Security Engineer
SambaSafety
Who we are: Hi, we're SambaSafety and we offer the industry's most comprehensive driver monitoring software. Our mission is promoting safer communities by reducing risk through data insights. Companies trust SambaSafety to keep their employees safe on the roads, price and reduce risk, help protect their brand, their bottom line, and our global community.
We've built an inclusive, supportive, and exceptional culture where every employee is empowered in their role. Don't take our word for it; we've been recognized as a Top Workplace by The Denver Post, Albuquerque Journal, Sacramento Bee, and Built In Colorado. And our employees rate SambaSafety as top-notch, with a rock solid Top Rating on Glassdoor. What You'll Do: We are seeking an experienced Security Engineer to join our growing security team in a multifaceted role that combines vulnerability management, application security, MITRE ATT&CK-based threat detection, AI-driven security automation, and security engineering expertise. This position requires a technical security professional with knowledge spanning cloud security, identity and access management (IAM), endpoint detection and response (EDR), SIEM administration, and hands-on scripting for automation development. The successful candidate will work closely with development teams, infrastructure teams, vendors, and internal stakeholders to optimize our security posture and manage enterprise risk. Key Responsibilities: Application Security & Vulnerability Remediation
We've built an inclusive, supportive, and exceptional culture where every employee is empowered in their role. Don't take our word for it; we've been recognized as a Top Workplace by The Denver Post, Albuquerque Journal, Sacramento Bee, and Built In Colorado. And our employees rate SambaSafety as top-notch, with a rock solid Top Rating on Glassdoor. What You'll Do: We are seeking an experienced Security Engineer to join our growing security team in a multifaceted role that combines vulnerability management, application security, MITRE ATT&CK-based threat detection, AI-driven security automation, and security engineering expertise. This position requires a technical security professional with knowledge spanning cloud security, identity and access management (IAM), endpoint detection and response (EDR), SIEM administration, and hands-on scripting for automation development. The successful candidate will work closely with development teams, infrastructure teams, vendors, and internal stakeholders to optimize our security posture and manage enterprise risk. Key Responsibilities: Application Security & Vulnerability Remediation
- Lead application security vulnerability remediation efforts across development teams
- Administer SAST tooling
- Administer DAST tooling
- Administer SCA and software composition / dependency scanning tools
- Triage and validate vulnerability findings to reduce false positives
- Provide remediation guidance to development teams on OWASP Top 10 and secure coding practices
- Integrate scanning tools with ticketing systems and CI/CD pipelines
- Generate AppSec metrics and reports
- Provide security code review support
- Administer vulnerability management platforms
- Configure scan policies, schedules, and asset groups
- Validate and prioritize vulnerability findings using risk-based prioritization (CVSS + context)
- Conduct expert analysis and risk scoring of vulnerabilities
- Coordinate remediation with IT and development teams
- Manage vulnerability exceptions and risk acceptances
- Track vulnerability aging and SLA compliance
- Generate management reports and dashboards
- Participate in product vulnerability management meetings
- Participate in Security by Design reviews
- Develop detection rules mapped to ATT&CK techniques
- Implement ATT&CK-based alert triage workflows
- Configure SIEM correlation rules using ATT&CK
- Conduct gap analysis of ATT&CK coverage
- Integrate threat intelligence feeds with ATT&CK mapping
- Build ATT&CK-based hunting queries
- Create ATT&CK-mapped incident reports
- Build and maintain scripted, cloud-based automation pipelines supporting the team's AI-driven security operations platform
- Develop and tune AI agent prompts, verdict logic, and disposition rules for automated alert triage
- Extend the team's internal tool-integration framework connecting security platforms for AI-assisted operations
- Integrate automation with SIEM, EDR, and ticketing systems
- Build automated enrichment and reporting workflows
- Monitor and tune agent/automation performance and disposition accuracy
- Develop custom integrations using APIs and cloud-native services
- Maintain observability for automated security workflows
- Lead Tier 2/3 security incident investigation and response
- Administer EDR, SIEM, and IAM platforms
- Implement and tune detection rules and alerts
- Manage cloud security configurations
- Support penetration testing and red team activities
- Conduct WAF/CDN rule audits and configuration reviews
- Provide security engineering expertise for infrastructure and application architecture decisions
- Support complex security investigations requiring deep technical analysis
- Contribute to security design reviews and technical security standards
- Draft and review security policies and procedures
- Conduct policy gap analysis against frameworks
- Analyze threat intelligence from multiple sources
- Integrate threat feeds into detection and automation workflows
- Implement IOC blocking and detection rules
- Participate in information sharing communities (ISACs)
- Create threat intelligence reports
- Bachelor's degree in Computer Science, Information Security, Engineering, or related technical field, or equivalent professional experience
- 5-7 years of experience in security engineering with demonstrated expertise in multiple security domains, including application security
- Expert knowledge of vulnerability management platforms
- Proficient in MITRE ATT&CK mapping for detection rules and incident response
- Strong experience with SAST, DAST, and SCA tooling for application security
