SIGN IN
Staff Security Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

Assured · 2 weeks ago

Staff Security Engineer

Assured is on a mission to modernize insurance by providing large insurers with software solutions to enhance claims processing. They are seeking a Staff Security Engineer to scale and mature security across their platform, partnering with engineering, infrastructure, and product teams to embed security in their software development processes.
FinanceProperty & Casualty InsuranceFinancial ServicesInsuranceInsurTech

Responsibilities

Lead security architecture and design reviews across applications, infrastructure, and integrations to ensure secure patterns are embedded early in the development lifecycle
Conduct and coordinate penetration testing, threat modeling, and security reviews for critical services, new features, and third-party integrations
Design and implement security automation within CI/CD pipelines to ensure secure coding practices and infrastructure policies are enforced at scale
Partner with infrastructure and DevOps teams to secure cloud platforms (AWS) and improve identity, network, and workload security
Build security observability and detection capabilities, including security data pipelines, SIEM integrations, and threat intelligence signals
Think like an attacker—identify systemic weaknesses and design controls that protect against entire classes of attacks, not just individual vulnerabilities
Work closely with developers to improve security practices through secure architecture guidance, code review support, and developer enablement
Lead incident response investigations and help build processes for identifying, analyzing, and mitigating security incidents
Own and evolve the bug bounty program, including triage, response processes, and improvements to vulnerability management workflows
Develop security standards, playbooks, and training programs that make security practices easier for engineering teams to adopt
Help define the security roadmap, identifying initiatives that improve both risk posture and operational efficiency

Qualification

Application SecurityCloud SecurityOWASP Top 10MITRE ATT&CKPythonTypescriptAWSIAMContainer SecurityDevSecOps PipelinesSASTDASTInfrastructure as CodeTerraformAnsibleSIEM PlatformsPenetration TestingThreat ModelingSecurity ArchitectureSecurity Incident ResponseBug Bounty Program ManagementSecurity FrameworksCIS BenchmarksNISTSOC2 CompliancePCI ComplianceHIPAA ComplianceKubernetesSecurity TelemetryThreat Intelligence

Required

Deep understanding of application security, cloud security, and modern threat landscapes, including common vulnerabilities and attack techniques (OWASP Top 10, MITRE ATT&CK, etc.)
Strong software engineering background with experience writing production-grade code or automation (Python, Typescript, or similar)
Hands-on experience securing cloud-native infrastructure, especially AWS, including IAM, networking, and containerized workloads
Experience building or integrating DevSecOps pipelines, including SAST, DAST, IaC scanning, and container security tooling
Experience designing security telemetry pipelines using tools such as SIEM platforms, observability systems, or data lakes
Experience running or participating in penetration testing, threat modeling, or architectural security reviews
Proven ability to collaborate effectively with engineering, DevOps, and product teams to drive secure design decisions
Excellent communication skills and the ability to clearly explain complex security risks and trade-offs to both technical and non-technical stakeholders
Strong understanding of SaaS architectures, distributed systems, and internet-facing platforms
Experience developing security frameworks aligned with CIS benchmarks, NIST, or SOC2 / PCI / HIPAA compliance requirements
Experience building security detections, threat intelligence pipelines, or runtime protection mechanisms
Hands-on experience with Kubernetes, container security, and infrastructure-as-code (Terraform, Ansible)

Benefits

Competitive salary and equity packages for all employees
Platinum medical, dental, and vision
Free life insurance: Including long-term disability & short-term disability
Unlimited PTO: Uncapped vacation days & paid holidays
Family Leave: Maternity & paternity
401(k) Contribution: Assured contributes 3% of your income, even if you don't contribute
WFH Benefits: Lunch on us 2x/week, monthly phone stipend & other home office perks
Health FSAs & HSAs: Pre-tax accounts for out-of-pocket medical expenses
Team events & Offsites: We're remote, but we regularly get together

Company

Assured

linkedincrunchbase
company-logo
**We have been made aware of individuals falsely posing as recruiters from Assured Insurance Technologies Inc.

Funding

Current Stage
Growth Stage
Total Funding
unknown
2025-03-04Series Unknown
2021-01-01Seed

Leadership Team

leader-logo
Justin Lewis-Weber
Founder/CEO
linkedin
Company data provided by crunchbase