Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Infrastructure Security Engineer

Macy's Backstage

Infrastructure Security Engineer

At Cast & Crew, we've empowered creativity and supported the global entertainment industry for decades. Together with our family of brands, we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools. The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater. We are a production's best ally every step of the way. #OneCastOneCrew

We are looking for an Infrastructure Security Engineer to run the operational core of our offensive and vulnerability management programs. You will own the tooling that continuously tests our environment — bug bounty, agentic red team, CSPM, and vulnerability scanners — turn the output of those platforms into a prioritized, de-duplicated set of real issues, and drive them to verified closure with engineering and infrastructure teams. This is a hands-on, highly cross-functional role for someone who is as comfortable validating an exploit as they are chasing a fix to completion.

We are also looking for someone who is genuinely curious and learns fast. Our security stack changes quickly, and a meaningful part of this role is exploring, testing, and deploying emerging security products — including tooling built on the latest AI capabilities — evaluating whether they actually work in our environment, and putting the ones that do into production.

Core Responsibilities
  • Oversee day-to-day operation of the bug bounty program, including program scope, policy, response targets, and researcher communications.
  • Triage inbound submissions: reproduce and validate findings, de-duplicate against known issues, assign severity, and reject out-of-scope or invalid reports with clear rationale.
  • Make and defend bounty award decisions in coordination with the platform provider and Security leadership.
  • Route confirmed findings to the owning engineering or infrastructure team, track them to closure, and verify fixes before the report is closed.
  • Use recurring submission patterns to drive systemic fixes, scope adjustments, and secure-development feedback rather than one-off patches.
  • Manage and operate enterprise vulnerability scanners across cloud, on-premise, and hybrid assets, ensuring coverage of the full asset inventory and investigating scanning gaps.
  • Configure, tune, and maintain scan policies, credentialed scanning, authenticated checks, and scan schedules to maximize signal and minimize disruption.
  • Triage and prioritize findings using exploitability, asset criticality, and business context (e.g., CVSS, EPSS, CISA KEV, threat intelligence).
  • Assign findings to the correct engineering and infrastructure owners, negotiate remediation timelines, and verify remediation through re-scan or manual validation.
  • Track remediation against SLAs, escalate aging findings, and manage the exception and risk-acceptance process with the GRC team.
  • Produce metrics and reporting on coverage, backlog, mean time to remediate, and SLA compliance for engineering and executive audiences.
  • Monitor emerging CVEs, assess applicability to our environment, and coordinate emergency patching when critical vulnerabilities arise.
  • Manage and operate the CSPM platform across our multi-cloud environment, including onboarding new accounts, subscriptions, and projects.
  • Tune policies and baselines, suppress noise, and maintain exception handling so that surfaced findings are consistently actionable.
  • Drive remediation of misconfigurations with cloud and platform owners, and verify that fixes hold over time.
  • Enforce least-privilege access principles and audit cloud permissions, IAM policies, security groups, SCPs, and guardrails on a recurring basis.
  • Support secure architecture reviews for new cloud infrastructure and services.
  • Manage and operate the agentic red-team pentesting platform, including target scoping, scheduling, credentials, and environment onboarding.
  • Define and enforce rules of engagement and safety guardrails so that automated testing does not disrupt production systems.
  • Validate platform output, eliminate false positives, and translate confirmed attack paths into concrete, owner-assigned remediation items.
  • Feed results into the same triage, prioritization, and verification workflow used for scanner and bug bounty findings so there is one prioritized view of risk.
  • Coordinate with third-party penetration testers and use platform coverage to focus manual testing where it adds the most value.
  • Research, pilot, and benchmark emerging security products, including AI-driven and agentic tooling, against real problems in our environment rather than vendor demos.
  • Run structured proofs of concept: define success criteria up front, test against known findings, and make a clear recommendation to adopt, defer, or reject.
  • Deploy and integrate selected tooling into existing workflows and ticketing, and own it operationally once it is in production.
  • Automate repetitive triage, enrichment, and reporting work so that engineering time goes to remediation rather than data handling.
  • Support enterprise network security infrastructure including firewalls, IDS/IPS, proxies, VPNs, and DDoS mitigation.
  • Perform firewall rule reviews and access control audits to reduce attack surface.
  • Investigate anomalous network activity surfaced by security tooling and escalate to incident response as needed.
Key Qualifications
  • 3–5 years of experience in infrastructure, network, or cloud security roles.
  • Experience running or supporting an enterprise vulnerability management program end-to-end, from scanner operation through verified remediation.
  • Demonstrated ability to triage security findings: reproduce issues, judge real-world exploitability, de-duplicate, and prioritize against business context rather than raw severity scores.
  • Deep, practical understanding of common vulnerability classes and how they are actually exploited — remote code execution, injection, cross-site scripting, SSRF, insecure deserialization, authentication and authorization bypasses, and denial-of-service and DDoS techniques — sufficient to assess real exploitability rather than defer to a scanner score.
  • Hands-on proficiency with security testing tooling, including Burp Suite for web application testing and Postman for API testing, along with comparable intercepting proxies and fuzzing tools.
  • Working coding ability, primarily Python and shell scripting, sufficient to automate triage and reporting, parse and enrich findings, build integrations between security platforms, and write or adapt proof-of-concept code to validate a finding.
  • Hands-on experience securing at least one major cloud platform (AWS, Azure, or GCP), including operating or responding to CSPM tooling.
  • Solid understanding of network protocols (TCP/IP, DNS, TLS) and perimeter security technologies.
  • Familiarity with security frameworks and standards (NIST CSF, CIS Benchmarks, ISO 27001) and the ability to translate control requirements into actionable technical configurations, including gathering, maintaining, and presenting evidence to support audit and assessment activities.
  • Strong written and verbal communication skills, with the ability to translate technical risk for non-technical stakeholders and to hold remediation owners accountable without escalating every disagreement.
  • Demonstrated curiosity and speed of learning: a track record of picking up unfamiliar tooling, evaluating new security products, and getting them into production use without extensive hand-holding.
  • Interest in applying emerging AI capabilities to security operations, and the judgment to distinguish tooling that meaningfully reduces risk from tooling that only adds noise.
Preferred Qualifications
  • Experience operating or triaging a public or private bug bounty program on a platform such as HackerOne, Bugcrowd, or Intigriti.
  • Offensive security experience: penetration testing, exploit validation, or red-team operations, including familiarity with automated or agentic testing platforms.
  • Experience with infrastructure-as-code security (Terraform, CloudFormation) and shift-left security practices.
  • Experience securing containerized workloads, including image hardening, registry security, runtime protection, and familiarity with orchestration platforms such as Kubernetes or ECS.
  • Experience developing security automation or internal tooling beyond scripting, including work with security platform APIs and CI/CD integrations.
  • Exposure to SIEM/SOAR platforms and security telemetry pipelines.
  • Familiarity with zero trust network architecture (ZTNA) and micro-segmentation.
  • Relevant certifications: AWS Security Specialty, CCSP, CISSP, OSCP, CompTIA Security+, or equivalent.
Special Work Conditions
  • Sedentary - Exerts up to 30 lbs. of force occasionally and/or a negligible amount of force frequently or constantly lift, carry, push, or pull. Involves sitting most of the time but may involve walking or standing
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Infrastructure Security Engineer in United States vacancy
  • $79.21k - $110k

