Security Engineer II
Pantheon Systems, Inc
About Pantheon Pantheon WebOps Platform powers the open web, running more than 300,000 sites in the cloud for customers including Google, Princeton, Salesloft and Doctors Without Borders. Every day, thousands of developers and marketers create, iterate, and scale WordPress and Drupal sites to reach billions of people globally. Pantheon's multitenant, container-based platform enables organizations to manage all of their websites from a single dashboard. Organizations including Clorox and the United Nations drive results through accelerated development and real-time publishing using Pantheon's collaborative workflows. The Role Pantheon's Security Engineering team is responsible for safeguarding, auditing, and testing the security of Pantheon's entire platform. Our Security Engineering team aims to create a comprehensive and multi-dimensional approach to application security, with a focus on Security by Design in agile software development and cloud native environments. We are seeking a Security Engineer II to join our growing team. This role bridges execution and tooling — you'll own security domains end-to-end while building the automation and processes that multiply the team's impact across engineering. This is a hands-on engineering role: you'll write detection rules, build vulnerability management tooling, implement supply chain security controls, and develop the automation pipelines that make security scale. Our mission is to safeguard, audit, and test the security of the entire cloud hosting platform in these core areas: Security by Design: Implement "Security by Design" within agile software development and cloud-native environments. Security Tooling & Automation: Build and maintain security tooling and automation that scales the team's impact beyond what manual processes can achieve. Support and Mentorship: Act as a Subject Matter Expert (SME), mentoring and supporting security engineering efforts across the organization. Standard Setting: Contribute to application security policy, process, standards, and guidelines — and build the tooling that enforces them. Application Security Performance: Help engineering teams design and build high-performing, secure applications by mitigating security issues in a risk-based manner. What You Will Do Detection Engineering: Author SIEM detection rules and response playbooks in Chronicle / Google SecOps (YARA-L), expanding coverage across Pantheon's security monitoring surface. Security Tooling Development: Build and maintain security automation pipelines (Python/Go) — vulnerability management tooling (vulntools, Wiz scripts), GHAS automation, and CI/CD security integrations. Vulnerability Management: Own vulnerability identification, triage, and remediation coordination with engineering squads across application (SAST/DAST/SCA) and infrastructure layers. Supply Chain Security: Implement supply chain security controls (Aikido, SLSA, dependency pinning) and integrate them into engineering workflows. Access & Identity: Execute RBAC cleanup, access architecture implementation, and periodic user access reviews. Manage GitHub org-level security policies and access controls. Cloud Security: Execute CSPM baseline findings triage, cloud security baseline validation, and data warehouse security implementation (Snowflake). DLP & Secrets: Define DLP policies and evaluate tooling; execute credential and secrets hygiene programs (plaintext credential remediation in repositories). What You Need to Succeed Builder Orientation: You measure impact by what you ship — tooling that engineering teams adopt, automation that replaces manual work, detection rules that catch real threats. Not by tickets closed or alerts triaged. Communication: Strong communication skills essential for partnering with engineering teams across the organization. You advocate for security priorities and tradeoffs across functions without being prompted. Commitment: Demonstrated commitment to teamwork, professionalism, and authenticity, fostering trust and accountability. Grit: Understanding that establishing security best practices is a marathon requiring persistence across many stakeholders. What You Bring to the Table Overall Experience: Minimum of 4+ years of overall experience, with at least 2+ years dedicated to Application Security or Security Engineering. Security Tooling: Demonstrated experience building security automation — vulnerability management scripts, CI/CD pipeline integrations, detection rules, or similar tooling that engineering teams use in production. Development Practices: Hands-on experience with Secure by Design development practices, including participating in security architecture and design reviews. Cloud Proficiency: Experience securing production systems in cloud environments (GCP preferred; AWS or Azure also valuable). Coding Proficiency: Ability to build maintainable components in Python or Go. You write tools, not just policies. CI/CD Fundamentals: Hands-on experience with Jenkins, Cloud Build, CircleCI, or similar (bonus points for experience with reusable workflows). Cloud & Infrastructure: Experience working with containerization (e.g., Docker, OCI), Terraform, and Kubernetes (K8s). Security Tooling Platforms: Experience with SAST/DAST/SCA/CSPM tools. Familiarity