Security Engineer II
Pantheon Web Ops Platform powers the open web, running more than 300,000 sites in the cloud for customers including Google, Princeton, Salesloft and Doctors Without Borders. Every day, thousands of developers and marketers create, iterate, and scale Word Press and Drupal sites to reach billions of people globally. Pantheon's multitenant, container-based platform enables organizations to manage all of their websites from a single dashboard.
Organizations including Clorox and the United Nations drive results through accelerated development and real-time publishing using Pantheon's collaborative workflows.
Pantheon's Security Engineering team is responsible for safeguarding, auditing, and testing the security of Pantheon's entire platform. Our Security Engineering team aims to create a comprehensive and multi-dimensional approach to application security, with a focus on Security by Design in agile software development and cloud native environments.
We are seeking a Security Engineer II to join our growing team. This role bridges execution and tooling — you'll own security domains end-to-end while building the automation and processes that multiply the team's impact across engineering. This is a hands-on engineering role: you'll write detection rules, build vulnerability management tooling, implement supply chain security controls, and develop the automation pipelines that make security scale.
Our mission is to safeguard, audit, and test the security of the entire cloud hosting platform in these core areas:
- Security by Design: Implement "Security by Design" within agile software development and cloud-native environments.
- Security Tooling & Automation: Build and maintain security tooling and automation that scales the team's impact beyond what manual processes can achieve.
- Support and Mentorship: Act as a Subject Matter Expert (SME), mentoring and supporting security engineering efforts across the organization.
- Standard Setting: Contribute to application security policy, process, standards, and guidelines — and build the tooling that enforces them.
- Application Security Performance: Help engineering teams design and build high-performing, secure applications by mitigating security issues in a risk-based manner.
- Detection Engineering: Author SIEM detection rules and response playbooks in Chronicle / Google Sec Ops (YARA-L), expanding coverage across Pantheon's security monitoring surface.
- Security Tooling Development: Build and maintain security automation pipelines (Python/Go) — vulnerability management tooling (vulntools, Wiz scripts), GHAS automation, and CI/CD security integrations.
- Vulnerability Management: Own vulnerability identification, triage, and remediation coordination with engineering squads across application (SAST/DAST/SCA) and infrastructure layers.
- Supply Chain Security: Implement supply chain security controls (Aikido, SLSA, dependency pinning) and integrate them into engineering workflows.
- Access & Identity: Execute RBAC cleanup, access architecture implementation, and periodic user access reviews. Manage Git Hub org-level security policies and access controls.
- Cloud Security: Execute CSPM baseline findings triage, cloud security baseline validation, and data warehouse security implementation (Snowflake).
- DLP & Secrets: Define DLP policies and evaluate tooling; execute credential and secrets hygiene programs (plaintext credential remediation in repositories).
- Builder Orientation: You measure impact by what you ship — tooling that engineering teams adopt, automation that replaces manual work, detection rules that catch real threats. Not by tickets closed or alerts triaged.
- Communication: Strong communication skills…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).