Maximum of 25 job preferences reached.
Top Senior Security Engineer Jobs in San Francisco, CA
Artificial Intelligence • Cloud • Information Technology • Cybersecurity
Designs and implements secure cloud architectures, IL5 controls, STIG-aligned hardening baselines, identity integrations, and cybersecurity controls for federal and DoD-aligned platforms. Performs security assessments, vulnerability analysis, continuous monitoring, secure deployment reviews, audit support, and remediation planning. Requires expertise in AWS, NIST, RMF, PKI, SIEM, and cloud security, along with mentoring junior engineers and documenting technical architectures. The role is fully remote but requires an active Top Secret clearance and substantial security engineering experience.
Top Skills:
AWSDevsecopsIl5Infrastructure As CodeKubernetesNist Sp 800-53PkiRmfSIEMSsoStigsZero Trust
Consumer Web • Healthtech • Professional Services • Social Impact • Software
Lead product and application security by partnering with product and engineering to design secure features, perform code and architecture reviews, build AI-native security tooling, create developer guardrails, and support incident response, vulnerability management, and penetration testing to scale Headway's security program.
Top Skills:
Aws EcsAws FargateDatadogFastapiGitKafkaLaceworkPagerdutyPostgresPythonReactRedisS3SemgrepSnykSparkSqlalchemyTypescript
Software
The Senior Application Security Engineer strengthens secure coding and DevSecOps practices by deploying and tuning SAST, DAST, and IAST tools, interpreting scan results, conducting threat modeling, and integrating security controls into CI/CD pipelines. The role establishes application security metrics, automates security improvements, documents key processes, and partners with engineering teams to prioritize and remediate meaningful vulnerabilities. Responsibilities include securing AWS cloud applications, APIs, authentication, authorization, secrets, and infrastructure-as-code environments.
Top Skills:
AnsibleAPIsAWSBurpChefCi/CdCloudFormationDastIastInfrastructure As CodeJavaJavaScriptNessusPuppetPythonSaltSastTerraformWeb Application Firewalls
19 Days AgoSaved
Easy Apply
Easy Apply
Cloud • Security • Software • Cybersecurity • Automation
Own and evolve GitLab’s authorization systems across its Ruby on Rails monolith and next-generation Rust policy engine. Design fine-grained permissions for users, tokens, roles, and AI agents; secure GraphQL and REST APIs; lead feature-flagged rollouts and migrations; improve performance and reliability; and collaborate across authentication, platform, AI, and modular-service teams in a distributed asynchronous environment.
Top Skills:
CedarGoGraphQLGrpcProtocol BuffersRestRubyRuby On RailsRustYamlZanzibar-Style Authorization
Software
Secure AWS cloud environments through architecture and network reviews, IAM and policy guardrails, workload protection, monitoring, threat detection, encryption, runtime controls, and secure CI/CD automation. Develop scalable security tooling, including AI-augmented solutions, and establish secure integrations with third-party services. Partner with engineering, product, DevOps, and compliance teams through design reviews, code reviews, documentation, and technical guidance.
Top Skills:
Ai ToolsAuroraAWSAws Identity CenterAws OrganizationsCi/CdCloudtrailCloudwatchDynamoDBEcsEksFargateFirewallsGuarddutyIamIds/IpsInfrastructure As CodeKotlinLambdaLlm ToolsLoad BalancersPolicy As CodePythonS3Security GroupsService Control PoliciesTerraformTransit GatewayTypescriptVpc
Fintech • Financial Services
Conduct manual penetration tests and secure code reviews across web applications, APIs, AWS infrastructure, and AI systems. Develop AI-assisted security tooling, test LLM applications and agents, triage SAST findings, tune detection rules, support security reviews before production, and communicate risks and remediation priorities to engineering teams.
Top Skills:
Ai AgentsAPIsAWSGoLlmsPythonRubySastSecure SdlcTypescript
Artificial Intelligence • Machine Learning • Security • Software
Design, implement, and operate Apollo’s security controls across identity, cloud infrastructure, endpoints, and incident response. Build secure-by-default systems, evaluate security vendors, lead security projects, shape the roadmap, and promote effective security practices across the organization. Key initiatives include zero-trust migration, agentic SOC development, sandbox hardening, third-party access reviews, incident response, and penetration-testing tooling.
Top Skills:
Ai AgentsApplication SecurityCloud SecurityDetection EngineeringEndpoint ManagementGrc EngineeringIdentity And Access ManagementIncident ResponseJAMFKandjiProduct SecuritySandboxingZero Trust Architecture
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills:
Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling
Software • Defense
Own and improve Onebrief’s corporate security stack across endpoints, identity, SaaS, browsers, Zero Trust, EDR, SIEM, and MDM. Establish secure configuration baselines, detect and remediate drift, integrate telemetry, and build API-driven or infrastructure-as-code automation. Translate CMMC 2.0 and NIST-aligned requirements into continuously validated technical controls and reliable audit evidence. Partner with Corporate IT, Security Operations, GRC, and application owners to strengthen security posture and reduce manual compliance work.
