Senior Cloud Security Engineer

Found in: Jooble US O C2 - 2 weeks ago


San Francisco CA, United States StockX Full time

StockX Buy and sell the hottest sneakers including Adidas Yeezy and Retro Jordans, Supreme streetwear, trading cards, collectibles, designer handbags and luxury watches.

View company page

Help empower our global customers to connect to culture through their passions.

Why you’ll love this role

This hands-on security engineering position will be part of StockX's Information Security Cloud & Application Engineering team. This team is responsible for leading efforts to enhance the security of the cloud infrastructure and applications all across StockX. Members of this team work with several stakeholders to ensure appropriate processes, procedures, and controls are adequately designed and implemented to meet StockX security requirements, mitigate risks, and ensure compliance. They provide ongoing engineering support for security systems in our cloud native environment. This is a critical IC role on the StockX Information Security team and will work with several stakeholders in Product, Engineering, Operations, Customer Service, Safety & Trust, & IT.

What you’ll do

  • Partner with the Platform Engineering and IT teams to design, implement, and manage security measures for our AWS & Azure cloud infrastructure.
  • Collaborate with cross-functional teams to automate and expedite integration of security best practices into the entire development lifecycle, from design to deployment.
  • Use available tooling to assess risks and vulnerabilities and implement strategies to mitigate and remediate identified security risks.
  • Automate enforcement security of policies and related controls for AWS cloud services and data protection.
  • Monitor and respond to security incidents, conduct investigations, and implement incident response procedures as needed with confidentiality and professionalism.
  • Design and implement identity and access management (IAM) solutions for secure access control.
  • Partner with other teams to ensure IAM controls are part of a defense in depth strategy
  • Ensure the continuing operation and effectiveness of key identity and access management controls
  • Stay abreast of the latest cloud security trends, threats, and vulnerabilities, and implement proactive measures to address emerging risks.
  • Possess knowledge of reliable and low-touch infrastructure using technologies such as Terraform, Kubernetes, and Docker supported by other engineering teams.
  • Provide mentorship and guidance to junior members of the security team.
  • Ability to quickly analyze logs and configurations using; Python, JQ, cURL, etc.
  • Integrate application security tooling within the existing CI/CD environment to improve application security.

About you

  • 4-7 years of relevant security experience.
  • Bachelor's degree preferred but not required.
  • Cyber security certifications preferred e.g. CISSP, CISM, Security +, AWS Security
  • Strong experience with cloud native environments and with multiple cloud services providers
  • Experience with scripting across multiple cloud providers and infrastructure APIs to analyze security posture and configurations.
  • Detailed understanding of cloud and network security
  • Experience reading other engineer’s code across a number of languages to identify security issues.
  • Understanding of modern cloud technology components and deployment patterns: containers, Kubernetes, serverless, infrastructure as code, etc.
  • Experience with OAuth/SAML techniques and OIDC
  • Deep understanding of Identity & Access Management security controls and tooling
  • Strong understanding of securing distributed cloud and on-premesis networks using security groups, network ACLs, VPNs, and WAFs among other technologies
  • Strong understanding of security monitoring tools for cloud environments such as CSPM, CASB, cloud audit logs such as AWS Cloudtrail, etc
  • Strong understanding of application security tools such as Snyk, Sonarcloud, Dependabot or Renovate, GitGuardian, etc
  • Technical understanding of how threats like Spam, Phishing, DDoS Attacks, Brute Force Attacks, SQL Injections, XSS are executed and how to protect against them across an organization.

Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation.

Pursuant to the various pay transparency laws/acts, the base salary range is $140,000 to $160,000 plus opportunities for benefits (e.g., medical, dental), equity and discretionary bonuses . Compensation is dependent on geography and may vary.

Help empower our global customers to connect to culture through their passions.

Why you’ll love this role

This hands-on security engineering position will be part of StockX's Information Security Cloud & Application Engineering team. This team is responsible for leading efforts to enhance the security of the cloud infrastructure and applications all across StockX. Members of this team work with several stakeholders to ensure appropriate processes, procedures, and controls are adequately designed and implemented to meet StockX security requirements, mitigate risks, and ensure compliance. They provide ongoing engineering support for security systems in our cloud native environment. This is a critical IC role on the StockX Information Security team and will work with several stakeholders in Product, Engineering, Operations, Customer Service, Safety & Trust, & IT.