     ..., and applications, working directly with client or internal infrastructure teams. Translate vulnerability findings into actionable...  ...remediation speed, consistency, and coverage. Collaborate with security, operations, and DevOps teams to integrate patching into CI/... 
    Suggested
    Full time
    Summer work
    Work at office
    Flexible hours

    Salem Five Bank

    Salem, MA
    10 days ago
  • $200k - $340k

     ...knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who...  ...ABOUT THE ROLE: We are seeking a talented and motivated Infrastructure Security Engineer to join our security team. In this role, you will... 
    Suggested
    Full time
    Temporary work
    Relocation

    SpaceXAI

    Washington DC
    10 days ago
  • $104k - $171.6k

    Job Classification:Technology - Engineering & CloudAre you interested in building capabilities that enable the organization with...  ...institutions. Your Team & RoleWe are looking for a motivated Senior Infrastructure Security Engineer to support the design, implementation and... 
    Suggested
    Full time
    Part time

    PGIM

    Newark, NJ
    2 days ago
  • $135k - $182.1k

     ...make an impact. Join us!LOB Overview:Global Information Security (GIS) is responsible for protecting bank information...  ...This role requires a solid technical understanding of Infrastructure Architecture engineering solution design experience, defining technical requirements... 
    Suggested
    Full time
    Work at office
    Shift work
    Day shift

