FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security engineering for products, focusing on threat modeling, incident response, and security testing. Proficient in managing cloud security posture and ensuring compliance with industry standards such as HIPAA.
Highest-signal resume keywords
Security Engineering OwnershipThreat ModelingPenetration TestingDeep Skill in Rust, TypeScript, or PythonCloud Security Engineering
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security TestingCode ReviewTLS and CertificatesIdentity and Access ManagementSecrets ManagementLinux HardeningTechnical WritingTrust Boundary AnalysisRisk AssessmentDependency Policy
Soft Skills
Problem-SolvingCommunication
Tools & Technologies
AWSCloud ServicesOperating-System ImagePharmacy Robot
Industry Keywords
HIPAAIEC 62443UL 2900-1NISTIR 8259Healthcare Security
Tech Stack
Tools & technologiesAWSCloudLinuxPythonRustTypeScript
About the role
Key responsibilities & impact- Own security engineering for a pharmacy robot, its operating-system image, on-device software, cloud service, and update path
- Maintain the threat model covering machine-to-cloud, operator-to-screen, update path, remote support, and supplier trust boundaries
- Review system designs early and record the reviews
- Own device identity and key-custody priorities and verification with operating-system image engineers
- Run independent security testing end to end, including scope, test environment, triage, remediation, and retest evidence
- Set rules for finding, triaging, and fixing weaknesses in code, dependencies, device images, and cloud systems; track findings to closure and report status
- Lead the security side of incident response, including detection, triage, containment, evidence, and follow-up changes, with systems reliability engineers
- Review customer security statements against versioned implementations, deployed configurations, and operational records
- Manage cloud posture covering identity and access, secrets, infrastructure-change review, and cloud-provider detection services
- Verify security and privacy controls, including controls arising from HIPAA, and collect evidence from systems
- Assess and recommend without accepting risk on the company's behalf; ensure exceptions have approvers and conditions and that authorized business owners accept residual risk
- Report to the Head of Software Engineering and work daily with on-machine software, cloud-service, and operating-system image engineers
Requirements
What you’ll need- Experience owning the security of a shipped product end to end
- Ability to describe a problem found, fixed, and followed until it stayed fixed
- Ability to read and write code
- Deep skill in one of Rust, TypeScript, or Python, with comfort reading the others
- TLS and certificates
- Identity and access
- Secrets management
- Linux hardening
- Ability to reason about a trust boundary from hardware to cloud
- Experience running or working closely with penetration tests
- Ability to rank security issues by potential impact and defend deferring an issue
- Threat-modeling experience that engineers use
- Precise technical writing for engineers, executives, and customer assessors
- Nice-to-have: verified start-up, hardware-held keys, signed updates, fleet identity
- Nice-to-have: security in healthcare or another regulated industry
- Nice-to-have: customer security reviews from the supplier's side
- Nice-to-have: AWS cloud security engineering
- Nice-to-have: dependency policy, artifact signing, and provenance
- Nice-to-have: working knowledge of IEC 62443, UL 2900-1, or NISTIR 8259
Benefits
Comp & perks- Ownership — security engineering for the machine and everything it talks to
- Hard problems: trust boundaries from the hardware to the cloud, device identity and key custody, and the path that updates the machine
- Small team, zero bureaucracy, high trust
- Significant autonomy and influence
- Hybrid work, three days a week at headquarters in the Bay Area
