Staff Cloud Security Engineer
Reports to: Senior Manager, Internal Security • Location: Remote US
About the role
Cybercrime is growing, and more businesses are getting hit by threats that used to target only the biggest organizations. That pushes defenders like us to operate at the highest level, and it deepens our need for good people who want to make a meaningful impact. Founded in 2015 by former NSA cyber operators, Huntress is a remote-first team working to make enterprise-grade cybersecurity accessible to businesses of all sizes. We work closely with security teams and service providers protecting complex environments, often without the time or headcount to handle it all. That’s why we build our technology in-house and back it with a 24/7 human-led Security Operations Center (SOC). As a result, our platform is never disconnected from the experts who manage it, ensuring our customers' protection. Huntress now secures more than 5M endpoints and 11M identities worldwide. Those numbers keep growing because more businesses rely on us to help carry the load and operate with more confidence.
Responsibilities
- Product Security: Huntress is a B2B SaaS company providing a range of cybersecurity services to our partners and customers. You will be a key member of the internal product security team and help drive effective security detection and response across our production platform. A requirement for this role is having worked at a B2B SaaS company that provides cloud-hosted services to customers. You are right at home interacting with developers who work in SaaS production environments.
- Secure Cloud Architecture: Design, evaluate, and implement architectural security standards for our AWS, Azure, and PaaS cloud platforms. You’ll be a key stakeholder when we onboard new technologies or modify existing ones to meet business goals and objectives.
- DevSecOps Collaboration: Partner directly with internal DevOps and Platform teams to build security into every stage of the infrastructure-as-code lifecycle. You are comfortable engaging via PRs and reviewing IaC/HCL/DSL configurations.
- Threat Modeling: Review architecture and product development pitches, leveraging your extensive security knowledge to ensure security and privacy by design.
- Platform Vulnerability and Risk Management: Manage a robust vulnerability management program specifically tailored to our cloud environments. This entails triaging high-severity alerts and coordinating with internal teams to drive mitigations or remediations.
- Threat Detection & Response: Develop strategies to respond to and recover from security incidents affecting the Huntress platform. Implement tools, including runtime and build-level controls, to assist in threat detection and prevention.
- Own Security Compliance: This role will have the primary responsibility of owning cloud security controls end-to-end, including the design, monitoring, and remediation of control failures.
Requirements
- Flexible Security Mindset: Approach security as a business enabler, with a passion for striking the right balance between security, usability, and agility. Bring a measured, risk-based approach to solving security risks and challenges.
- SaaS Background: Experience working within a fast-paced SaaS company and understanding the unique security challenges of a cloud-first environment.
- Value Documentation: Recognize documentation as a critical tool for showing impact and value. Effectively detail security recommendations, process improvements, architectural decisions, and innovative ideas to ensure clarity and organizational buy-in.
- A Security-as-Code / Infrastructure-as-Code Mindset: Comfortable with IaC tools such as Terraform / Spacelift, as well as other engineering tools such as CircleCI and Git. Comfortable reading cloud configurations and understanding architecture from the code up.
- Proficiency with Scripting: Comfortable with a scripting language (e.g., Python or Go) to parse data or comb through logs efficiently.
- Team Player: An effective collaborator and communicator both cross-functionally and functionally.
- Deep Cloud Expertise: Extensive knowledge of AWS and/or Azure and other cloud platforms, with demonstrated expertise in designing secure cloud, application, and system architectures. Intimately familiar with cloud-native security tooling, logging, identity management, and security policy.
- Incident Response Knowledge: Working knowledge of incident response processes and strategies and familiarity with computer forensic tools and methods. Comfortable with a query language (jQL, SQL, Splunk, etc.) and combing through datasets during an incident.
- Remote-First Collaboration: Excellent communicator, capable of thriving and driving initiatives in a distributed, asynchronous work environment.
Pay
Compensation Range: $165,000 to $193,000 base plus bonus and equity
Benefits
- 100% remote work environment (since our founding in 2015)
- Generous paid time off policy, including vacation, sick time, and paid holidays
- 12 weeks of paid parental leave
- Highly competitive and comprehensive medical, dental, and vision benefits plans
- 401(k) with a 5% contribution regardless of employee contribution
- Life and Disability insurance plans
- Stock options for all full-time employees
- One-time $500 reimbursement for building/upgrading home office
- Annual allowance for education and professional development assistance
- $75 USD/month digital reimbursement
- Access to the BetterUp platform for coaching, personal, and professional growth