Top Skills:
Configuration ManagementCrowdstrikeEdrGithub ActionsInfrastructure-As-CodeMdmMfaOktaOkta WorkflowsRest ApisSIEMSplunkSsoWebhooksWorkspace OneZero TrustZscaler
Aerospace • Artificial Intelligence • Hardware • Machine Learning • Software • Defense • Manufacturing
The Senior Embedded Security Engineer will enhance the security of the flight software for space vehicles, ensuring high standards for safety and secure coding practices throughout the development lifecycle.
Top Skills:
CC++CompilersDebuggersEmbedded SystemsIdesSecurity StandardsStatic Analysis Tools
Logistics • Transportation • 3PL: Third Party Logistics
Lead the strategy, architecture, and development of Uber’s enterprise endpoint security platform across macOS, Windows, and Linux. Drive vulnerability management, application security, scalable defense automation, and AI-enabled security operations. Establish technical direction, mentor engineers, promote engineering excellence, and collaborate across IT, product, and operations teams to improve security posture at cloud scale.
Top Skills:
AIAWSAzureEdrGCPGenerative AiGoJavaLinuxmacOSOciPythonWindows
18 Days AgoSaved
Healthtech
Designs, implements, and maintains enterprise IAM solutions across hybrid on-premises and cloud environments. The role drives Zero Trust modernization, identity automation, access governance, privileged access controls, threat monitoring, and automated response. Responsibilities include evaluating security technologies, mitigating identity risks, supporting compliance and audit readiness, and establishing security standards. The engineer collaborates with infrastructure, application, and security teams and participates in rotational on-call, weekend, and holiday support.
Top Skills:
Active DirectoryAzure AdAzure Logic AppsClaude CodeFirewallsGithub CopilotHipaaIntrusion Prevention SystemsIsoKerberosLan/WanLdapMicrosoft Entra IdMicrosoft Graph ApiMicrosoft Security CopilotNistOauthOidcPatch ManagementPower AutomatePowershellPythonRoutingSAMLSwitchingTcp/IpTelephonyVoipVpnVulnerability AssessmentZero Trust
New
Cut your apply time in half.
Use ourAI Assistantto automatically fill your job applications.
Use For Free
Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
Lead product security and incident response efforts: design and deploy security controls, hunt and investigate threats using endpoint/network/cloud telemetry, build detections and workflows, perform forensics, and partner with engineering to remediate vulnerabilities and improve secure design.
Top Skills:
Alibaba CloudAuthentication SystemsCi/CdCloud VpnEdrEndpoint ToolsFirewallsGCPGoogle SuiteJavaKotlinKubernetesNetwork Traffic LogsOktaPipelinesPythonSplunk
Cloud • Information Technology • Machine Learning
As a Solutions Architect, engage with customers to architect cloud solutions, optimize workloads, and provide technical leadership while collaborating with engineering teams.
Top Skills:
Distributed TrainingInferenceKubernetesMachine Learning OperationsNetworking EngineeringSlurm Workload Manager
Artificial Intelligence • Software
Design and validate threat models for agentic AI systems, create adversarial experiments and synthetic environments, develop static and dynamic risk analysis, fine-tune and evaluate models, and build production-ready guardrails, monitoring, dashboards, and evaluation infrastructure. Optimize security systems for latency, cost, reliability, and measurable real-world performance while translating research into product capabilities.
Top Skills:
Agentic AiDynamic AnalysisGenerative AiMachine LearningReinforcement LearningStatic Analysis
Productivity • Software • Conversational AI
Lead technical response to security incidents across Twilio's global cloud infrastructure. Triage, contain, remediate, document incidents, drive post-incident improvements, automate workflows (SOAR), extend SIEM capabilities, participate in on-call rotation, mentor teammates, and collaborate with R&D to improve detection and threat mitigation.
Top Skills:
AWSGCPGenaiLlmSIEMSoar
Biotech
Senior hands-on engineer responsible for hybrid infrastructure operations and IT security. Maintains Windows, macOS, Linux, cloud, networking, virtualization, identity, endpoint, and security environments; investigates incidents, vulnerabilities, and alerts; supports incident response, access management, audits, and compliance; and develops automation and documentation. The role requires troubleshooting across complex systems, improving security controls and operational processes, and collaborating with IT teams, stakeholders, vendors, and managed service providers. The position is temporary and requires working onsite in San Francisco four days per week.
