Senior Security Engineer

Los Angeles, CA (Remote)

$145K/yr – $170K/yrSenior Level5+ years expFull time

Posted 1 day ago

Top 1% of applicants do these two things.

The other 99% submit and hope. You're about to do something different.

Job Summary

Own and evolve the security tooling and architecture portfolio across identity, cloud posture, authentication, incident response, and security automation while partnering with platform engineering and mentoring the team.

  • Own and evolve the security tooling and architecture portfolio
  • Design identity and access architecture and governance
  • Lead incident response and security automation programs

Job Description

Responsibilities

  • Owning the Security Tooling Portfolio: Evaluating, integrating, and rationalizing the security tool stack so investments are coherent, well-integrated, and earning their value
  • Owning Identity and Access Architecture: Designing identity, access, and session governance across Google Workspace and additional identity providers, including least-privilege design, credential and secrets hygiene, service-identity architecture, and joiner, mover, and leaver controls at the design layer
  • Governing Cloud Security Posture: Defining security requirements for the GCP environment and translating them into policy and controls across Cloud IAM, organization policy, service account governance, and audit logging
  • Partnering with platform engineering on implementation, governing posture against those requirements, and feeding cloud telemetry into the detection pipeline
  • Advancing Authentication and Secrets: Driving our phishing-resistant MFA strategy such as passkeys and hardware keys, strengthening secrets-management architecture, and advancing SAML SSO, SCIM provisioning, and session policy across the SaaS environment
  • Governing OAuth and Token Lifecycle: Owning OAuth app vetting and governance, token lifecycle and revocation, and third-party application risk management
  • Owning Incident Response: Owning incident response and forensic practice, running investigations independently, and coordinating external partners during major escalations
  • Applying Security Automation and DaC: Treating detection, policy, configuration, and response automation as code that is version-controlled, peer-reviewed, and tested. Partnering with platform engineering on Terraform and cloud guardrails where security controls intersect with infrastructure
  • Developing Internal Capability: Mentoring and developing team members on security practice over time, and partnering with the Director of IT to inform security decisions across the organization

Requirements

  • 5+ years of hands-on security engineering experience in a professional environment, with a track record of owning security architecture and projects end to end
  • Detection engineering experience, including selecting, building, and operating a SIEM, writing and tuning detections, and owning log pipelines, alerting, and monitoring
  • 4+ years of hands-on security cloud engineering, GCP strongly preferred, including Cloud IAM, organization policy, service account governance, and audit logging
  • Deep identity and access management expertise, including federation (SAML SSO) and SCIM provisioning and deprovisioning
  • SaaS identity security depth, including phishing-resistant MFA (passkeys, hardware keys), secrets-management architecture, and OAuth app governance, token lifecycle, and third-party application risk
  • Hands-on incident response and forensic methodology, including sound evidence handling
  • Endpoint security posture experience, including EDR operations (CrowdStrike Falcon or equivalent) and device-trust or conditional-access design
  • Experience operating vulnerability management or exposure management programs, including prioritization by exploitability, asset criticality, and business risk
  • Security automation and infrastructure-as-code fluency, including detection-as-code and a tool such as Terraform, at a level beyond ad hoc scripting

Preferred

  • A background in infrastructure, cloud platform, DevOps, SRE, or systems engineering before moving into security, bringing an automation-first foundation to detection and governance work
  • Experience scaling or maturing a security program in a fast-growing environment
  • Industry certifications (GCP Professional Cloud Security Engineer, GIAC such as GCIH, GCDA, or GDAT, CISSP, OSCP)
  • Experience managing least-privilege access across many vendor systems, including those that do not support SSO
  • Player-coach or mentoring experience: while this role is scoped as a senior individual contributor, candidates who can develop internal talent will be considered for expanded scope
  • Exposure to SOC 2 or similar compliance frameworks, partnering with GRC on audit readiness
  • Scripting and automation experience (Python, Bash) for security tooling and workflow optimization

Benefits

  • Unlimited PTO
  • Extended Holiday break (Winter)
  • 100% paid parental leave
  • 401(k) matching
  • Medical, Dental, Vision, Life, Pet Insurance
  • Sponsored life insurance
  • Short Term Disability insurance and additional voluntary insurance
  • Annual Class Pass credits and more!
Wpromote logo

Wpromote

Wpromote is a top independent marketing agency that challenges convention to accelerate growth for brands. We believe every client, including legacy enterprise brands like Whirlpool, category leaders like Spanx, and fast-growing DTCs like Vuori, can maximize the business impact of media with the right outcomes-driven partner. Our holistic total commerce approach drives transformative results for retail brands across channels and purchase points, powered by our Challenger culture, deep business intelligence, and predictive Polaris platform. To stay ahead of the rapid evolution of commerce and consumer behavior, we put data-driven testing and experimentation at the heart of our organization and delivery model so our clients can outsmart instead of outspend the competition and move fast to capitalize on opportunities in an ever-changing media ecosystem

Founded in 2001
El Segundo, CA, US
694 employees (281 in marketing)

Traffic Signals

Monthly Visitors
584.9M
Monthly Google Ads Budget
$8.1K
Traffic Source Mix
Search
17.6%
Direct
57.3%
Referral
14.1%
Social
10.3%
Paid
0.7%

Headcount Trend

Current headcount: ~684

Marketing Team

Marketing Team Size
269 (39% of company)
Median Career Experience
11 years
Median Tenure
5.7 years
Marketing Roles Posted (Last 30 Days)
13

Recent News