FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Security Engineer
MatX. Own and grow the supply chain and build integrity program, including dependency and third-party IP provenance, artifact and code signing, SBOM generation and consumption, reproducible builds, and CI/CD, build cache, and runner hardening .
Posted 9/16/2026full-timeMountain View • California • United StatesSeniorLead💰 $160,000 - $600,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in security engineering with a focus on application and cloud security, vulnerability management, and secure software development practices. Proficient in threat modeling, manual code review, and integrating security into the software development lifecycle.
Highest-signal resume keywords
Security EngineeringApplication Security FundamentalsCloud Infrastructure SecurityVulnerability ManagementProduction-Quality Code in Go, Python, or Rust
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Threat ModelingManual Secure Code ReviewVulnerability ResearchPenetration TestingSASTDASTSCA ToolingInfrastructure-as-CodeCI/CD SecurityArtifact Signing
Soft Skills
Risk PrioritizationAbility to Operate with Ambiguity
Tools & Technologies
GCPAWSAzureTerraformHSMKMS
Industry Keywords
Supply Chain SecurityBuild SecurityExport-Controlled Technical DataOpen Source Security ToolingCompliance with U.S. Export Control Laws
Tech Stack
Tools & technologiesAWSAzureCloudGoogle Cloud PlatformOpen SourcePythonRustSDLCTerraformGo
About the role
Key responsibilities & impact- Own and grow the supply chain and build integrity program, including dependency and third-party IP provenance, artifact and code signing, SBOM generation and consumption, reproducible builds, and CI/CD, build cache, and runner hardening
- Perform hands-on security assessments of code, build tooling, internal services and dashboards, developer platforms, and systems holding design data
- Conduct manual code review, application and API testing, and infrastructure assessment
- Conduct vulnerability research and turn findings into fixes and durable controls
- Partner with software, compiler, ML, and silicon teams on threat modeling and design reviews
- Harden cloud infrastructure through IAM, network segmentation, secrets management, workload identity, infrastructure-as-code review, and security guardrails
- Build and run vulnerability management, including discovery, triage, exploitability-based prioritization, and remediation tracking
- Integrate security into the SDLC through code scanning, dependency policy, pre-merge checks, secrets detection, and paved-road libraries and templates
- Write automation, tooling, services, internal utilities, and developer-facing tools that scale security work
- Help protect sensitive IP and export-controlled technical data with People, IT, and Legal teams
- Report to the Security Lead
Requirements
What you’ll need- 8+ years in security engineering
- Real depth in at least two of: application and product security, offensive security, cloud infrastructure security, supply chain and build security, detection and response
- Strong application security fundamentals: threat modeling, manual secure code review, vulnerability classes and mitigations, and SAST, DAST, and SCA tooling
- Hands-on offensive experience in penetration testing, red team engagements, or vulnerability research
- Current fluency in application and cloud attack paths
- Strong software engineering skills; production-quality code in Go, Python, Rust, or similar
- Ability to read code in languages you do not write
- Working knowledge of GCP, AWS, or Azure, including IAM, network architecture, secrets management, and logging
- Familiarity with artifact signing, provenance and attestation, SBOMs, and CI/CD security
- Track record of shipping fixes with development teams
- Ability to prioritize risk-reduction work and operate with ambiguity and breadth
- Experience with containers and infrastructure-as-code, such as Terraform, is a bonus
- Experience securing high-value IP or export-controlled technical data is a bonus
- Familiarity with EDA, hardware design, or ML training infrastructure is a bonus
- Experience with secure boot, firmware signing, code signing infrastructure, HSM, or KMS-backed key management is a bonus
- Experience standing up a security function and first compliance efforts is a bonus
- Open source security tooling, published research, or conference talks are a bonus
- Must be able to perform job functions in compliance with U.S. export control laws without obtaining a license from U.S. export control authorities
Benefits
Comp & perks- 4 weeks PTO (accrued) + 12 company Holidays + up to 3 weeks remote work
- Company-subsidized Medical (Kaiser or Anthem) for employees & dependents
- Guardian Dental and Vision insurances for employee & dependents
- Life insurance, plus HSA and FSA offerings via Lively
- Roth IRA and/or 401K retirement plans with up to 5% company contribution to 401K
- 100% company-paid life insurance (up to $300K)
- Long-term disability insurance
- $1500 Professional Development Budget (per year)
- Onsite team lunch and dinner Monday-Friday
- Company-paid daily commute via Uber account or train reimbursement
- $50/month MatX E[x]tras perk allowance
- $35/month cellular reimbursement and $40/month wifi reimbursement
- 100% paid mental health benefit via SpringHealth and Guardian EAP
- Up to 12 weeks paid parental leave, 10 weeks pregnancy disability leave, flexible return-to-work hours, and reproductive health and parental benefit
- Up to $20K/month AI resources plus a dedicated internal AI Tooling Team