Nue

Nue

Staff Security Engineer, DevSecOps

USA · Staff+

Sponsorship not specifiedDetected 1 day ago
JavaScriptPythonGoAWSCloud PlatformsCI/CDDevOpsSite Reliability EngineeringPlatform EngineeringCybersecuritySOC OperationsDetection EngineeringIncident ResponseSupply ChainCommunicationCollaboration

About the role

  • We want someone who is hands-on, writes code, automates security controls, improves infrastructure, hardens systems, and helps engineers ship safely at speed.
  • You'll work at the intersection of software engineering, cloud infrastructure, security operations, and developer enablement.
  • Help define the security tooling strategy across application security, cloud security, detection, and developer workflows, evaluating and integrating tools that meaningfully reduce risk without slowing delivery.

Responsibilities

  • Drive secure-by-default patterns across the organization through reusable libraries, templates, guardrails, and paved-road workflows, improving security posture across cloud infrastructure, the application stack, and developer workflows.
  • Lead practical threat modeling for new product capabilities, platform changes, and high-risk workflows, translating findings into clear engineering actions.
  • Improve software supply chain security across build systems, dependencies, container images, secrets, and deployment processes.
  • Design, build, and operate security automation and production-quality tooling for identity and access management, secrets management, vulnerability management, and policy enforcement.
  • Build and maintain detection and alerting for meaningful security events across endpoints, cloud infrastructure, application logs, audit trails, and identity systems.
  • Partner with engineering teams to review architecture, application design, infrastructure changes, and operational patterns with a focus on reducing exploitable risk.
  • Support compliance and audit needs through engineering-driven controls, evidence automation, logging, and repeatable operational practices.
  • Own hands-on incident response, including triage, containment, root cause analysis, remediation, and post-incident follow-through.
  • Participate in on-call rotations for high-severity security and platform incidents and build and test response procedures for scenarios such as credential compromise, privilege escalation, and exposed secrets.

Requirements

  • Bachelor's degree in Computer Science, Engineering, or equivalent practical experience.
  • 8+ years of experience across software engineering, infrastructure engineering, platform engineering, SRE, DevOps, security engineering, or related roles in production SaaS environments.
  • 3+ years of hands-on experience in security engineering, platform security, cloud security, or related security-focused roles.
  • Proven ability to write code for automation, integrations, internal tooling, and operational workflows using languages such as Python, Go, JavaScript, or Bash.
  • Experience operating in a DevSecOps or platform-adjacent model where security is embedded into delivery pipelines and engineering workflows.
  • Strong experience with identity and access management, secrets handling, key management, logging, auditability, and least-privilege design.
  • Practical experience with security monitoring, detection engineering, alert tuning, and incident response.
  • Ability to assess real-world risk and prioritize pragmatic fixes over theoretical perfection.
  • Experience partnering with engineering teams to improve security architecture, code patterns, infrastructure posture, and operational readiness.
  • Demonstrated ability to use AI-assisted development tools to accelerate investigations, automate repetitive work, and improve engineering effectiveness while maintaining strong judgment.

This listing is sourced directly from Nue's careers page and normalized into a canonical job model.