Senior Security Engineer
US New York
Full Time Senior-level / Expert USD 130K - 150K
SoundCloud
Discover and play over 320 million music tracks. Join the world’s largest online community of artists, bands, DJs, and audio creators.SoundCloud is a next-generation music entertainment company powered by an ecosystem of artists, fans, and thriving communities. As one of the world’s most influential cultural platforms, SoundCloud holds a singular market position as both a music-streaming service with the largest catalogue of music, and an artist services and distribution business to help artists grow long-term, successful careers.
We are looking for Senior Security Engineers to join our growing technology organization!
As Security engineers at SoundCloud, we secure the infrastructure for products that music listeners and creators love. Our work often involves large-scale distributed systems, parallel computing, and data science. We actively improve our tools and processes to support collaboration and productivity. We cultivate an environment where we can all learn and grow.
Requirements:
Over 6 years of software engineering and/or security experience
Familiarity with common security libraries, security controls, and common security flaws that apply to web applications
Experience in designing and implementing security controls within a multi-cloud environment, preferably AWS and GCP
Experience with Terraform, containers, Kubernetes, CI/CD pipelines, Identity and Access Management (IAM), and secrets management in microservices-based architectures
Proficient experience in software development such as Python and JavaScript
Proven experience with Web Application Security Testing, Code Reviews, Vulnerability Assessment
Excellent troubleshooting and problem-solving skills
Strong communication and collaboration skills
Nice-to-haves
Computer science education or equivalent experience
Experience with implementing and maintaining ELK stacks
Experience with designing, implementing, and maintaining SIEM systems
Experience with open source and developer tools
Key Responsibilities:
- Responsible for configuring, maintaining, and using Elastic Security for SIEM and endpoint protection
- Security incident response, including identifying and remediating security-related infrastructure incidents and endpoint anomalies
- Responsible for implementing and maintaining the security for internal workplace, on-premises and cloud infrastructure, and customer-facing environments
- Maintain involvement with security vendors, industry peers, news and blogs, and professional associations to understand existing and evolving industry standards, technologies, and threats
- Identify opportunities for conducting proof-of-concepts for new technologies
- Lead collaborative administration for Google Workspace and Identity, containerized application security, cloud security and vulnerability management in AWS and GCP, and IAM pipelines
- Coordinate penetration testing and vulnerability testing of infrastructure and applications
- Promote and implement security best practices in a collaborative manner with engineering teams
- Perform security onboarding training for all employees
- Develop and manage educational and training campaigns for security awareness and policy compliance
- Manage bug bounty program to review reported vulnerabilities, facilitate confirmation and remediation of bugs, and communicate with participants/researchers
- Seek out opportunities to develop and implement automated processes and integrations
The salary range for this role is $130,000 to $150,000 annually. The final salary offered will be determined based on relative experience, skills, internal equity, and location. We also offer a generous total rewards program - read more about additional benefits and perks below!
Title:
Senior Security EngineerLocation:
Remote - United States, US Los Angeles, US New YorkAbout Us:
We are a multinational company with offices in the US (New York and Los Angeles), Germany (Berlin), and the UK (London)
We provide a flexible work culture that offers the opportunity to collaborate and connect in person at our offices as well as accommodating work from home
We are deeply committed to ensuring diversity, equity and inclusion at all levels of our organization and fostering a community where everyone’s voice, perspective and experience is respected and heard
We believe a strong team is made by investing in employees through mentorship, workshops and enrichment opportunities
Benefits:
Comprehensive health benefits including medical, dental, and vision plans, as well as mental health resources
Robust 401k program
Employee Stock Ownership Plan
Generous professional development allowance
Interested in a gym membership, photography course or book? We have a Creativity and Wellness benefit!
Flexible vacation and public holiday policy where you can take up to 35 days of PTO annually
16 paid weeks for all parents (birthing and non-birthing), regardless of gender, to welcome newborns, adopted and foster children
Various snacks, goodies, and 2 free lunches weekly when at the office
Diversity, Equity and Inclusion at SoundCloud
SoundCloud is for everyone. Diversity and open expression are fundamental to our organization; they help us lead what’s next in music by understanding and empowering our creators and fans, no matter their identity. We acknowledge the challenges in the music industry, and strive to influence an inclusive culture where everyone can contribute respectfully and thrive, especially the historically marginalized communities that many of our creators, fans and SoundClouders identify with. We are dedicated to creating an inclusive environment at SoundCloud for everyone, regardless of gender identity, sexual orientation, race, ethnicity, migration background, national origin, age, disability status, or care-giver status.
At SoundCloud you can find your community or elevate your allyship by joining a Diversity Resource Group. Diversity Resource Groups are employee-organized groups focused on supporting and promoting the interests of a particular underrepresented community in order to build a more inclusive culture at SoundCloud. Anyone can join, whether you share the identity or strive to be an ally.
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
Tags: Application security AWS CI/CD Cloud Compliance Computer Science ELK GCP IAM Incident response JavaScript Kubernetes Microservices Open Source Pentesting Python SIEM Terraform Vulnerabilities Vulnerability management
Perks/benefits: 401(k) matching Career development Equity Fitness / gym Flex hours Flex vacation Health care Home office stipend Lunch / meals Wellness
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Senior Information Security Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Architect jobs
- Open Chief Information Security Officer jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Security Analyst jobs
- Open o365 Security Architect jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Security Researcher jobs
- Open Product Security Engineer jobs
- Open Cyber Security Architect jobs
- Open SOC-related jobs
- Open GCP-related jobs
- Open Risk assessment-related jobs
- Open Governance-related jobs
- Open Network security-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open Analytics-related jobs
- Open CISM-related jobs
- Open IAM-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open Security Clearance-related jobs
- Open Malware-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open Java-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open DoD-related jobs
- Open Splunk-related jobs
- Open EDR-related jobs