Senior Security Engineer
Skills
C#Software As A ServiceAdoptionCommandISO 27001ISO StandardsModeling
What the job involves
The main requirements, responsibilities and hiring steps.
Requirements
- 5-7+ years of experience as a Security Engineer or Software Engineer with strong security focus
- Proven ability to build and operate production-quality software automation and internal tooling
- Strong understanding of application security infrastructure security cloud security secure CI/CD practices and corporate security controls
- Hands-on experience with vulnerability management secure software development threat modeling remediation workflows and operational security improvements
- Experience with security frameworks and standards such as OWASP NIST CIS Controls SOC 2 and ISO 27001
- Experience supporting SOC 2 compliance efforts through practical automated and auditable controls
- Familiarity with cloud security platforms such as AWS Security Hub Azure Security Center or GCP Security Command Center
- Experience with SIEM/SOAR tools logging and monitoring platforms detection workflows and practical incident response processes
- Experience with Infrastructure-as-Code security scanning for tools such as Terraform or CloudFormation
- Ability to translate complex security concepts into clear actionable guidance for technical and non-technical audiences
- Experience collaborating closely with engineering IT compliance and business teams to improve security outcomes
- Familiarity with C# modern backend systems cloud-native architecture and SaaS business tooling
Nice to have
- Pragmatic
- Collaborative
- Strategic
- Curious
- Resilient
- Accountable
- Emotionally intelligent
Day to day
- Strengthen Later's security posture through hands-on engineering and pragmatic security standards.
- Assess applications infrastructure cloud environments corporate systems vendor tooling and business workflows to identify risks and drive remediation.
- Build internal security tools automation and controls for secure development compliance workflows vulnerability management and incident response readiness.