368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$145k – $170k per year
Location
Remote (United States, Canada)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Wpromote is a digital marketing agency that helps our clients Think Like A Challenger: from enterprise brands to fast-growing digital disruptors, we believe that the right marketing strategy can help every business connect with customers and drive...

The Role

The Senior Security Engineer is a newly established senior individual contributor role that will drive the design, implementation, and continuous advancement of Wpromote's security engineering program.

Reporting to the Director of IT, you will operate as a true partner to IT leadership, trusted to shape security decisions with a depth of expertise that elevates the whole organization. This is not an analyst or application security role; you will be expected to build and improve our security systems, ideal for someone energized by owning a domain end to end and continuously raising the bar.

This is a remote role, serving as a senior security presence and point of escalation across the function.

At Wpromote, we believe that great work is only possible with great people. Our goal is to build a better, more inclusive work environment and support our people at every stage of their careers by prioritizing a strong work-life balance through our policies and benefits listed below. As a Best Place to Work according to both Ad Age and Glassdoor and Adweek’s Fastest Growing Digital Agency, we are moving fast to expand our teams and bring new experts into the fold to keep pushing the boundaries of what’s possible in marketing.

We offer:

-Unlimited PTO

-Extended Holiday break (Winter)

-100% paid parental leave

-401(k) matching

-Medical, Dental, Vision, Life, Pet Insurance

-Sponsored life insurance

-Short Term Disability insurance and additional voluntary insurance

-Annual Class Pass credits and more!

The anticipated annual salary for this role will range from $145,000 - $170,000, based on a variety of factors unique to each candidate, including skill set, years and depth of experience, education and certifications, competitive benchmarks, scope of responsibility, market dynamics, geographic location, and the respective state’s salary threshold for exempt employees. At Wpromote, pay ranges are subject to change and are based on specific market medians for similar jobs according to third-party salary benchmark surveys. Individual pay within that range can vary due to skills, experience, and available budget. The total compensation package for this role will include benefits (listed above).

*This position may be performed remotely in most states within the US, with some exclusions

**While this role offers the flexibility to work remotely, we have office hubs in Los Angeles, Chicago, and New York, where you can join in on learning and development opportunities, fun events, take advantage of a space to work, and collaborate in person!

***This position is not eligible for immigration sponsorship

Important Notice: Beware of Job Scams

Wpromote recruiting communications will only be sent through our official channels via wpromote.com email addresses. If you see a posting elsewhere that is not reflected on Wpromote.com/careers, it may be a fraudulent posting. We do not require payment or fees during the hiring process nor do we request sensitive information, such as Social Security numbers or payment details. Please safeguard yourself against possible scams and contact us if you encounter any suspicious activity.

You Are

  • Composed under fire: When a security event lands, you move toward it, not away. You stay methodical and let the evidence drive your decisions, instead of panicking or jumping to conclusions.
  • Relentlessly current: You live at the leading edge of the security field, tracking emerging threats, techniques, and tooling, and you treat staying ahead of the threat landscape as a core part of the job rather than an afterthought.
  • Evidence-driven and precise: You distinguish what is observed from what is assessed, and you hold that line even when stakeholders are pushing for a certainty you cannot yet responsibly give.
  • Deeply autonomous: You own investigations end to end, escalating genuine judgment calls rather than routine unknowns, and you operate with high autonomy on security architecture and incident decisions.
  • A detailed planner who executes: You translate ambiguous problems into granular, sequenced plans of action, then deliver against them. Your plans are specific enough that others can trust and follow them.
  • A builder at heart: You are energized by owning solutions, testing new ideas, and driving improvements quickly rather than settling for the status quo.
  • An audience-aware communicator: You write clearly for executive, technical, and non-technical readers, and you exhibit good judgement and discretion during sensitive incidents where accuracy, confidentiality, and timing matter

You Will Be

  • Owning the Security Tooling Portfolio: Evaluating, integrating, and rationalizing the security tool stack so investments are coherent, well-integrated, and earning their value
  • Owning Identity and Access Architecture: Designing identity, access, and session governance across Google Workspace and additional identity providers, including least-privilege design, credential and secrets hygiene, service-identity architecture, and joiner, mover, and leaver controls at the design layer.
  • Governing Cloud Security Posture: Defining security requirements for the GCP environment and translating them into policy and controls across Cloud IAM, organization policy, service account governance, and audit logging. Partnering with platform engineering on implementation, governing posture against those requirements, and feeding cloud telemetry into the detection pipeline.
  • Advancing Authentication and Secrets: Driving our phishing-resistant MFA strategy such as passkeys and hardware keys, strengthening secrets-management architecture, and advancing SAML SSO, SCIM provisioning, and session policy across the SaaS environment.
  • Governing OAuth and Token Lifecycle: Owning OAuth app vetting and governance, token lifecycle and revocation, and third-party application risk management.
  • Owning Incident Response: Owning incident response and forensic practice, running investigations independently, and coordinating external partners during major escalations.
  • Applying Security Automation and DaC: Treating detection, policy, configuration, and response automation as code that is version-controlled, peer-reviewed, and tested. Partnering with platform engineering on Terraform and cloud guardrails where security controls intersect with infrastructure.
  • Developing Internal Capability: Mentoring and developing team members on security practice over time, and partnering with the Director of IT to inform security decisions across the organization.

