Sift Stack
Software Engineer, Security Infrastructure
Marina Del Rey, CA
Work authorization required$170k-$220kDetected 88 days ago
PythonGoBashAWSCloud PlatformsKubernetesTerraformCI/CDPlatform EngineeringRESTCybersecurityIncident ResponseComplianceAuditingHardware DesignProblem Solving
About the role
- you will define the posture, architecture, and practices that keep our products and infrastructure secure in the most demanding environments.
- Embed security guardrails directly into infrastructure-as-code (Terraform), container orchestration, and deployment workflows so that secure-by-default becomes the path of least resistance.
- Improve visibility into our overall security posture through automated reporting, dashboards, and real-time observability that highlight risks and control coverage.
Responsibilities
- Build and maintain tooling, scripts, services, and automation that assess, enforce, and monitor security and compliance controls across our AWS cloud environments, Kubernetes clusters, and CI/CD pipelines.
- Develop lightweight internal solutions (e.g., policy-as-code, custom scanners, CI/CD integrations) that make security and compliance automatic, auditable, and invisible to the rest of engineering.
- Partner closely with the infrastructure and platform engineering teams to harden cloud-native systems, implement access controls, encryption, logging/monitoring, and vulnerability management at scale.
- Support incident response and post-incident improvements by building better observability and tooling that accelerates detection and recovery.
- Conduct security reviews of new features, services, and infrastructure changes, providing clear guidance that helps teams design and implement secure solutions.
- We collaborate in person twice a week-on Mondays and Thursdays-and come together for a full week every two months.
- As a Software Engineer, Security Infrastructure, you will not just maintain a security checklist
- As a Software Engineer, Security Infrastructure, you will not just maintain a security checklist; you will define the posture, architecture, and practices that keep our products and infrastructure secure in the most demanding environments.
Requirements
- U.S. Person Required: Must be a U.S. citizen, lawful permanent resident, or protected individual such as an asylee or refugee in compliance with ITAR (International Traffic in Arms Regulations) / EAR (Export Administration Regulations) regulations.
Skills
- Deep familiarity with implementing technical controls for SOC 2, FedRAMP, or similar frameworks in real production systems.
- Working knowledge across core security domains:
- Access control, identity management, and least-privilege enforcement
- Logging, monitoring, auditing, and security observability
- Encryption, key management, and secrets handling
- Vulnerability scanning, policy-as-code, and continuous compliance
- Incident response and change management
Compensation
- $170,000 - $220,000 per year. Plus equity and benefits.
Benefits
- Plus equity and benefits.
Company info
- We are open to relocating candidates to LA or working from our San Francisco office for the right candidate.
Visa & Work Authorization
- U.S. Person Required: Must be a U
Apply directly at Sift Stack →Create a free account for alerts like thisView Sift Stack immigration profile
This listing is sourced directly from Sift Stack's careers page and normalized into a canonical job model.