Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Guidewire Software

Senior Security Engineer

Guidewire Software

. Lead complex infrastructure security initiatives involving multiple teams, systems, and dependencies, focusing on AWS cloud environments and CI/CD pipelines .

Posted 9/15/2026full-timeRemote • United StatesSenior💰 $133,000 - $199,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in designing and operating secure AWS environments, implementing infrastructure as code, and managing cloud security initiatives. Proficient in risk-based security analysis, CI/CD pipeline security, and cloud governance practices.

Highest-signal resume keywords
AWS Security EngineeringInfrastructure As Code (Terraform, CloudFormation)CI/CD Pipeline Security (GitHub Actions)Cloud Governance And Access ManagementThreat Modeling And Risk Assessment

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Cloud SecurityInfrastructure SecurityDevSecOpsScripting (Python, Go)Network SecurityKubernetes SecurityConfiguration ManagementIncident ResponseVulnerability ManagementData Protection
Soft Skills
Strong Communication SkillsMentoringRisk ManagementCollaborationProblem Solving
Tools & Technologies
AWSGoogle Cloud Platform (GCP)CI/CD ToolsMonitoring ToolsSecrets Management ToolsAI Security ToolsNetwork Telemetry ToolsLogging ToolsContainer Security ToolsArtifact Management Tools
Certifications & Qualifications
AWS Security SpecialtyCISSPGIAC
Industry Keywords
Cloud EnvironmentsSecurity ControlsOperational ResilienceAccess ControlZero-Standing PrivilegeSoftware Supply Chain SecurityAI SecurityNIST AI RMFOWASP LLM Top 10ISO/IEC 42001

Tech Stack

Tools & technologies
AWSCloudDNSFirewallsGoogle Cloud PlatformGuidewireKubernetesPythonTerraformGo

About the role

Key responsibilities & impact
  • Lead complex infrastructure security initiatives involving multiple teams, systems, and dependencies, focusing on AWS cloud environments and CI/CD pipelines
  • Design, implement, and operate security controls across AWS and applicable cloud platforms
  • Build secure-by-default solutions using infrastructure as code, policy as code, CI/CD, and automation
  • Improve cloud governance, security posture, and operational resilience
  • Define and maintain security baselines for cloud accounts, operating systems, containers, AMIs, Kubernetes, networks, and supporting infrastructure
  • Support cloud account onboarding, offboarding, inventory, configuration drift management, exception handling, and control validation
  • Design and improve cloud and infrastructure network security, including segmentation, traffic visibility, ingress and egress control, DNS, firewalls, routing, private connectivity, monitoring, and enforcement
  • Secure CI/CD and software supply chains, including build and deployment workflows, dependencies, artifacts, containers, registries, third-party actions, secrets, and runner environments
  • Support asset and identity governance for applications, infrastructure, containers, service accounts, workload identities, API keys, AI agents, and MCP tools
  • Participate in AI security initiatives involving AI models, agents, and tool integrations, including threat modeling, prompt injection defenses, data egress protection, guardrails, human-in-the-loop controls, and monitoring
  • Apply risk-based security analysis using reachability, attack paths, asset criticality, exploitability, and business impact
  • Validate scanning-tool and AI-generated findings, establish ownership and remediation expectations, and improve finding-quality feedback loops
  • Represent Security in architecture, change management, design review, and operational forums
  • Communicate risks, trade-offs, assumptions, dependencies, and business impact to technical and non-technical audiences
  • Create standards, runbooks, architecture decision records, dashboards, documentation, and enablement materials
  • Mentor engineers and help partner teams adopt secure patterns without direct management responsibility
  • Participate in on-call rotations and incident response support for cloud and infrastructure security incidents
  • Monitor emerging threats and translate relevant developments into improvements to Guidewire’s security controls

Requirements

What you’ll need
  • Typically 5+ years of experience in security engineering, cloud security, infrastructure security, DevSecOps, or equivalent practical experience
  • Hands-on experience designing and operating secure AWS environments is required
  • Experience with Google Cloud Platform (GCP) is strongly preferred; experience with other cloud platforms is a plus
  • Experience with cloud governance, access management integration, policy enforcement, logging and monitoring, data protection, network security, configuration management, and cloud account lifecycle controls
  • Hands-on experience with infrastructure-as-code using Terraform, CloudFormation, or comparable technologies
  • Hands-on experience building, securing, testing, and operating CI/CD pipelines, preferably using GitHub Actions or comparable platforms
  • Experience with pipeline automation, secrets management, artifact handling, and runner security
  • Hands-on scripting or programming experience using Python, Go, or another appropriate language
  • Practical knowledge of cloud and infrastructure networking, including segmentation, routing, DNS, firewalls, ingress and egress controls, private connectivity, and network telemetry
  • Experience securing containers and Kubernetes platforms, preferably EKS or an equivalent platform
  • Knowledge of threat modeling, secure design, vulnerability management, security testing, risk assessment, monitoring, and incident response
  • Ability to evaluate security-control effectiveness using evidence, operational feedback, exceptions, findings, and relevant metrics
  • Demonstrated experience building, operating, or contributing to security measurement and analysis capabilities
  • Working knowledge of identity and access-control concepts, including authentication, authorization, privileged access management, identity governance, zero-standing privilege, workload and non-human identities, and secrets management
  • Working knowledge of software supply-chain security concepts, including SBOMs, artifact signing, provenance, dependency management, secure registries, and CI/CD runner hardening
  • Working knowledge of foundational AI security concepts, including LLM risks and prompt safety
  • Ability to own complex work, manage ambiguity, make trade-offs, identify risks, and deliver outcomes across multiple teams
  • Strong written and verbal communication skills
  • Preferred: hands-on experience or deep knowledge of AI-security risks and controls, including LLMs, AI agents, MCP, AI gateways, prompt injection defense, sensitive-data leakage, and advanced AI models/tools
  • Preferred: familiarity with NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, ISO/IEC 42001, or comparable frameworks
  • Preferred: certifications such as AWS Security Specialty, CISSP, GIAC, or equivalent practical expertise

Benefits

Comp & perks
  • Health insurance
  • Dental insurance
  • Vision insurance
  • Paid time off
  • Company sponsored retirement plan
  • Some roles may be eligible for the annual company bonus plan
  • Some roles may be eligible for commissions
  • Some roles may be eligible for long term incentive awards
  • Disability accommodations throughout the hiring process
  • Appeals process for denied accommodations or non-selection decisions