You Must Have

  • 5+ years of hands-on security engineering experience in a professional environment, with a track record of owning security architecture and projects end to end
  • Detection engineering experience, including selecting, building, and operating a SIEM, writing and tuning detections, and owning log pipelines, alerting, and monitoring
  • 4+ years of hands-on security cloud engineering, GCP strongly preferred, including Cloud IAM, organization policy, service account governance, and audit logging
  • Deep identity and access management expertise, including federation (SAML SSO) and SCIM provisioning and deprovisioning
  • SaaS identity security depth, including phishing-resistant MFA (passkeys, hardware keys), secrets-management architecture, and OAuth app governance, token lifecycle, and third-party application risk
  • Hands-on incident response and forensic methodology, including sound evidence handling
  • Endpoint security posture experience, including EDR operations (CrowdStrike Falcon or equivalent) and device-trust or conditional-access design
  • Experience operating vulnerability management or exposure management programs, including prioritization by exploitability, asset criticality, and business risk
  • Security automation and infrastructure-as-code fluency, including detection-as-code and a tool such as Terraform, at a level beyond ad hoc scripting

Nice to Have

  • A background in infrastructure, cloud platform, DevOps, SRE, or systems engineering before moving into security, bringing an automation-first foundation to detection and governance work
  • Experience scaling or maturing a security program in a fast-growing environment
  • Industry certifications (GCP Professional Cloud Security Engineer, GIAC such as GCIH, GCDA, or GDAT, CISSP, OSCP)
  • Experience managing least-privilege access across many vendor systems, including those that do not support SSO
  • Player-coach or mentoring experience: while this role is scoped as a senior individual contributor, candidates who can develop internal talent will be considered for expanded scope
  • Exposure to SOC 2 or similar compliance frameworks, partnering with GRC on audit readiness
  • Scripting and automation experience (Python, Bash) for security tooling and workflow optimization
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Los Angeles
$25k – $42k per year • Equity 0–0.2% • Remote • Full-Time • 3+ years exp
Bash
Go
JavaScript
Python
TypeScript
DevOps
AWS
Azure
CI/CD
Datadog
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Incident Management
Kubernetes
Platform Engineering
Prometheus
Terraform
Amazon CloudWatch
GitHub
GitLab
IAM
Cybersecurity
Least Privilege
Apply
$100k – $210k per year • Equity 0–0.5% • Remote • Full-Time • 3+ years exp • San Francisco
Bash
Go
JavaScript
Python
TypeScript
DevOps
AWS
Azure
CI/CD
Datadog
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Incident Management
Kubernetes
Platform Engineering
Prometheus
Terraform
Amazon CloudWatch
GitHub
GitLab
IAM
Cybersecurity
Least Privilege
Apply
Team Lead DevOps 1 day ago
$23k – $62k per year (Estimated) • Remote • 5+ years exp • Moscow
Bash
Python
Erlang
Erlang
EMQX
Databases
Apache Kafka
ClickHouse
PostgreSQL
RabbitMQ
Redis
Redpanda
Trino
DevOps
Ansible
AWS
AWX
FinOps
HAProxy
Hetzner
Kubernetes
SLI/SLO/SLA
Terraform
Yandex Cloud
Amazon S3
Apply
$230k – $300k per year • Equity 0.1–0.2% • In office • Full-Time • 3+ years exp • PhD • New York
TypeScript
Databases
PostgreSQL
AI/ML
AI Agents
Claude
Claude Code
Cursor
Devin
OpenAI Codex
Frontend
Next.js
tRPC
DevOps
Platform Engineering
Vercel
Apply
Backend Engineer 1 day ago
Remote/Hybrid • 1+ year exp
Node JS
TypeScript
JavaScript
Node JS
Express
Nest.JS
Databases
MySQL
PostgreSQL
Redis
Mobile
Firebase
DevOps
CI/CD
GCP
Git
Apply
$105k – $135k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Python
SQL
Databases
Google BigQuery
AI/ML
Claude
Claude Code
Copilot
Cursor
Dagster
dbt
OpenAI
OpenAI Codex
DevOps
AWS
Azure
CI/CD
Git
GitHub
Analytics
ETL/ELT
Marketing
HubSpot
Marketo
Salesforce
Apply
$90k – $115k per year • Remote • Full-Time • 5+ years exp
Management
Linear
Apply
$105k – $135k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Python
SQL
Databases
Google BigQuery
AI/ML
Claude
Claude Code
Copilot
Cursor
Dagster
dbt
AI Agents
LLM Guardrails
OpenAI
OpenAI Codex
DevOps
AWS
Azure
CI/CD
Git
GitHub
Marketing
Google Ads
Apply
$170k – $205k per year • Remote • Full-Time • 10+ years exp • Los Angeles
Python
Databases
Apache Kafka
Google BigQuery
PostgreSQL
Snowflake
AI/ML
dbt
DevOps
ArgoCD
CI/CD
Docker
FinOps
GCP
GitHub Actions
GitOps
Google Cloud Run
Google GKE
Grafana
Helm
Kubernetes
OpenTelemetry
Platform Engineering
Prometheus
Terraform
GitHub
IAM
Cybersecurity
CIS Benchmarks
SOC 2
Least Privilege
QA
Sentry
Apply
$74k – $95k per year • Remote • Full-Time • 4+ years exp
Analytics
A/B Testing
Design
Adobe After Effects
Adobe Photoshop
Blender
Cinema 4D
Figma
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$94k – $294k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Portland • Milwaukee • Dallas • Columbus
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$150k – $185k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Los Angeles
AI/ML
Human-in-the-Loop
Apply
$228k – $363k per year • Equity • In office • Full-Time • 5+ years exp • Boston • New York • Los Angeles
Ruby
SQL
JavaScript
Ruby
Ruby on Rails
AI/ML
AI Agents
Frontend
React.js
Mobile
React Native
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.