GoodLeap · 13 hours ago
Senior Security Engineer, Security Operations
GoodLeap is a technology company delivering financing and software products for sustainable solutions. The Senior Security Engineer role involves shaping the security and resilience of GoodLeap systems, working closely with various teams to design, implement, and operate security and fraud monitoring capabilities.
Responsibilities
Lead, participate in, and contribute to security and fraud monitoring, detection, and response activities, inclusive of investigations, threat hunting,etc. Create playbooks for specific incident response scenarios
Identify potential misuse and abuse cases in enterprise systems, propose solutions to detect these scenarios, and identify and implement monitoring and detection solutions for such scenarios
Support or develop components of the security analytics platform
Support embedded (product) security team
Support general security operations team with vulnerability management, tools management, and more
Qualification
Required
Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences
Expertise in security event management, monitoring, threat hunting, incident response, playbook creation, orchestration/automations, etc
Experience with threat modeling methodologies
Expertise with EDR solutions/platforms, such as CrowdStrike, S1, Palo Alto Cortex EDR, etc
Experience with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus)
Proven ability to establish credibility and build trust with business, engineers, and operational staff; confident yet humble
Experience designing, configuring, and implementing security and fraud monitoring for core enterprise systems, e.g., ERP, HCM, Salesforce, etc
Experience working with and creating solutions based AI and ML toolsets – e.g., creation of AI skills, agents, MCP clients, vibe coding
Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases
Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault
Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed
Prior experience interfacing and supporting teams outside of security – e.g., internal product teams and other cross-functional areas
Proficiency in writing automation scripts in multiple languages and integrating with REST/GraphQL APIs to orchestrate workflows between security tooling and third-party cloud/SaaS platforms, automating detection, response, and operational processes
Experience engaging with vendors in design partnerships
Experience overseeing vulnerability and threat management at the platform and application levels
Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement
Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution
Benefits
This role may be eligible for a bonus and equity
Company
GoodLeap
GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more.
H1B Sponsorship
GoodLeap has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (15)
2024 (13)
2023 (6)
2022 (7)
2021 (2)
Funding
Current Stage
Late StageCompany data provided by crunchbase