- Deep understanding of application vulnerabilities (OWASP Top 10, injection flaws, XSS, authentication bypasses)
- Hands-on scripting experience building cloud-based automation (serverless functions, event-driven pipelines, secrets management)
- Experience with, or strong interest in, AI agent engineering and tool-integration protocols for security operations
- Proficiency administering EDR platforms
- Experience with SIEM administration
- Solid understanding of IAM platforms and federation/SSO concepts
- Proficiency in cloud security (AWS, Azure, or GCP)
- Solid understanding of WAF configuration and audit
- Proficiency in scripting and automation (Python required; PowerShell a plus)
- Understanding of DevSecOps and secure CI/CD practices
- Practical experience with AI-powered security tooling, including building or operating LLM-based agents, and awareness of emerging AI threats (prompt injection, tool/agent security risks)
- Ability to produce dashboards and reporting for technical and executive audiences
- SIEM administration
- Security automation/orchestration, including AI agent-based automation
- Vulnerability management platforms
- EDR platforms
- DLP platforms
- GRC platforms
- SAST tooling
- DAST tooling
- SCA / dependency scanning tooling
- Cloud security (AWS, Azure, or GCP)
- Threat intelligence platforms
- Ticketing and collaboration platforms
- Strong analytical thinking and problem-solving capabilities
- Excellent communication skills for technical and business audiences
- Strong Agile proficiency with ability to integrate security into sprint planning
- Experience collaborating with development teams and partnering on secure coding
- Ability to translate technical vulnerability findings into actionable remediation guidance
- Strong written communication skills for security documentation, audit responses, and questionnaire completion
- Act as escalation point for Security Analysts
- Participate in project security reviews
- Support sales team with security questionnaires
- Participate in customer security calls
- CySA+ (CompTIA)
- Cloud Security certification (AWS, Azure, or GCP)
- GIAC GSEC
- Certified Ethical Hacker (CEH)
- GIAC GWEB (Web Application Penetration Tester)
- CompTIA PenTest+ (optional)
- GIAC GCTI (Cyber Threat Intelligence) (optional)
- SIEM Platform Certification (optional)
- DevSecOps experience integrating SAST/DAST into CI/CD pipelines
- Secure software development lifecycle (SSDLC) implementation experience
- Compliance experience with SOC 2, ISO 27001, or industry-specific regulations
- Experience with security audit preparation and vendor risk assessment programs
- Threat intelligence analysis and integration experience
- Experience coordinating third-party penetration testing
- Security awareness training development and delivery
- Experience building or integrating LLM-based agents/automation for security operations
- Experience with container and Kubernetes security concepts
- Flexible and generous Paid Time Off and Paid Volunteer Days
- 401k Employer Match
- Generous Healthcare Benefits
- Up to 12 weeks paid time off for maternity leave based on tenure
- Wellness &Tuition Reimbursement
- Flexible Work Arrangements
- Lots of SambaSafety swag & SambaSafety Events
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Engineer in United States vacancy
- ...the sidelines.We're looking for builders, problem-solvers, and security professionals who thrive in a fast-paced environment where... ...security professionals.Collaborate effectively across security, engineering, development, infrastructure teams, app teams, and various levels...SuggestedPermanent employmentFull timePart timeH1bWork visaShift workDay shift
$178.4k - $226.7k
The Senior Security Engineer is a senior individual contributor responsible for independently driving security initiatives across multiple services and teams. This role requires deep technical expertise in application security, threat modeling, and secure system design,...SuggestedInternshipFlexible hours$159.3k - $202.4k
...communities around the world.Have you wanted an opportunity to secure an advanced satellite based broadband telecom service? The Amazon... ...builders who aspire to become security advocates & security engineers via 1-1 sessions & office hours.You will assist Red Teams in identifying...SuggestedPermanent employmentInternshipWork at officeFlexible hours$178.4k - $226.7k
At Amazon Web Services (AWS), Security is our highest priority. We are looking for a passionate, innovative, results oriented Security Engineer. Security Escalations is responsible for driving innovative enhancements that raise the bar for how AWS employees interact with...SuggestedInternshipFlexible hours- ...enterprise software architectures that support the bank’s information security operations functions. This role performs feedback and... ...bank. The position serves as a technical resource for security engineering initiatives, applying advanced knowledge to evaluate, build, and...SuggestedRemote work
$159.3k - $202.4k
Amazon Healthcare Security's (HealthSec) Security Operations team is hiring a Security Engineer to be the first line of defense to our most critical customer data. You will be a guardian of healthcare information and work with Amazon Healthcare products to secure customer...Flexible hours$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats...InternshipFlexible hours$159.3k - $202.4k
Amazon Healthcare Security's (HealthSec) Detections & Monitoring team is hiring a Security Engineer II to design, build, and operate detection and monitoring capabilities that protect Amazon Health Services (AHS) across cloud infrastructure, applications, endpoints, and...Flexible hours$159.3k - $212.8k
...to no-checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As a Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services...InternshipFlexible hours- ...solutions that enhance maritime operations through autonomous and intelligent platforms.Security at Saronic is a force multiplier, not a blocker. We’re looking for a Security Engineer for Application Security to empower our teams to ship fast without trading away safety...Permanent employment
