Jobs
>
San Francisco

    Senior Cloud Security Engineer - San Francisco, CA, United States - StockX

    Default job background
    Description

    StockX

    Buy and sell the hottest sneakers including Adidas Yeezy and Retro Jordans, Supreme streetwear, trading cards, collectibles, designer handbags and luxury watches.

    View company page

    Help empower our global customers to connect to culture through their passions.

    Why you'll love this role

    This hands-on security engineering position will be part of StockX's Information Security Cloud & Application Engineering team. This team is responsible for leading efforts to enhance the security of the cloud infrastructure and applications all across StockX. Members of this team work with several stakeholders to ensure appropriate processes, procedures, and controls are adequately designed and implemented to meet StockX security requirements, mitigate risks, and ensure compliance. They provide ongoing engineering support for security systems in our cloud native environment. This is a critical IC role on the StockX Information Security team and will work with several stakeholders in Product, Engineering, Operations, Customer Service, Safety & Trust, & IT.

    What you'll do

    • Partner with the Platform Engineering and IT teams to design, implement, and manage security measures for our AWS & Azure cloud infrastructure.
    • Collaborate with cross-functional teams to automate and expedite integration of security best practices into the entire development lifecycle, from design to deployment.
    • Use available tooling to assess risks and vulnerabilities and implement strategies to mitigate and remediate identified security risks.
    • Automate enforcement security of policies and related controls for AWS cloud services and data protection.
    • Monitor and respond to security incidents, conduct investigations, and implement incident response procedures as needed with confidentiality and professionalism.
    • Design and implement identity and access management (IAM) solutions for secure access control.
    • Partner with other teams to ensure IAM controls are part of a defense in depth strategy
    • Ensure the continuing operation and effectiveness of key identity and access management controls
    • Stay abreast of the latest cloud security trends, threats, and vulnerabilities, and implement proactive measures to address emerging risks.
    • Possess knowledge of reliable and low-touch infrastructure using technologies such as Terraform, Kubernetes, and Docker supported by other engineering teams.
    • Provide mentorship and guidance to junior members of the security team.
    • Ability to quickly analyze logs and configurations using; Python, JQ, cURL, etc.
    • Integrate application security tooling within the existing CI/CD environment to improve application security.

    About you

    • 4-7 years of relevant security experience.
    • Bachelor's degree preferred but not required.
    • Cyber security certifications preferred e.g. CISSP, CISM, Security +, AWS Security
    • Strong experience with cloud native environments and with multiple cloud services providers
    • Experience with scripting across multiple cloud providers and infrastructure APIs to analyze security posture and configurations.
    • Detailed understanding of cloud and network security
    • Experience reading other engineer's code across a number of languages to identify security issues.
    • Understanding of modern cloud technology components and deployment patterns: containers, Kubernetes, serverless, infrastructure as code, etc.
    • Experience with OAuth/SAML techniques and OIDC
    • Deep understanding of Identity & Access Management security controls and tooling
    • Strong understanding of securing distributed cloud and on-premesis networks using security groups, network ACLs, VPNs, and WAFs among other technologies
    • Strong understanding of security monitoring tools for cloud environments such as CSPM, CASB, cloud audit logs such as AWS Cloudtrail, etc
    • Strong understanding of application security tools such as Snyk, Sonarcloud, Dependabot or Renovate, GitGuardian, etc
    • Technical understanding of how threats like Spam, Phishing, DDoS Attacks, Brute Force Attacks, SQL Injections, XSS are executed and how to protect against them across an organization.

    Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation.

    Pursuant to the various pay transparency laws/acts, the base salary range is $140,000 to $160,000 plus opportunities for benefits (e.g., medical, dental), equity and discretionary bonuses . Compensation is dependent on geography and may vary.

    Help empower our global customers to connect to culture through their passions.

    Why you'll love this role

    This hands-on security engineering position will be part of StockX's Information Security Cloud & Application Engineering team. This team is responsible for leading efforts to enhance the security of the cloud infrastructure and applications all across StockX. Members of this team work with several stakeholders to ensure appropriate processes, procedures, and controls are adequately designed and implemented to meet StockX security requirements, mitigate risks, and ensure compliance. They provide ongoing engineering support for security systems in our cloud native environment. This is a critical IC role on the StockX Information Security team and will work with several stakeholders in Product, Engineering, Operations, Customer Service, Safety & Trust, & IT.