    Bank of America

    Boston, NY
    2 days ago
  • $130k - $160k

     ...our outstanding work environments and opportunities for career growth and advancement.Our Technology team is seeking an Infrastructure Security Engineer to design, build, and secure the cloud, network, and identity infrastructure that runs a mixed-use real estate... 
    Suggested
    Full time
    Work experience placement

    JBG SMITH

    Bethesda, MD
    4 hours ago
  •  ...of people and we’re just getting started.About The RoleOur Security Engineering team builds intelligent systems that protect Opendoor and...  ...engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter,... 
    Work at office
    Monday to Friday
    Shift work

    Opendoor

    Miami, FL
    4 days ago
  • $80 - $110 per hour

     ...billing, and more. This company is highly invested in AWS infrastructure, security, automation and scalability to support insurance organizations...  .... What we are looking for is an infrastructure security engineer that is responsible for securing the AWS infrastructure that... 
    Full time
    Contract work
    Temporary work
    Remote work
    Worldwide
    Flexible hours

    Motion Recruitment

    Boston, MA
    4 days ago
  • $198.4k - $342k

    We are seeking a highly technical Infrastructure Security Engineer to join our Public Sector Infrastructure & Security team. Our Infrastructure Security Engineers ensure the security and integrity of our platform. You will be responsible for securing large cloud environments... 
    Full time

    Scale AI

    New York, NY
    2 days ago
  •  ...of times a day - quickly, reliably, and securely. Any time you swipe your credit card,...  ...a difference at Fiserv.Job TitleSenior Infrastructure Security EngineerSenior Infrastructure...  ...successful Senior Infrastructure Security Engineer do at Fiserv?Excited about shaping the... 
    Full time
    Temporary work
    H1b

    Fiserv

    Sunnyvale, CA
    1 day ago
  • $195k - $220k

     ...listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security & Infrastructure Engineer based in the United States. As a Senior Security & Infrastructure Engineer, you will own the security,... 
    Full time
    Remote work
    Flexible hours

    Jobgether

    Remote
    3 days ago
  • $120k - $130k

    Job DescriptionEverforth ECS is seeking an Network & Security Infrastructure Engineer to work in our Washington, DC office / remote. The role is contingent upon additional funding.We are seeking an experienced and technically versatile Network & Security Infrastructure... 
    Work at office
    Remote work

    ECS Federal

    Washington DC
    2 days ago
  •  ...possible, with the ultimate goal of enabling human life on Mars.SECURITY ENGINEER (EMBEDDED & NETWORKING)SpaceX is looking for a Security...  ...organizations.Network security systems and the backend infrastructure that powers such services.Application level security controls... 
    Permanent employment
    Remote work
    Weekend work

    SpaceX

    Cape Canaveral, FL
    1 day ago
  • $215k - $260k

     ...energy and intelligence . As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each...  ...and intelligence. We’re seeking a Senior Infrastructure Security Engineer dedicated to establishing a high-assurance security posture... 
    Full time
    Temporary work

    Crusoe

    San Francisco, CA
    3 days ago
  • Caltech is a world-renowned science and engineering institute that marshals some of the...  ...Job SummaryIPAC at Caltech is seeking a Security and Network Engineer to support the cybersecurity...  ..., and high-performance network infrastructure powering world-class NASA, NSF, and privately... 
    Permanent employment
    Casual work
    Remote work
    1 day per week

    California Institute of Technology

    Pasadena, CA
    1 day ago
  • $60 - $75 per hour

    Malvern, PennsylvaniaHybridContract$60/hr - $75/hrA financial institution is looking to hire a Network Security Engineer to serve as the team's Palo Alto subject matter expert. You'll work with Palo Alto, Cisco firewalls, and Cisco ISE. Ideal candidates have strong experience... 
    Full time
    Temporary work
    Work from home
    Flexible hours

    Motion Recruitment

    Malvern, PA
    4 days ago
  • A leading AI research company is hiring a Security Engineer to join the Infrastructure Security team. Responsibilities include designing security controls and collaborating with engineering teams to enhance security across infrastructure. Candidates should have a strong... 
    Remote work
    Flexible hours

    OpenAI

    United States
    1 day ago
  •  ...Security Engineer We're looking for a Security Engineer to join the ElevenLabs Security team. In this role, you'll work at the intersection of security, software and infrastructure engineering, building the platforms, controls and tooling that let teams ship and operate... 
    Remote work

    Eleven Labs

    United States
    2 days ago
  •  ...Lead Security & Infrastructure EngineerSan Francisco or Los Altos, CASummaryWe're a well-funded, stealth startup building a new end-to-end personal...  ...computing platform.As our Lead Security & Infrastructure Engineer, your responsibility is to build a high-performance,... 

