Senior Security Engineer
Listed on 2026-08-03
-
IT/Tech
Cybersecurity, Systems Engineer
About the Role
You will own and drive security engineering strategy across our Azure cloud, hybrid infrastructure, and edge computing platform. This is a senior, hands-on role: you'll set direction for detection engineering, application security testing, Kubernetes hardening, and CI/CD controls, while also advising other engineers and teams on complex security decisions. You will also help define our strategic approach to securing AI/ML workloads running at the edge.
Location.This role is office-based at our Bellevue, Washington office.
What You'll Do (Key Responsibilities)Cloud and Infrastructure Security
- Own and evolve security architecture strategy across Azure, hybrid infrastructure, and edge deployments, guiding design decisions across teams
- Direct the use of SIEM (Microsoft Sentinel), EDR/XDR, WAF, email security, and CSPM/CNAPP tooling, adapting approach as the environment evolves
- Design detection rules, correlation logic, and automated response playbooks, and guide others in building their own
- Lead incident response end-to-end, from triage through containment and remediation, serving as the senior escalation point for complex incidents
- Lead security assessments, vulnerability scanning, and penetration testing across cloud, infrastructure, and application layers
- Test web applications and APIs for authentication and authorization flaws, business logic abuse, and OWASP Top 10 issues
- Threat model new services and architectures before they ship, advising engineering teams on risk tradeoffs
- Own the vulnerability lifecycle end-to-end: risk-based prioritization, SLA tracking, and remediation follow-through, holding owning teams accountable
- Direct the integration of SAST, DAST, SCA, secrets scanning,IaCscanning, and container image scanning into CI/CD as automated gates
- Harden the software supply chain: build provenance, artifact signing, SBOM generation, dependency governance
- Define and enforce guardrails as policy-as-code using Azure Policy, OPA/Gatekeeper, or Kyverno
- Serve as a senior security reviewer for designs and code across engineering teams, influencing secure deployment practices org-wide
- Define and lead our approach to securing AI/ML development and deployment, including model and data supply chain integrity, inference endpoint exposure, prompt injection and agentic tool abuse, and training data governance
- Own security policies, standards, and procedures aligned to NIST, ISO 27001, and SOC 2, and drive their adoption across teams
- Produce audit evidence and lead customer security assessments
- Track emerging threats and translate them into roadmap priorities,advising leadership on risk
- Bachelor's degree in Computer Science, Cybersecurity, or a related field and 8+ years of experience; or Master'sdegree and 6+ years; or equivalent practical experience
- 8+ years in information security, including 5+ years focused on cloud security
- Deep, hands-onexpertisewith Azure security services including Defender for Cloud, Sentinel, Entra , Key Vault, Azure Policy, and network security
- Production experience across multiple of: SIEM, EDR/XDR, WAF, email security, CSPM/CNAPP, vulnerability management, with the judgment to adapt tooling strategy as needs evolve
- Proven experience securing Kubernetes and containerized workloads in production at scale
- Experience embedding security testing into CI/CD pipelines using SAST, DAST, SCA, secrets scanning, andIa Cscanning
- Advanced application security testing experience covering web and API penetration testing and secure code review
- Proficiency with vulnerability management platforms such as Nessus, Nexpose, Qualys, or Defender Vulnerability Management
- Python and SQL/KQL for automation, tooling, and log analysis
- Strong working knowledge of NIST, ISO 27001, and SOC 2, with experience applying them to real audit and compliance cycles
- Experience leading incident response as the primary or senior responder on complex, high-stakes incidents
- Demonstrated experience advising or mentoring other engineers on security best practices
- Experience securing edge, disconnected, or intermittently connected environments
- Experience securing AI/ML or LLM-based systems, including OWASP Top 10 for LLM Applications and MITRE ATLAS
- Advanced detection engineering experience: writing and tuning KQL, detection-as-code, purple team exercises
- Infrastructure-as-code fluency with Terraform or Bicep
- Familiarity with MITRE ATT&CK for threat modeling and detection coverage mapping
- Experience leading or supporting SOC 2 Type II or FedRAMP audit cycles
At leastone from either group is preferred.
- Defensive and architecture: CISSP, CCSP, Azure Security Engineer Associate (AZ-500), GCIH, GCIA
- Offensive: OSCP, OSWE, OSWP, OSEE, GPEN, GWAPT, CEH
Forselectroles, due to the nature of our clientele and the technologies involved, there may be specific nationality or citizenshipindicatedin the required qualifications section.
These roles may…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).