with CodeQL, Wiz, or similar platforms is a plus. Education: Bachelor's degree (preferred) in Computer Science or equivalent practical experience. What We Offer We have all the usual perks and benefits but what we can really offer you is a fantastic work environment powered by an amazing team. Industry competitive compensation and equity plan Flexible time off, sick days, and 13 paid holidays Comprehensive medical insurance including Health, Dental and Vision Paid parental leave (plus fertility, adoption and other family planning benefits) In-office workspace (San Francisco & Chicago) Monthly allowance for wellness, reading and access to LinkedIn Learning for continued development Events and activities both team-based and company wide that inspire, educate and cultivate Compensation: CAD $94,000 - 118,0000 annual salary plus bonus and equity Pantheon is an equal opportunity employer and we welcome applications from all backgrounds regardless of race, color, religion, sex, national origin, ancestry, age, marital status, sexual orientation, gender identity, veteran status, disability, or any other classification protected by law. Pantheon complies with federal and local disability laws and makes reasonable accommodations for applicants and employees with disabilities. If you need a reasonable accommodation due to a disability for any part of the interview process, please contact View email address on click.appcast.io. Pursuant to local and federal regulations, Pantheon will consider qualified applicants with arrest and conviction records for employment. After an offer is made and accepted, E-verify will be utilized to establish your identity and employment eligibility as required by the U.S. Department of Homeland Security. Visa Sponsorship is not available at this time. #J-18808-Ljbffr
$149k - $235k
...AWS, GCP, and self-managed Kubernetes, backed by self-managed data stores such as MongoDB. We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual contributor and technical leader for cloud security. This...SuggestedWork at officeLocal areaFlexible hours- ...committed to the highest standards of data security and privacy protection. To learn more... ...in lockstep to deliver SOC 2 Type II audit readiness by Q4 2026. Cloud & Infrastructure... ...via JIT/CIEM. SIEM Build & Detection Engineering - Deploy the SIEM platform and author 30+...SuggestedWorldwide
$174.5k - $240k
...community, come join ours.About the role:As a Senior Enterprise Security Engineer, you will help protect Faire's corporate environment across... ...audits for frameworks such as ISO 27001, SOX, and SOC 2 Type II.Strong written and verbal communication.Analytical, outcomes-driven...SuggestedWork experience placementWork at officeLocal areaRemote workMonday to FridayFlexible hours3 days per week$220k
...Venture Partners, and Craft Ventures.The Security Team @ PaveSecurity at Pave protects the... ...across domains. As Pave's Corporate Security Engineer, you'll own the corporate side of that... ...compliance operations behind our SOC 2 Type II and ISO 27001 programs, with an explicit...SuggestedWork at officeFlexible hours$275k - $300k
...at Postman.About the TeamThe Information Security organization at Postman operates across three... ...-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance... ...for a Principal Offensive Security Engineer who is as much a strategist as they are a...SuggestedFull timeWork at officeFlexible hours3 days per week$237.6k - $297k
We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...Full time$183k - $247.6k
...underserved communities around the world.We are a specialized security team that sits inside a global satellite communications business... ...mitigation plans- Experience in threat hunting, detection engineering, or product/application security, including moving from a security...Permanent employmentLocal areaImmediate startFlexible hoursShift work$10 per hour
...impact business, society, and the environment? Come join us.All security disciplines work under the umbrella of the combined PSI (... ...Infrastructure) team: we build the paved path and tooling that hundreds of engineers around the world rely on every day to ship. Corporate Security...Work at officeImmediate startRelocationRelocation packageFlexible hours$200k - $220k
...employees, their laptops, their identities, and the SaaS apps they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our workforce and corporate environment safe. This is a security engineering...Work at officeLocal area$266k
...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are... ...engaging a robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for identifying and...Work at officeRemote workRelocation packageFlexible hours$82.6k - $162.8k
...clients to operate with resilience, grow with confidence, and proactively manage to secure success. Recruiting for this role ends on 12/31/2026. Work you'll do As a Managed Services Engineer II on the Cyber Operate Offering team, you will be responsible for helping develop,...Local areaVisa sponsorship- ...Application Security Engineer Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million...Work at officeRemote workRelocation packageShift work
$320k - $405k
...whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role Corporate Security protects the environment Anthropic's people work in every day:...Work at officeVisa sponsorshipFlexible hours$266k - $385k
...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are... ...engaging a robust security culture.About the RoleAs a Security Engineer on Detection & Response, you’ll help protect OpenAI’s most...Work at officeLocal areaFlexible hours$153k - $376k
...together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us!As a Security Engineer you will identify and drive impactful projects to improve the security of Figma’s product, platform, and IT systems. We are...Minimum wageFull timeLocal areaRemote workFlexible hours$232k - $290k
...your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest technical expert at the intersection of artificial intelligence and security...Full timeWork at officeLocal area$266k
...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are... ...security culture.About the RoleOpenAI is seeking a Security Engineer to join our Infrastructure Security (InfraSec) team. InfraSec protects...Work at officeLocal areaRemote workFlexible hours- ...Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology... ...and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver...Full timeLocal area
$189k - $255.5k
...continuing to invest heavily in building the best creator platform with the best team in the creator economy and are looking for a Security Engineer to support our mission.This role is Fully Remote (US only), or can be based in New York or San Francisco (where it is open to...Work at officeLocal areaRemote workWorldwideFlexible hours3 days per week$180k - $280k
...sensitive data and privileged access they need to get issues fixed.You'll lead application security across our SaaS and AI products as part of our infrastructure team within Engineering. Working directly with product managers and other engineers, you'll establish our...Shift work$204k - $240k
...to join us on our journey to create a better future of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a staff security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems...Full timeWork at officeLocal area$300k - $320k
...whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the Team The Security Engineering team's mission is to safeguard our AI systems and...Visa sponsorship$159.3k - $202.4k
...sure to explore our Interviewing Guide to learn how to ace our interview process.About the RoleTwitch is looking for a Security Incident Response Engineer to join our SIRT. Reporting to the SIRT Manager, you'll be at the heart of our mission to find, handle, and learn...Flexible hours$208k - $312k
...products that help builders move from idea to production with speed, security, and exceptional developer experience.Now, software is entering... ...what comes next.About the Role:We are looking for a Security Engineer to join our Detection Response team. In this role, you will be...Work at officeRemote workWork from homeWorldwideMonday to FridayFlexible hoursShift work- ...Seattle, Washington D.C., Raleigh, London, and Amsterdam.The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s... ...resilient, and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into...Work experience placementWork at officeLocal areaShift work
$165k - $200k
...single API, Merge Agent Handler, which empowers AI agents with secure access to thousands of third-party tools, and Merge Gateway,... ...product development, unblock sales, reduce customer churn, and save engineering resources—allowing them to focus on their core product.Merge...Full timeWork at officeHome office$146k - $240k
...scalers to join us on our journey to create a better future of work with AI. About the roleJoin WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's transforming how the world works. You'll build sophisticated...Full timeWork at officeLocal area- ...product design questions, and it puts product security on the critical path of every enterprise deal we close. We are looking for the engineer who owns that. This is a hands-on role... ...as untrusted input. SOC 2 Type I/II, ISO 27001, or similar audits taken end to...Work at officeFlexible hours
- ...Cloud Security Engineer BackOps AI is transforming supply chain operations with agentic AI solutions that automate complex workflows, freeing... ...automation tooling Experience supporting SOC 2 Type I/II, SOC 3, ISO 27001 certification, or similar audits end-to-end...Remote workFlexible hours
- ...and Access Management (IAM) team is dedicated to ensuring the secure and efficient management of user identities, access privileges,... ...the Role As an Identity and Access Management (IAM) Security Engineer, you will play a crucial role in designing, implementing, and scaling...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer II. Be the first to apply!
- application security engineer San Francisco, CA
- principal security engineer San Francisco, CA
- senior cloud security engineer San Francisco, CA
- cloud security engineer San Francisco, CA
- aws cloud security engineer San Francisco, CA
- security software engineer San Francisco, CA
- sr information security engineer San Francisco, CA
- physical security engineer San Francisco, CA
- network security engineer San Francisco, CA
- dlp security engineer San Francisco, CA