Top Skills:
Active DirectoryAWSLinuxmacOSMicrosoft Entra IdOktaPowershellPythonWindowsWindows Server
Fintech • Software • Financial Services
Secure Agora’s applications, APIs, cloud infrastructure, Kubernetes workloads, deployment pipelines, and blockchain-related systems. Responsibilities include threat modeling, architecture and code reviews, security tooling administration, detection engineering, monitoring, incident response, vulnerability management, penetration-test coordination, security automation, and cross-functional remediation. The role partners closely with Engineering, Product, Infrastructure, Compliance, Operations, and the SOC to improve controls, telemetry, response readiness, and security risk visibility.
Top Skills:
Argo CdAWSBlockchainCi/CdCloudflareCryptographic Key ManagementCspmDastDockerGitopsGrafanaJavaScriptKubernetesNode.jsPostgresPrometheusPulumiReactRest ApisSastScaSIEMSmart ContractsTypescript
Healthtech
Integrate security into the software development lifecycle through secure code reviews, threat modeling, vulnerability assessment, remediation guidance, security testing, penetration testing, and developer training. The role uses SAST, DAST, SCA, AI security tools, and vulnerability management practices while addressing modern AI threats. It also supports cloud, infrastructure-as-code, containerization, and healthcare security requirements in a hybrid San Francisco environment.
Top Skills:
AnsibleAWSC++ChefCi/CdClaude CodeDastDockerGithub ActionsGithub CopilotKubernetesPythonSastScaTerraform
Information Technology
Consult with clients to design, implement, configure, test, troubleshoot, and support physical security systems, including video surveillance, access control, sensors, and integrations. Develop network architectures, lead design workshops, execute test plans, document solutions, and serve as a technical customer contact. Support project delivery, sales engagements, upgrades, and complex hardware/software problem resolution while managing timelines, expenses, and customer expectations. Travel and occasional off-hours work are required.
Top Skills:
Access Control SystemsAxisEnvironmental SensorsGenetecIot DevicesLanMeraki MvMilestoneNetwork SecurityVerkadaVideo Surveillance SystemsWan
Reposted 28 Days AgoSaved
Information Technology
Design, implement, and support enterprise physical security systems (video surveillance, access control, sensors, IoT). Consult with clients, develop technical architectures, configure and test systems, troubleshoot hardware/software, manage projects, run design workshops, and support sales and delivery. Travel 25-50% and perform hands-on installations and network-integrated solutions.
Top Skills:
Access Control SystemsAxisGenetecGenetec Security CenterIotLanMeraki MvMilestoneNetwork SecurityOmnicastSynergisVerkadaVideo Surveillance SystemsWan
Cloud • Software • Cybersecurity
Designs and maintains secure Linux OS components for hardened container images and cloud-native workloads. Responsibilities include remediating CVEs, patching and rebuilding packages across Linux distributions, hardening container images, managing SBOMs and software provenance, and automating reproducible OS build and CI/CD pipelines. The role requires deep Linux systems, package management, dependency, container runtime, and supply chain security expertise, along with cross-functional collaboration to deliver stable, secure OS baselines.
Top Skills:
AlpineApkAptBashCC++Ci/CdContainersDebianDnfGlibcGoKojiLaunchpadLinuxLinux KernelMockObsOpensslPythonRhelRpmSbomSlsaUbuntu
Cloud • Software • Cybersecurity
Build backend services and distributed systems for a cybersecurity and software supply chain security platform. Develop scalable APIs, data pipelines, and platform components handling vulnerability, container, package, runtime, and SBOM data. Work across Linux, Kubernetes, containers, and cloud environments while solving concurrency, performance, reliability, and distributed processing challenges. Own projects from design through deployment, participate in architecture discussions, review code, and collaborate with security researchers and product teams.
Top Skills:
APIsApkAWSAzureC++Ci/CdContainer RuntimesData PipelinesDebDockerGCPGoJavaKubernetesLinuxMicroservicesNosql DatabasesPythonRelational DatabasesRpmSbomsSoftware Composition Analysis
Healthtech • Social Impact • Software
Own and build Grow Therapy's data security infrastructure: automated data classification, field-level masking/tokenization, encryption and key management, secure data connectors to AI tooling, and access controls. Define a multi-year vision, implement pipelines and services, and partner across Data, Engineering, and Detection & Response to make secure-by-default the company standard.
Cloud
Develop backend systems for large-scale web applications and security products primarily in Go. Write robust, modular code, optimize performance, participate in code reviews and documentation, and collaborate across technical and product teams. The role requires strong HTTP and networking knowledge, Linux, automation, shell scripting, and backend operations experience. Engineers participate in core US business hours and an on-call rotation, with occasional travel as needed.
Top Skills:
CGoH2OHTTPKubernetesLinuxRustShell ScriptingVarnish
Let Your Resume Do The Work
Upload your resume to be matched with jobs you're a great fit for.
Success! We'll use this to further personalize your experience.
Top San Francisco Companies Hiring Senior Security Engineers
See AllPopular Job Searches
All Filters
Total selected ()
No Results
No Results














_0.png)


.png)



.png)