What you’ll do

  • Partner with the Platform Engineering and IT teams to design, implement, and manage security measures for our AWS & Azure cloud infrastructure.
  • Collaborate with cross-functional teams to automate and expedite integration of security best practices into the entire development lifecycle, from design to deployment.
  • Use available tooling to assess risks and vulnerabilities and implement strategies to mitigate and remediate identified security risks.
  • Automate enforcement security of policies and related controls for AWS cloud services and data protection.
  • Monitor and respond to security incidents, conduct investigations, and implement incident response procedures as needed with confidentiality and professionalism.
  • Design and implement identity and access management (IAM) solutions for secure access control.
  • Partner with other teams to ensure IAM controls are part of a defense in depth strategy
  • Ensure the continuing operation and effectiveness of key identity and access management controls
  • Stay abreast of the latest cloud security trends, threats, and vulnerabilities, and implement proactive measures to address emerging risks.
  • Possess knowledge of reliable and low-touch infrastructure using technologies such as Terraform, Kubernetes, and Docker supported by other engineering teams.
  • Provide mentorship and guidance to junior members of the security team.
  • Ability to quickly analyze logs and configurations using; Python, JQ, cURL, etc.
  • Integrate application security tooling within the existing CI/CD environment to improve application security.

About you

  • 4-7 years of relevant security experience.
  • Bachelor's degree preferred but not required.
  • Cyber security certifications preferred e.g. CISSP, CISM, Security +, AWS Security
  • Strong experience with cloud native environments and with multiple cloud services providers
  • Experience with scripting across multiple cloud providers and infrastructure APIs to analyze security posture and configurations.
  • Detailed understanding of cloud and network security
  • Experience reading other engineer’s code across a number of languages to identify security issues.
  • Understanding of modern cloud technology components and deployment patterns: containers, Kubernetes, serverless, infrastructure as code, etc.
  • Experience with OAuth/SAML techniques and OIDC
  • Deep understanding of Identity & Access Management security controls and tooling
  • Strong understanding of securing distributed cloud and on-premesis networks using security groups, network ACLs, VPNs, and WAFs among other technologies
  • Strong understanding of security monitoring tools for cloud environments such as CSPM, CASB, cloud audit logs such as AWS Cloudtrail, etc
  • Strong understanding of application security tools such as Snyk, Sonarcloud, Dependabot or Renovate, GitGuardian, etc
  • Technical understanding of how threats like Spam, Phishing, DDoS Attacks, Brute Force Attacks, SQL Injections, XSS are executed and how to protect against them across an organization.

Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation.

Pursuant to the various pay transparency laws/acts, the base salary range is $140,000 to $160,000 plus opportunities for benefits (e.g., medical, dental), equity and discretionary bonuses . Compensation is dependent on geography and may vary.

About Us StockX is proud to be a Detroit-based technology leader focused on the large and growing online market for sneakers, apparel, accessories, electronics, collectibles, trading cards, and more. StockX's powerful platform connects buyers and sellers of high-demand consumer goods from around the world using dynamic pricing mechanics. This approach affords access and market visibility powered by real-time data that empowers buyers and sellers to determine and transact based on market value. The StockX platform features hundreds of brands across verticals including Jordan Brand, adidas, Nike, Supreme, BAPE, Off-White, Louis Vuitton, Gucci; collectibles from artists including KAWS and Takashi Murakami; and electronics from industry-leading manufacturers Sony, Microsoft, Nvidia, and Apple. Launched in 2016, StockX employs more than 1,000 people across offices and verification centers around the world. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. This job description is intended to convey information essential to understanding the scope of the job and the general nature and level of work performed by job holders within this job. However, this job description is not intended to be an exhaustive list of qualifications, skills, efforts, duties, responsibilities or working conditions associated with the position. StockX reserves the right to amend this job description at any time. Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

#J-18808-Ljbffr
  • Senior Cloud Security Engineer

    Found in: Jooble US O C2 - 2 weeks ago


    San Francisco, CA, United States Avant Digital, Inc. Full time

    Job Description: Job Description- Location: Remote Contract type - Contract / C2C Contract duration - 12 months Juniper Networks Cyber Fusion is looking for a certified cybersecurity professional to join our highly collaborative and diverse team of talent. who will be responsible for ensuring the security and compliance of our cloud infrastructure and...