$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience... ...Services. Apart from work, we provide opportunities for our engineers to pursue projects they are passionate about while maintaining...InternshipFlexible hours$136k - $184k
The AWS Hardware Supply Chain Security (HSCS) Team is looking for a Security Engineer to help guide our global hardware supplier and manufacturing security program. You will work with a team of professionals around the world to help assess and mitigate risks in partner...InternshipFlexible hoursShift work$165k - $242k
...CRWV) in March 2025. Learn more at .What You’ll Do:The Enterprise Security team at CoreWeave is responsible for securing how our people... ..., this is the team to join.About the Role:As a Senior Security Engineer, Enterprise Security, you’ll design and ship the security controls...Permanent employmentFull timeTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours$100k - $120k
...manufacturing, turning abstract ideas into realities that transform the world for good. Your impact The Endpoint Security & Exposure Management Engineer is responsible for the design, implementation, administration, and continuous improvement of endpoint security controls...Full time$237.6k - $297k
We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...Full time$136k - $184k
...to no-checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As a Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services...InternshipFlexible hours$178.4k - $226.7k
The Ads Security organization at Amazon is dedicated to creating innovative technical solutions that detect, assess, and mitigate security... ...inherently secure. We are seeking a talented Senior Security Engineer to join our team, where you will have the opportunity to...Flexible hours$167.5k - $226.3k
...team.Our ValuesIf this sounds like you, you’ll fit right in.Who You AreJustworks is looking for an experienced, hands-on Senior Security Engineer specializing in AI who will drive and execute the company’s AI strategy and Digital Security’s objectives. Our ideal candidate...Casual workWork at officeLocal area$128.9k - $180k
...passionate team at your back. If Braze sounds like a place where you can thrive, we can’t wait to meet you.WHAT YOU'LL DOAs a Senior Security Engineer on the Enterprise Security team, you'll protect Braze employees, their assets, and work locations using various tools and...Work at officeLocal area- Position: Senior Security Engineer - PKI & Detection, Aircraft SecurityLocation: Fort Worth Texas (Hybrid - onsite Tuesday through Thursday; remote Monday and Friday)Duration: ContractJob ID: 178660Job Overview:We are seeking a Senior Security Engineer to support aircraft...Full timeRemote workMonday to Friday
$183k - $247.6k
The ideal candidate will have a broad understanding of proactive security, have past experience leading security assessments, and have the ability to work with product and engineering teams in designing secure systems. In this role, you will conduct secure design reviews...InternshipLocal areaFlexible hours$147k - $210k
...) tooling to scale advanced vulnerability research, defensive engineering, and mitigation strategies across the organization.Participate... ...into our VRP pipeline to improve efficiency.Conduct deep-dive security research into Android vulnerabilities and threat vectors, converting...$159.3k - $202.4k
We're looking for a Security Engineer to join the team that secures the foundational compute and networking systems powering AWS — the systems behind EC2, Nitro, EBS, VPC, and more.You'll work directly with service teams across some of the most critical systems in cloud...InternshipFlexible hours$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...InternshipRemote workFlexible hours$146.3k - $257.7k
...scalers to join us on our journey to create a better future of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems...Full timeWork at officeLocal area$183k - $247.6k
...part of this goal is achieved through the work of our dedicated security teams. Our attack surface spans over consumer devices, mobile... ...and apply appropriate technologies while following security engineering best practices. You are also expected to mentor more junior engineers...InternshipLocal areaFlexible hours$200k - $220k
...employees, their laptops, their identities, and the SaaS apps they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our workforce and corporate environment safe. This is a security engineering...Work at officeLocal area$136k - $184k
Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role, you will work alongside other Threat Hunting engineers to proactively...InternshipFlexible hoursShift work- Senior Security Engineer- Product SecurityAugusta, GaWork Location & ScheduleThis is a hybrid position based in our Augusta, GA office. Team members are expected to work on-site two days per week in our Augusta office and remotely three days per week. This schedule supports...Full timeTemporary workFor contractorsFixed term contractWork at officeRemote workFlexible hours2 days per week3 days per week
$159.3k - $202.4k
The Corporate Services Security (CPSS) Finance and Communication Security (FCS) Team is responsible for securing the applications, infrastructure... ...make your own life easier and share that benefit with all our engineers globally.Contribute to recruiting activities, mentoring and...Flexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!
Related searches
- security engineering manager United States
- application security engineer United States
- sr information security engineer United States
- sr security engineer United States
- entry level security engineer United States
- senior application security engineer United States
- staff security engineer United States
- information system security engineer United States
- junior security engineer United States
- security project engineer United States
