Senior Security Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

Block MB ยท 21 hours ago

Senior Security Engineer

Block MB is seeking a Senior Security Engineer to own and strengthen the technical foundation of their security program. This role will focus on security automation, infrastructure protection, and proactive threat detection, ensuring security is integrated into development and operational processes.

Responsibilities

Champion and enable DevSecOps practices by embedding security controls into CI/CD and infrastructure pipelines
Manage and automate GitHub Enterprise and JFrog environments using Infrastructure-as-Code principles
Operate, optimize, and maintain SIEM, DLP, and centralized logging platforms, including detection logic and alerting rules
Partner closely with engineering teams to design and implement secure-by-default infrastructure and workflows
Lead end-to-end penetration testing initiatives, from scoping and vendor coordination to remediation tracking and follow-up

Qualification

DevSecOps practicesSecurity automationSIEM/DLP platformsPythonInfrastructure-as-CodeIdentity managementSecurity frameworksGoGitHubJFrogGoogle WorkspaceOktaAuth0OIDC/SAMLSOC 2NISTCISOWASP

Required

5+ years of experience in security engineering
Champion and enable DevSecOps practices by embedding security controls into CI/CD and infrastructure pipelines
Manage and automate GitHub Enterprise and JFrog environments using Infrastructure-as-Code principles
Operate, optimize, and maintain SIEM, DLP, and centralized logging platforms, including detection logic and alerting rules
Partner closely with engineering teams to design and implement secure-by-default infrastructure and workflows
Lead end-to-end penetration testing initiatives, from scoping and vendor coordination to remediation tracking and follow-up
Strong automation skills (Python, Go) and proficiency with infrastructure-as-code (Terraform)
Deep understanding of identity management, SSO, and federation (Google Workspace, Okta, Auth0, OIDC/SAML)
Familiarity with SOC 2 and security frameworks (NIST, CIS, OWASP)

Preferred

DevSecOps practices, integrating security into CI/CD pipelines
Managing and automating users/groups on AWS, GitHub, JFrog
Experience implementing and improving software supply chain security, integrating security into CI/CD pipelines (e.g., GitHub Actions)
Operating and tuning SIEM/DLP platforms and writing detection rules

Company

Block MB

twitter
company-logo
Specialised IT-Infrastructure and Security Recruitment company, operating in the Germany, the UK and the US.

Funding

Current Stage
Early Stage
Company data provided by crunchbase