    What you'll do

    • Partner with the Platform Engineering and IT teams to design, implement, and manage security measures for our AWS & Azure cloud infrastructure.
    • Collaborate with cross-functional teams to automate and expedite integration of security best practices into the entire development lifecycle, from design to deployment.
    • Use available tooling to assess risks and vulnerabilities and implement strategies to mitigate and remediate identified security risks.
    • Automate enforcement security of policies and related controls for AWS cloud services and data protection.
    • Monitor and respond to security incidents, conduct investigations, and implement incident response procedures as needed with confidentiality and professionalism.
    • Design and implement identity and access management (IAM) solutions for secure access control.
    • Partner with other teams to ensure IAM controls are part of a defense in depth strategy
    • Ensure the continuing operation and effectiveness of key identity and access management controls
    • Stay abreast of the latest cloud security trends, threats, and vulnerabilities, and implement proactive measures to address emerging risks.
    • Possess knowledge of reliable and low-touch infrastructure using technologies such as Terraform, Kubernetes, and Docker supported by other engineering teams.
    • Provide mentorship and guidance to junior members of the security team.
    • Ability to quickly analyze logs and configurations using; Python, JQ, cURL, etc.
    • Integrate application security tooling within the existing CI/CD environment to improve application security.

    About you

    • 4-7 years of relevant security experience.
    • Bachelor's degree preferred but not required.
    • Cyber security certifications preferred e.g. CISSP, CISM, Security +, AWS Security
    • Strong experience with cloud native environments and with multiple cloud services providers
    • Experience with scripting across multiple cloud providers and infrastructure APIs to analyze security posture and configurations.
    • Detailed understanding of cloud and network security
    • Experience reading other engineer's code across a number of languages to identify security issues.
    • Understanding of modern cloud technology components and deployment patterns: containers, Kubernetes, serverless, infrastructure as code, etc.
    • Experience with OAuth/SAML techniques and OIDC
    • Deep understanding of Identity & Access Management security controls and tooling
    • Strong understanding of securing distributed cloud and on-premesis networks using security groups, network ACLs, VPNs, and WAFs among other technologies
    • Strong understanding of security monitoring tools for cloud environments such as CSPM, CASB, cloud audit logs such as AWS Cloudtrail, etc
    • Strong understanding of application security tools such as Snyk, Sonarcloud, Dependabot or Renovate, GitGuardian, etc
    • Technical understanding of how threats like Spam, Phishing, DDoS Attacks, Brute Force Attacks, SQL Injections, XSS are executed and how to protect against them across an organization.

    Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation.

    Pursuant to the various pay transparency laws/acts, the base salary range is $140,000 to $160,000 plus opportunities for benefits (e.g., medical, dental), equity and discretionary bonuses . Compensation is dependent on geography and may vary.

    About Us StockX is proud to be a Detroit-based technology leader focused on the large and growing online market for sneakers, apparel, accessories, electronics, collectibles, trading cards, and more. StockX's powerful platform connects buyers and sellers of high-demand consumer goods from around the world using dynamic pricing mechanics. This approach affords access and market visibility powered by real-time data that empowers buyers and sellers to determine and transact based on market value. The StockX platform features hundreds of brands across verticals including Jordan Brand, adidas, Nike, Supreme, BAPE, Off-White, Louis Vuitton, Gucci; collectibles from artists including KAWS and Takashi Murakami; and electronics from industry-leading manufacturers Sony, Microsoft, Nvidia, and Apple. Launched in 2016, StockX employs more than 1,000 people across offices and verification centers around the world. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. This job description is intended to convey information essential to understanding the scope of the job and the general nature and level of work performed by job holders within this job. However, this job description is not intended to be an exhaustive list of qualifications, skills, efforts, duties, responsibilities or working conditions associated with the position. StockX reserves the right to amend this job description at any time.

    Explore more InfoSec / Cybersecurity career opportunities

    Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

    #J-18808-Ljbffr

  • ShiftCode Analytics

    Security Engineer

    1 day ago


    ShiftCode Analytics San Francisco, United States

    Interview : Video · Visa : All apart from H1b and CPT · This is hybrid from day-1. Candidate must be local. · Description : · Qualifications: · 4+ years of security engineering experience OR equivalent experience in a SWE/DevOps role and an interest in working on security en ...

  • Vouch

    Security Engineer

    1 day ago


    Vouch San Francisco, United States

    [Full Time] Security Engineer at Vouch (United States) | BEAMSTART Jobs · Security Engineer · Vouch United States · Date Posted · 04 Jan, 2023 · Work Location · San Francisco, United States · Salary Offered · $145000 — $165000 yearly · Job Type · Full Time · Experience Required ...

  • Commit Partnership

    Security Engineer

    3 days ago


    Commit Partnership San Francisco, United States

    About the company: Company size: <50 · Industry: Data Analytics, Data Science, AI · Founding year: 2019 · Stage: B · Funding: $100M · Backed by: Top-tier investors including Sequoia Capital, Andreessen Horowitz, and Snowflake · Tech Stack/Key Tech: Kubernetes, AWS, Terrafor ...

  • HonorVet Technologies

    Security Engineer

    1 day ago


    HonorVet Technologies San Francisco, United States

    Title: Security Engineer · Location: Remote · Duration: 12+ months · Position Description · A Security Engineer serves as the security engineer of complex technology implementations in a product-centric environment; is comfortable with bridging the gap between legacy developmen ...

