- Company Name
- Index Exchange
- Job Title
- Staff Security Engineer
- Job Description
-
**Job Title:** Staff Security Engineer
**Role Summary:** Lead the design, implementation, and maintenance of scalable security solutions across a global, high‑volume, low‑latency ad‑tech platform. Drive threat modeling, vulnerability management, incident response, and security policy enforcement while mentoring teams and integrating security best practices into the software development lifecycle.
**Expectations:**
- Analytical problem solver with strong written and verbal communication.
- Collaborative, cross‑functional communicator comfortable influencing stakeholders.
- Adaptive to change, highly self‑motivated, and accountable for ownership of security initiatives.
**Key Responsibilities:**
- Architect secure infrastructure for cloud, on‑prem, and hybrid environments.
- Conduct threat modeling and risk assessments; recommend and implement mitigation strategies.
- Manage vulnerability programs (scanning, penetration testing, remediation).
- Lead incident response activities, develop playbooks, and refine response plans.
- Build and automate security tooling (DLP, detection, remediation).
- Draft, enforce, and evolve security policies, standards, and compliance frameworks (ISO 27001, SOC 2, NIST, GDPR, PCI DSS).
- Embed security into SDLC (SAST/DAST, SBOM, secure coding practices).
- Mentor engineers, champion security awareness, and drive continuous improvement.
- Monitor emerging threats, evaluate new technologies, and recommend adoption.
**Required Skills:**
- 8+ years as a security engineer in a distributed, high‑throughput environment.
- Proficiency in securing cloud and on‑prem workloads (bare metal, virtual, container).
- OS hardening expertise for Linux and Windows.
- Network security knowledge: firewalls, IDS/IPS, WAF, VPNs, segmentation.
- Application security expertise (OWASP Top 10, secure coding, SAST/DAST).
- Scripting languages (Python, Bash, PowerShell) and IaC automation (Ansible, Puppet, Terraform).
- Experience with identity and access management (IAM, RBAC, MFA, SSO).
- Strong analytical, problem‑solving, and communication abilities.
**Required Education & Certifications:**
- Bachelor’s degree or higher in Computer Science, Cybersecurity, Engineering, or related field.
- Relevant industry certifications desirable: CISSP, CISM, CCSP, CCNA/CCNP Security, CEH, or equivalent.