Security Engineer II (Defensive)
Core
Integrate automated security tooling into engineering pipelines and protect cloud-native applications and generative AI features against security risks.
Role type
Mid-level IC security engineer (defensive/cloud)
Builds
Automated security controls, IaC scans, and LLM-based security review workflows for pull requests
Domain
Cloud security, DevSecOps, Generative AI security
Required skills
Application security, Cloud security, Infrastructure as Code (IaC), Container security, Source code auditing, API security, Python/Java/Node.js, CI/CD pipelines, OWASP Top 10 for LLMs
Preferred skills
Zero Trust architecture, Risk-based decision making, Incident response, Technical risk communication
Technologies
Terraform, AWS, Docker, Kubernetes, CI/CD pipelines
Responsibilities
Support integration of automated security requirements and validation tooling into engineering pipelines; Build and maintain internal security tooling and automated controls; Perform Infrastructure as Code security scans; Contribute to cloud IAM reviews and maintain Zero Trust boundaries; Configure and run automated LLM-based security review workflows; Support source code audits and API security reviews; Provide actionable feedback on code and configuration issues; Collaborate with software, SRE, DevOps, and product teams; Support risk-based decisions and transparent communication during active security incidents.
Seniority
Mid-level, hands-on IC