  • Retool

    Security Engineer

    5 days ago


    Retool San Francisco, United States Full time

    ABOUT RETOOL: · Nearly every company in the world runs on custom software: Gartner estimates that up to 50% of all code is written for internal use. This is the operational software for refunding orders, underwriting loans, onboarding employees, analyzing transactions, and prov ...

  • Insight Global

    Security Engineer

    1 week ago


    Insight Global San Francisco, United States

    The Security Engineer on the Enterprise Security team is responsible for protecting Grammarly's infrastructure, including the corporate environment within which all our employees do their work and our cloud infrastructure within which all our product offerings and services run · ...

  • HonorVet Technologies

    Security Engineer

    22 hours ago


    HonorVet Technologies San Francisco, United States

    Title: Security Engineer · Location: Remote · Duration: 12+ months · Position Description · A Security Engineer serves as the security engineer of complex technology implementations in a product-centric environment; is comfortable with bridging the gap between legacy development ...

  • Asana

    Security Engineer

    1 week ago


    Asana San Francisco, United States

    We're looking for a motivated security engineer interested in maturing Asana's product security posture to expand trust with our growing customer base. As a member of the Product Security team, you will focus on shipping features that are free from critical security bugs, enablin ...

  • Hive

    Security Engineer

    1 week ago


    Hive San Francisco, CA, United States

    About Hive · Hive is the leading provider of cloud-based AI solutions for content understanding, trusted by the world's largest, fastest growing, and most innovative organizations. The company empowers developers with a portfolio of best-in-class, pre-trained AI models, serving ...

  • Anyscale

    Security Engineer

    1 day ago


    Anyscale San Francisco, United States

    About Anyscale · At Anyscale , we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We're commercializing Ray , a popular open-source project that's creating an ecosystem of libraries for scalable machine lear ...

  • Insight Global

    Security Engineer

    1 week ago


    Insight Global San Francisco, United States

    Job Description · * The Security Engineer on the Enterprise Security team is responsible for protecting Grammarly's infrastructure, including the corporate environment within which all our employees do their work and our cloud infrastructure within which all our product offering ...

  • Saxon Global

    Security Engineer

    1 week ago


    Saxon Global San Francisco, CA, United States

    USC,GC Title: Security Engineer Location: San Francisco, CA (hybrid) and travel as needed Duration: 6 Months + Client: WWT/PG&E Interview: Phone/Video Rate: $60-65/hr on c2c Required Skills: Security Engineering Contractor with experience deploying the Elastic Endgame-REQUIRED ( ...


  • Gunderson Dettmer San Francisco, United States

    Gunderson Dettmer · is the only business law firm of its kind - exclusively serving the global venture capital and emerging technology marketplace. With 400 attorneys in eleven offices - from Silicon Valley to Singapore - we innovate for innovators, accelerate entrepreneurship, ...

  • HeyGen

    Security Engineer

    4 days ago


    HeyGen San Francisco, United States

    About HeyGen · HeyGen is a cutting-edge AI-powered platform revolutionizing the world of video creation. · Position Summary: · As a Security Engineer at HeyGen, you will play a critical role in protecting our systems and data from threats. Your expertise will be essential in i ...

  • Vouch

    Security Engineer

    1 week ago


    Vouch San Francisco, CA, United States

    Full Time] Security Engineer at Vouch (United States) | BEAMSTART Jobs Security Engineer · Full Time · Remote Work · Stock Options · Vouch is a new, technology-first insurance company backed with $160M in funding from world-class investors. Like Stripe for payments or Brex fo ...

  • Retool

    Security Engineer

    1 week ago


    Retool San Francisco, CA, United States

    Retool aspires to be the single best way companies build internal tools, bringing good software to everyone. Retool both handles our clients' most sensitive data and offers a Turing-complete coding environment, so security is a core criterion for everything we build. Bringing our ...


  • Asana San Francisco, CA, United States

    Keep remote and distributed teams, and your entire organization, focused on their goals, projects, and tasks with Asana. We are looking for a Corporate Security Engineer to lead our cross-functional IT and Security initiatives. You will be working with the Security and IT teams t ...

  • Replit

    Security Engineer

    1 week ago


    Replit San Francisco, CA, United States

    [Full Time] Security Engineer at Replit (United States) | BEAMSTART Jobs · Security Engineer · Replit United States · Date Posted · 31 Oct, 2022 · Work Location · San Francisco, United States · Salary Offered · Not Specified · Job Type · Full Time · Experience Required ...


  • Gunderson Dettmer San Francisco, United States

    Job Description · Job DescriptionGunderson Dettmer is the only business law firm of its kind - exclusively serving the global venture capital and emerging technology marketplace. With 400 attorneys in eleven offices - from Silicon Valley to Singapore - we innovate for innovators, ...

  • Retool

    Security Engineer

    1 week ago


    Retool San Francisco, CA, United States

    WHY WE'RE LOOKING FOR YOU · Retool aspires to be the single best way companies build internal tools, bringing good software to everyone. Central to this vision is an unwavering commitment to security. Retool both handles our clients' most sensitive data and offers a Turing-compl ...