    Anodize Inc

    San Francisco, CA
    2 days ago
  • $101k - $194k

     ...the #VTeamLife. What you’ll be doing The GN&T Network Security team has an opening for Engineer IV in the Network Access organization. This role will...  ...responsible for the respective function. Infrastructure Access Engineering – This team will design, build, and... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Work from home
    Shift work

    Verizon

    Cary, NC
    2 days ago
  •  ...The Information Technologies (IT) Security and Infrastructure Administrator is responsible for the design, implementation, administration, and...  ...Education Bachelors degree in computer science or engineering with any IT certification and a minimum of three (3) years... 
    Work experience placement

    Paragon Implant MFG LLC

    Los Angeles, CA
    4 days ago
  •  ...Infrastructure Security Engineer Social Discovery Group (SDG) solves the problems of loneliness, isolation, and disconnection - transforming virtual intimacy into the new normal. SDG's products redefine the way people interact and connect with one another. Our portfolio... 
    Full time
    Work at office
    Remote work
    Work from home

    Social Discovery Group

    United States
    1 day ago
  • $110k - $140k

     ...The opportunity to work on enterprise-scale infrastructure and cybersecurity initiatives, leveraging modern cloud and security technologies while helping shape HKA's global...  ...for a Senior Infrastructure and Security Engineer to play a key role in strengthening and evolving... 
    Worldwide

    HKA Birmingham

    Phoenix, AZ
    3 days ago
  •  ...NexGen Data Systems is seeking an Infrastructure Support Engineer to join its network engineering team. The role focuses on identifying, troubleshooting, and resolving outages across routers, switches, firewalls, and VPN devices, supporting DHA Medical Treatment Facilities... 

    NexGen Data Systems

    San Antonio, TX
    2 days ago
  •  ...Abridge is seeking a Senior or Staff Infrastructure Security Engineer to join our security team in NYC. You will lead the design and implementation of secure-by-default cloud infrastructure, data pipelines for security telemetry, and automations that scale with our AI... 

    Abridge

    New York, NY
    2 days ago
  •  ...Security Integration EngineerIK Systems is seeking a Systems Integration Engineer to configure, integrate, and commission enterprise security and low-voltage systems for...  ..., and supporting server and network infrastructure operate reliably before customer handoff.What... 
    Permanent employment
    Casual work

    IK Systems, Inc

    Buffalo, NY
    2 days ago
  • $155k - $175k

     ...Join us in San Diego, CA as an Infrastructure, Operations and Security Manager to lead our ITOpS group.This role reports into our Director of Technology...  ...team while partnering closely with Software Engineering and business leaders Manage vendor relationships, strategic... 

    Brandes Investment Partners

    San Diego, CA
    2 days ago
  •  ...is seeking a motivated Data Protection Engineer to support the Cybersecurity Data Protection...  ...Engineers to support Microsoft M365 security controls, data loss prevention...  ...enterprise technology, cybersecurity, infrastructure, systems administration, or a related technical... 

    Caesars Entertainment

    Las Vegas, NV
    3 days ago
  • $140k - $160k

     ...DevSecOps Engineer Remote Sphinx builds software to solve complex national security problems in Space. Founded by engineers and technologists with deep experience...  ...to help secure and scale the cloud-native infrastructure supporting our national security and space-... 
    Remote work
    Flexible hours

    Sphinx Defense

    United States
    2 days ago
  •  ...scientists, PhDs, creatives, technologists, and engineers working together to empower people and...  ...The Role Want to work on building out security from the ground up at the leading edge...  ...and highly motivated Senior or Staff Infrastructure Security Engineer to join our team as... 
    Hourly pay
    Full time
    Flexible hours

    Abridge

    San Francisco, CA
    2 days ago
  •  ...Infrastructure Security Engineer As an Infrastructure Security Engineer, you will partner directly with the Infosec team to lead the adoption, implementation and execution of security related policies, projects, and initiatives. This position sits with the Infrastructure... 
    For contractors
    Remote work
    Shift work

    InterSources

    United States
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Infrastructure Security Engineer. Be the first to apply!