  • Senior Cloud App Security Engineer

    Found in: Jooble US O C2 - 2 weeks ago


    San Francisco, CA, United States Aurora Innovation Full time

    Bringing self-driving vehicles to our roads is the most transformative opportunity of our generation. Aurora is taking a fresh start with the development of self-driving technology, combining excellence in AI, rigorous engineering, and a team with decades of experience building robots that work. We are designing the software and hardware to power the...

  • Senior Cloud Security Engineer

    Found in: Jooble US O C2 - 6 days ago


    San Francisco, CA, United States Aurora Full time

    Aurora Overview Bringing self-driving vehicles to our roads is the most transformative opportunity of our generation. Aurora is taking a fresh start with the development of self-driving technology, combining excellence in AI, rigorous engineering, and a team with decades of experience building robots that work. Led by a team of seasoned experts, our...

  • Senior Cloud Security Engineer

    Found in: Jooble US O C2 - 2 weeks ago


    San Francisco, CA, United States Aurora Innovation Full time

    Aurora Overview Bringing self-driving vehicles to our roads is the most transformative opportunity of our generation. Aurora is taking a fresh start with the development of self-driving technology, combining excellence in AI, rigorous engineering, and a team with decades of experience building robots that work. Led by a team of seasoned experts, our...

  • Senior Cloud Security Engineer

    Found in: Resume Library US A2 - 6 days ago


    San Francisco, California, United States Avant Digital Inc Full time

    Job Description- Location: Remote Contract type - Contract / C2C Contract duration - 12 months Juniper Networks Cyber Fusion is looking for a certified cybersecurity professional to join our highly collaborative and diverse team of talent. who will be responsible for ensuring the security and compliance of our cloud infrastructure and data. You will work...

  • Senior Security Engineer

    Found in: Jooble US O C2 - 2 weeks ago


    San Francisco, CA, United States Primer Full time

    As a Senior Security Engineer you will be a key member of the Information Security team ensuring security across the company. You will help confirm that sensitive data is protected and make sure we have the right tools implemented to maintain trust. You will also help our software engineers be successful by sharing your knowledge and working to prevent...


  • San Francisco, United States Abnormal Security Full time

    Job DescriptionJob DescriptionAbout the RoleAbnormal Security is looking for a Software Engineer to join the Cloud Infrastructure team. This team is responsible for Abnormal's presence in the public cloud and ensuring our use of the cloud is secure, reliable, and repeatable while meeting the needs of our engineering team.This role includes responsibility...

  • ForgeRock Engineer

    6 days ago


    San Francisco, United States Cloud Security Services Full time

    Job DescriptionJob DescriptionCloud Security Services is seeking experienced ForgeRock Engineers to join our team for a 6+ month assignment. The selected candidates will work closely with ForgeRock Professional Services on projects related to Identity Governance and Administration (IGA), Access Management (AM), and Cloud integrations. This is an excellent...

  • Senior Security Engineer

    Found in: Jooble US O C2 - 2 weeks ago


    San Francisco, CA, United States primer.ai Full time

    Primer exists to make the world a safer place. We do this by providing trusted decision-ready AI to the world's most critical organizations. Our software enables leaders, operators, and analysts to better understand the changing world around us in real time and make informed decisions when the stakes are high. Primer has offices in San Francisco,...

  • Senior Security Engineer

    Found in: Jooble US O C2 - 2 weeks ago


    San Francisco, CA, United States Cyber Crime Full time

    Primer exists to make the world a safer place. We do this by providing trusted decision-ready AI to the world's most critical organizations. Our software enables leaders, operators, and analysts to better understand the changing world around us in real time and make informed decisions when the stakes are high. Primer has offices in San Francisco, Pasadena,...

