Security Engineer II (Defensive)
Core
Integrate automated security tooling into engineering pipelines and protect cloud-native applications and generative AI features against security risks.
Role type
Mid-level IC security engineer (defensive/cloud)
Builds
Automated security controls, IaC scans, and LLM-based security review workflows for pull requests
Domain
Cloud security, DevSecOps, Generative AI security
Deliverable
production ML models | product features | infrastructure
Required skills
Application security, Cloud security, Infrastructure as Code (IaC), Container security, Source code auditing, API security, Python/Java/Node.js, CI/CD pipelines, OWASP Top 10 for LLMs
Preferred skills
Zero Trust architecture, Risk-based decision making, Incident response, Technical risk communication
Technologies
Terraform, AWS, Docker, Kubernetes, CI/CD pipelines
Responsibilities
Support integration of automated security requirements and validation tooling into engineering pipelines; Build and maintain internal security tooling and automated controls; Perform Infrastructure as Code security scans; Contribute to cloud IAM reviews and maintain Zero Trust boundaries; Configure and run automated LLM-based security review workflows; Support source code audits and API security reviews; Provide actionable feedback on code and configuration issues; Collaborate with software, SRE, DevOps, and product teams; Support risk-based decisions and transparent communication during active security incidents.
Seniority
Mid-level, hands-on IC