Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
DreamHost

Security Engineer II

DreamHost

. Investigate and resolve complex security incidents across shared, virtualized, and dedicated Linux hosts .

Posted 9/24/2026full-timeRemote • Arizona • United StatesMid-LevelSenior💰 $125,000 - $145,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in security engineering, incident response, and application security, with a strong focus on Linux environments and vulnerability management. Proficient in automation, tooling, and security policy development, while effectively communicating technical risks to diverse stakeholders.

Highest-signal resume keywords
Security EngineeringIncident ResponseApplication SecurityLinux AdministrationVulnerability Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Incident ResponseApplication SecurityVulnerability ManagementLinux AdministrationProduction ScriptingLog AnalysisCloud SecuritySecrets ManagementAI ToolingAutomation
Soft Skills
Clear CommunicationMentoringProblem SolvingEthical JudgmentAbility to Work Under Pressure
Tools & Technologies
VaultGitAnsibleAWSGCPAzureOpenStackMod_securityPythonBash
Industry Keywords
Incident Write-UpsSecurity PoliciesCompliance EffortsMulti-Tenant EnvironmentsSupply-Chain Risk

Tech Stack

Tools & technologies
AnsibleAWSAzureCloudFirewallsGoogle Cloud PlatformLinuxOpenStackPerlPythonVaultGo

About the role

Key responsibilities & impact
  • Investigate and resolve complex security incidents across shared, virtualized, and dedicated Linux hosts
  • Scope blast radius, contain compromises, preserve evidence, and produce incident write-ups
  • Design and implement safeguards for customer sites, accounts, and infrastructure
  • Build malware and webshell signatures and log-based detections while reducing false positives
  • Review the security of in-house applications, infrastructure, control plane, customer panel, internal tooling, and third-party/open-source dependencies
  • Modernize secrets management by moving static credentials into Vault, adopting dynamic credentials, and eliminating plaintext secrets
  • Manage identity and access lifecycle, including directory and SSO migration, privileged access reviews, and offboarding
  • Drive vulnerability management and patch velocity across a heterogeneous fleet, including end-of-life OS and runtime remediation
  • Build automation and tooling for detection, monitoring, response, and operational safety
  • Review and govern internal AI and agent tooling for data exposure, permission scope, agent identity, and abuse paths
  • Partner with Systems, Development, Abuse, and Support to implement security controls
  • Mentor less experienced team members and contribute to shared knowledge and runbooks
  • Contribute to security policies, standards, processes, and compliance efforts

Requirements

What you’ll need
  • 3–6 years in security engineering, incident response, application security, offensive security, or systems administration
  • Demonstrated ability to resolve complex security problems independently
  • Depth in at least one of application security, incident response and detection engineering, or offensive security and penetration testing, plus working competence in the other two
  • Strong hands-on Linux, preferably Debian/Ubuntu, including processes, namespaces, capabilities, filesystems, kernels, and failure modes
  • Experience operating long-lived production systems, including repairing hosts in place under load with real users
  • Experience in multi-tenant or customer-facing environments where users are untrusted
  • Production scripting and automation experience using Python, Go, Bash, Perl, or similar
  • Log analysis and investigation at scale
  • Familiarity with intrusion detection and web application firewalls such as mod_security
  • Working knowledge of cloud platform security, including AWS, GCP, Azure, or OpenStack, IAM, network controls, and workload isolation
  • Familiarity with secrets management and CI/CD security, including Vault or equivalent, pipeline hardening, dependency and supply-chain risk
  • Fluency with version control and infrastructure as code, including Git and Ansible or similar
  • Practical, current fluency with AI tooling used in real engineering work
  • Clear written and verbal communication, including translating technical risk for non-technical stakeholders
  • Strong sense of ethics, healthy skepticism, and ability to stay useful under pressure

Benefits

Comp & perks
  • Full health/vision/dental for the entire family at zero cost to team member
  • 3% Safe Harbor contributed to 401(k) plus up to 1% employer match
  • Opportunities for profit sharing and bonuses
  • Generous time-off (starting at 15 vacation days)
  • 11 Paid holidays
  • Paid sick leave (80 hours accrued)
  • Tuition reimbursement (50/50 up to a specific amount)
  • Pet Insurance
  • Thrive Pass wellness allowance of $30 per month
  • Udemy online learning courses
  • Disability Insurance
  • Generous maternity/paternity leave
  • Discounted personal travel through corporate booking program Egencia
  • Laid-back atmosphere
  • Fun monthly company events
  • Free web hosting
  • Company-issued laptop
  • Opportunities for growth
  • Extensive training