CronJobs

security jobs

Staff Security Engineer

Beyondfinance · Remote

remotesenior$160,000–$160,000Posted Sep 4, 2026PythonGoAWSTerraformSASTSCADASTSIEM

Apply on the employer site

About this role

**Staff Security Engineer — Beyond Finance** *Role Overview* As a Staff Security Engineer, you’ll work early with Product and Software Engineering teams to embed security into architecture and processes as they design, build, and ship. You’ll also be a go-to security partner the Security team can pull into any project, at any phase and across domains, to ensure the right security outcomes. This is a hands-on role. You don’t need to be an expert in all three areas—application security, cloud security, and security automation/tooling—but you should have strong depth in one, plus enough working knowledge of the other two to contribute independently and be a trusted voice in technical decisions. **What You’ll Do** - Partner with Engineering, DevOps, and Product across projects, providing security input at any phase of design or build. - Guide secure design and code review for web and mobile applications. - Manage core AppSec tooling: SAST, SCA, secret scanning, DAST, ASM, and mobile security tooling. - Help triage and remediate application-level vulnerabilities with engineering teams. - Contribute to cloud security posture across AWS (IAM, network segmentation, container security, secrets, and data exposure) using CNAPP and AWS-native tooling. - Support cloud and application vulnerability management, including tuning WAF rules as needed. - Build automation and internal tooling (primarily in Python) to reduce manual work for the security team. - Contribute to security log pipelines, SIEM detections, and endpoint security controls. - Embed security checks (scanning and secrets detection) into CI/CD pipelines with DevOps. - Contribute to secure development and infrastructure standards, playbooks, and enablement materials. **What We’re Looking For** **Requirements** - 8+ years of hands-on security engineering experience. - Strong depth in one of: application security, cloud security, or security automation/tooling, with working knowledge of the other two. - Working knowledge of threat modeling. - Ability to operate independently and drive projects without day-to-day oversight. **Nice to Have** - Deeper expertise across multiple areas (AppSec, cloud security, or security automation). - Hands-on Infrastructure as Code experience (ideally Terraform). - Red teaming / offensive security experience. - Experience in PCI-regulated or financial services environments. - Mobile application security experience. - AI/ML security exposure (prompt injection, data poisoning, model abuse, and mitigations). - Identity security across human and non-human identities. - Development experience with Ruby on Rails, Python, Go, or similar languages. **The Ideal Candidate** - Measures success by reduced risk (not tickets closed). - Understands attacker approaches and favors secure design + simple guardrails over adding more scanners/approval gates. - Treats application code, cloud infrastructure, identity, and the pipeline as one connected system. - Proactive: tackles the highest-impact piece of an ambiguous problem and iterates (partial fixes now, improvements over time). - When changes are needed outside your domain, you make the change, get it reviewed, and ship it. - Engineers trust your judgment: you catch bad designs, fragile systems, and overlooked risks early enough to design around them. **Why Join Us** - High-ownership role with influence over architecture, tooling, and process beyond your domain. - Spans application security, cloud security, and securi

Listing freshness

CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord