Senior Security Engineer

Skills
C#Software As A ServiceAdoptionCommandISO 27001ISO StandardsModeling
Role

What the job involves

The main requirements, responsibilities and hiring steps.

Requirements

  • 5-7+ years of experience as a Security Engineer or Software Engineer with strong security focus
  • Proven ability to build and operate production-quality software automation and internal tooling
  • Strong understanding of application security infrastructure security cloud security secure CI/CD practices and corporate security controls
  • Hands-on experience with vulnerability management secure software development threat modeling remediation workflows and operational security improvements
  • Experience with security frameworks and standards such as OWASP NIST CIS Controls SOC 2 and ISO 27001
  • Experience supporting SOC 2 compliance efforts through practical automated and auditable controls
  • Familiarity with cloud security platforms such as AWS Security Hub Azure Security Center or GCP Security Command Center
  • Experience with SIEM/SOAR tools logging and monitoring platforms detection workflows and practical incident response processes
  • Experience with Infrastructure-as-Code security scanning for tools such as Terraform or CloudFormation
  • Ability to translate complex security concepts into clear actionable guidance for technical and non-technical audiences
  • Experience collaborating closely with engineering IT compliance and business teams to improve security outcomes
  • Familiarity with C# modern backend systems cloud-native architecture and SaaS business tooling

Nice to have

  • Pragmatic
  • Collaborative
  • Strategic
  • Curious
  • Resilient
  • Accountable
  • Emotionally intelligent

Day to day

  • Strengthen Later's security posture through hands-on engineering and pragmatic security standards.
  • Assess applications infrastructure cloud environments corporate systems vendor tooling and business workflows to identify risks and drive remediation.
  • Build internal security tools automation and controls for secure development compliance workflows vulnerability management and incident response readiness.