  • Senior Security Engineer

    Found in: Jooble US O C2 - 2 weeks ago


    San Francisco, CA, United States Cyber Crime Full time

    Our software enables leaders, operators, and analysts to better understand the changing world around us in real time and make informed decisions when the stakes are high. Our software enables leaders, operators, and analysts to better understand the changing world around us in real time and make informed decisions when the stakes are high. As a Senior...

  • Senior Lead Software Engineer- Cloud Platform

    Found in: Jooble US O C2 - 2 weeks ago


    San Francisco, CA, United States JPMorgan Chase & Co. Full time

    Job Description Be an integral part of an agile team that's constantly pushing the envelope to enhance, build, and deliver top-notch technology products. As a Senior Lead Software Engineer at JPMorgan Chase within the Corporate Investment Banking, you are an integral part of an agile team that works to enhance, build, and deliver trusted...


  • San Mateo, United States Snowflake Computing Full time

    Build the future of data. Join the Snowflake team. There is only one Data Cloud. Snowflake's founders started from scratch and designed a data platform built for the cloud that is effective, affordable, and accessible to all data users. But it didn't stop there. They engineered Snowflake to power the Data Cloud, where thousands of organizations unlock the...


  • San Francisco, United States Contrast Security, Inc Full time

    ???? **Privacy Notice****Director/Senior Cloud Alliance Sales Manager**San Francisco, Bay Area / Sales & Business Development Alliances / Full-time Contrast Security is the worlds leading provider of security technology that enables software applications to protect themselves against cyberattacks, heralding the new era of self-protecting software....

  • Engineering Manager, Cloud Platform

    Found in: Jooble US O C2 - 2 weeks ago


    San Francisco, CA, United States Rescale Full time

    Full Time] Engineering Manager - Rescale at Rescale (United States) | BEAMSTART Jobs Engineering Manager - Rescale Full Time Remote Work Stock Options Rescale is high performance computing built for the cloud. Rescale is a cloud platform delivering intelligent full-stack automation and performance optimization. IT leaders use Rescale to deliver...


  • San Francisco, CA, United States Staff Tech Full time

    6946 - Senior Program Manager: Leading Cloud and Security Initiatives Job Type : Temp/Contract Hours : Full Time Travel : No Relocation : No Staff Tech is looking for an IT Program Manager to provide long term oversight to various related IT initiates including IT projects and provide coordination functions needed...


  • San Francisco, United States Caldera Full time

    Senior Infrastructure Engineer, Security We're looking for an incredible senior engineer to help us build the future of blockchain scalability. This is an ideal opportunity for an engineer who is already passionate about tackling problems in blockchain scalability, or looking to break into the blockchain engineering space. If you're looking to work in a...

  • Senior Security Engineer

    Found in: Jooble US O C2 - 2 weeks ago


    San Francisco, CA, United States Pave Full time

    Full Time] Senior Security Engineer at Pave (United States) | BEAMSTART Jobs Senior Security Engineer Full Time Stock Options Today, teams cobble together hundreds of messy spreadsheets and outdated surveys to determine how to compensate their employees. At best, they’re leveraging stale data from an industry that is quickly evolving past it. Add...

  • Cloud Engineer

    6 days ago


    San Francisco, United States Northwest Talent Solutions LLC Full time

    Job DescriptionJob DescriptionOur client is a phenomenal start-up with an outstanding culture, a well sought-after product and clearly defined growth trajectory. We are in search of a senior Cloud Engineer with 10+ years' experience, an entrepreneurial mindset but with experience from a large tech environment such as LinkedIn, Snap, Meta, Amazon, etc....

  • Cloud Engineer

    6 days ago


    San Mateo, United States LanceSoft Full time

    Job Title: Cloud Security Engineer Location: Foster City, CA Duration: 6+ Months Description: The client is seeking an experienced Cloud Security Engineer, who will be responsible for helping ensure the security of our customers, staff, systems, communications, and data. The Cloud Security Engineer will support the implementation, maintenance and upkeep of...