across bare-metal fleet and AWS footprint
- •Own configuration management and host hardening as code with Ansible
- •Secure containerized workloads including Docker image build pipelines and runtime hardening
- •Run vulnerability management end to end including discovery, prioritization, remediation, and reporting
- •Own patch and update management program for servers, endpoints, base images, OS, packages, and firmware
- •Manage penetration testing lifecycle including scoping, vendor selection, triaging findings, verifying fixes, and reporting
- •Write detections, tune out noise, and participate in incident response
- •Run periodic log and access reviews and automate evidence collection
- •Automate compliance evidence collection for SOC 2, PCI DSS, and ISO 27001 and support audit fieldwork
- •Harden GitHub Actions CI/CD and software supply chain security
- •Apply AI and agentic tooling to security work and help secure internal AI usage
- •Provide technical input for customer-facing security work including questionnaires and architecture answers
Nice to Have
- •Datacenter or colocation experience including network segmentation and out-of-band management
- •Detection engineering or SIEM/HIDS ownership at scale
- •Secrets management with HashiCorp Vault
- •AWS security (IAM, SCPs, VPC) and Terraform experience
- •Kubernetes security
- •Offensive security background such as penetration testing or red teaming
- •PCI DSS work inside a cardholder data environment
- •Ownership of a secure SDLC program
- •Experience with GPU infrastructure, ML platforms, or multi-tenant inference workloads
- •Certifications such as OSCP, GIAC, CISSP, or AWS Security Specialty
