Senior Security Engineer in Remote at AutoFi
Explore Related Opportunities
Job Description
About the Role:
AutoFi is looking for a passionate and driven Senior Security Engineer. You will work closely with development teams, product managers, and third-party groups to ensure AutoFi’s products, services, cloud environments, internal systems, and vendor ecosystem are secure.
You will contribute to secure design reviews, application security standards, vulnerability management, security monitoring, incident response, threat hunting, and third-party security assessments. This role is ideal for someone who is comfortable working across both proactive and operational security functions in a fast-paced environment.
Define, implement, and maintain security practices, standards, and controls across AutoFi’s products, services, cloud environments, and internal systems.
Partner with engineering and product teams to conduct security design reviews for new features, architecture changes, sensitive workflows, and production-bound implementations.
Design and implement security standards and secure development practices across engineering teams.
Champion security-related activities throughout the software development lifecycle, including secure design, threat modeling, secure coding practices, security testing, and risk-based remediation.
Implement, operate, and improve DevSecOps tooling and processes, including SAST, DAST, SCA, secret scanning, dependency analysis, and other application security controls.
Assess infrastructure, web applications, and cloud environments to help identify, prioritize, and drive remediation of security risks.
Triage vulnerability findings from application security tools, penetration tests, vendor assessments, external reports, and internal reviews.
Conduct proactive threat hunting using available telemetry from cloud environments, application logs, WAF events, identity systems, endpoint signals, and security platforms.
Support continuous improvement of AutoFi’s security operations processes, including alert tuning, detection logic, workflow automation, and post-incident lessons learned.
Assist in defining, implementing, and maintaining third-party risk management policies, procedures, standards, and assessment workflows.
Conduct and support vendor security assessments
Identify, document, and help reduce risks related to third-party vendors, SaaS platforms, integrations, service providers, and business partners.
6+ years of experience in security engineering, application security, cloud security, security operations, or a related security function.
Experience designing and implementing security controls for modern SaaS, cloud, web application, and API environments.
Hands-on experience with application security practices, including secure design reviews, threat modeling, secure code review, vulnerability assessment, and OWASP-based testing methodologies.
Strong understanding of SAST, DAST, IAST, and SCA tooling
Experience with web & cloud security controls/frameworks
Familiarity with network and web application protocols (HTTP/S, SAML 2.0, OAuth, Rest APIs)
Experience with SIEM platforms, alert triage, security investigations, detection workflows, and incident response procedures.
Familiarity with indicators of compromise, indicators of attack, threat hunting techniques, and incident escalation processes.
Industry experience building data-driven applications with Javascript, Node.js, and NoQSL.
Minimum BS/BA in Cybersecurity, Information Security, Computer Science, or relevant degree, with the ability to demonstrate sophisticated logical thought processes.
Ability to communicate security risks clearly to engineering, product, compliance, business, and executive stakeholders.
Comfortable operating in a fast-paced environment with evolving priorities and shared ownership across multiple security domains.
Experience with common threat modeling frameworks (STRIDE, DREAD, etc).
Experience with cloud-based Web Application Firewall solutions and web application protection strategies.
Familiarity with CNAPP, CSPM, CWPP, container security, runtime security, or cloud workload protection platforms.
Experience with source code security platforms such as GitHub Advanced Security or similar tools.
Experience conducting proactive threat hunting across cloud, identity, endpoint, network, SaaS, and application telemetry.
Familiarity with ethical hacking and penetration testing tools & methodologies.
Experience with AWS security best practices and native controls & services.
Prior Automotive or FinTech experience.
$175,000 - $185,000 a year