Senior Cybersecurity Engineer
Listed on 2026-07-29
-
IT/Tech
Cybersecurity, Systems Engineer, Security Management & Operations, Network Security
Senior Cybersecurity Engineer
Location:
USA, East Coast Preferred
Experience
Required:
6-10 years
The Senior Cybersecurity Engineer is a hands-on technical security role responsible for improving Indico’s security posture across AWS, Kubernetes, CI/CD, product security, internal systems, and incident response.
This role works in partnership with Indico’s CISO and CTO. The CISO owns security strategy, formal risk acceptance, policy approval, and executive accountability. The Senior Security Engineer turns that direction into practical technical controls, security reviews, operating processes, and cross-functional execution.
This role acts as a security check and balance for Engineering and Platform. You will review technical work against defined security expectations, request changes where needed, and help teams build secure systems without creating unnecessary friction.
Security does not own every security task. Engineering and Platform own implementation and remediation for the systems they build and run, including CVEs, infrastructure changes, CI/CD permissions, committed-secret remediation, and production access implementation. IT/Ops, People Ops, and system owners own day-to-day access administration. The Senior Security Engineer owns technical security standards, reviews, escalation paths, control design, and program execution.
This is a remote role, with East Coast hours preferred.
About YouYou are a pragmatic technical security generalist with strong cloud security instincts. You are comfortable working across AWS, Kubernetes, IAM, networking, secrets management, CI/CD, monitoring, product security, and incident response.
You are technical enough to earn credibility with Engineering and Platform, independent enough to act as a real check and balance, and practical enough to focus on controls that reduce meaningful risk.
You know how to make security work in a startup: focus on the risks that matter, keep the process lightweight, and build guardrails that help teams move quickly without creating unnecessary exposure.
Responsibilities- Improve Indico’s technical security posture across AWS, Kubernetes, CI/CD, product security, internal systems, and incident response
- Partner with the CISO and CTO to turn security priorities into practical technical controls, standards, reviews, and operating processes
- Review Engineering work against security standards, with authority to request changes where needed
- Partner with Engineering on AWS security controls, including IAM, networking, account structure, logging, encryption, key management, backups, production access, and customer-dedicated environments
- Review and improve Kubernetes and container security controls, including workload identity, RBAC, network boundaries, image security, runtime monitoring, and deployment patterns
- Define and improve secure CI/CD patterns, including Git Hub permissions, branch protections, privileged workflows, secrets handling, release controls, and deployment access
- Define and oversee processes for vulnerability management, committed-secret response, secure development, incident response, and access control while Engineering, Platform, IT/Ops, and system owners operate them in their domains
- Provide product security support, including secure design review, threat modeling for sensitive features, scanner tuning, and high-risk change review
- Improve detection and response coverage across tools such as Cloud Trail, Guard Duty, Crowd Strike, SIEM/logging platforms, vulnerability scanners, and secrets detection
- Own day-to-day security monitoring and response operations, including alert routing, triage expectations, escalation paths, and detection improvements
- Coordinate technical containment during security incidents across Engineering, Platform, IT/Ops, and leadership
- Maintain incident response runbooks and partner with the CISO on severity, executive escalation, counsel/compliance coordination, and customer communication strategy
- Create practical security guidance, standards, procedures, and runbooks for security-sensitive work such as production access, secrets handling, vulnerability remediation, incident response, customer…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).