- Company Name
- Pebl
- Job Title
- Senior Security Engineer
- Job Description
-
**Job Title**
Senior Security Engineer
**Role Summary**
Lead security initiatives for a cloud‑first platform, ensuring compliance with global standards (GDPR, HIPAA, OWASP, SOC 2, ISO). Design, implement, and operate secure DevSecOps pipelines, infrastructure, and application security controls. Act as a technical advisor, incident responder, and partner with engineering and product teams to embed security best practices throughout the SDLC.
**Expectations**
- 5+ years of hands‑on experience in DevSecOps, cloud provisioning, CI/CD pipeline security, and incident response.
- Proficiency with public cloud providers (AWS, Azure, or GCP) and container platforms (Docker, Kubernetes, serverless).
- Advanced scripting (Python, TypeScript) and automation (Terraform, GitHub/GitLab CI).
- Deep knowledge of web, network, and application security (OWASP Top 10, API security, container security).
- Ability to evaluate risk, prioritize findings from static/dynamic scans, and drive remediation.
- Strong analytical, problem‑solving, and communication skills for cross‑functional collaboration.
**Key Responsibilities**
- Architect and enforce security‑first cloud designs and patterns.
- Build and maintain secure CI/CD pipelines, integrating static/dynamic analysis, secret scanning, and dependency checks.
- Conduct risk assessments, vulnerability management, and incident response for mission‑critical systems.
- Deliver security guidance on performance, cost, and architecture to development teams.
- Automate security controls in IaC, monitoring, and observability (Datadog, Prometheus).
- Produce metrics, reports, and dashboards to track DevSecOps KPIs.
- Mentor and educate teams on security best practices and compliance requirements.
**Required Skills**
- Cloud platforms: AWS, Azure, or GCP (IAM, VPC, RBAC).
- Container & serverless technologies (Docker, Kubernetes, Lambda/Functions).
- Automation tools: Terraform, CloudFormation, GitHub Actions, GitLab CI.
- Scripting: Python, TypeScript.
- Security frameworks: OWASP Top 10, SOC 2 Type 2, ISO 27001, GDPR, CCPA.
- Incident response, vulnerability management, risk prioritization.
- Observability & monitoring (Datadog, Prometheus, Grafana).
- Strong analytical and communication capabilities.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field (preferred).
- Certifications: CISSP, CISM, or equivalent security credential highly desirable.
- Additional DevSecOps or cloud security certifications (e.g., AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer) are a plus.