远程工作雷达

高级安全工程师

Senior Security Engineer

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Roofr
薪资未公开
工作地点Canada
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间昨天
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 Canada 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

在Roofr,我们对客户充满热情。我们不断收集反馈,以塑造、优先排序并推出客户真正需要的产品。这就是Roofr的CRM与众不同之处。我们最初构建了基本的销售工具,如航拍屋顶测量和数字销售提案。但当我们的客户要求一种简单、经济的方式来管理和扩展他们的整个业务时,我们倾听并做出了回应。因此,我们创建了一个CRM,将这些解决方案——以及支付、材料订购等——整合到一个无缝且强大的平台上。随着清晰的路线图,我们期待继续扩展并以创新产品引领市场。

我们拥有出色的文化、稳健的财务状况和一流的公司指标。加入一家已经取得成功但仍处于早期阶段的初创公司,是一个激动人心的时刻,团队将获得显著的成长、股权以及真正产生影响的机会。

此职位为现有空缺。

作为高级安全工程师,你将向工程副总裁汇报,并作为Roofr安全小组的一部分,与CTO和DevOps紧密合作。你将直接参与提升Roofr的安全态势——完善现有的措施并推动其随着公司的发展而进步。你将负责检测和阻止威胁的工具和流程,与工程团队合作推进设计安全实践,并在出现问题时担任第一响应者。

#### **你将负责的工作**

- 负责跨云环境的安全基础设施设计与加固——网络分段、防火墙、IDS/IPS、VPN、WAF和端点检测与响应(EDR)
- 全流程主导漏洞管理:执行评估和认证扫描,根据可利用性和影响范围进行分类和优先级排序,并与工程团队推动修复的SLA
- 构建和优化检测内容(SIEM/SOAR规则、警报逻辑)以应对真实攻击技术——不仅仅是默认的供应商签名
- 作为安全事件指挥官处理安全事件:隔离、清除、进行取证分析并撰写事件后复盘报告
- 在新功能和基础设施变更上线前进行威胁建模——发现设计层面的风险,而不仅仅是实现中的错误
- 负责生产AWS账户中的IAM规范和云安全态势(最小权限、密钥/密钥管理、网络边界)
- 编写、执行并维护安全策略和标准——作为动态控制来管理,而不是放在驱动器上的文档

查看英文原文

At Roofr, we’re obsessed with our customers. We constantly gather feedback to shape, prioritize, and launch the products they truly need. That’s what makes Roofr’s CRM special. We started by building essential sales tools like aerial roof measurements and digital sales proposals. But when our customers asked for a simple, affordable way to manage and scale their entire businesses, we listened. So, we created a CRM that connects these solutions—along with payments, material ordering, and more—into a seamless, powerful platform. With a clear roadmap ahead, we’re excited to continue expanding and leading the market with innovative products.

We have an amazing culture, strong financials, and best-in-class company metrics. It’s an exciting time to be part of an extraordinary startup that is already successful, yet still early enough to offer its team significant growth, equity, and the opportunity to make a real impact.

This position is for an existing vacancy.

As Senior Security Engineer, you'll report to the VP of Engineering and work closely with the CTO and DevOps as part of Roofr's security guild. You'll contribute directly to improving Roofr's security posture — sharpening what's already in place and driving it forward as the company scales. You'll own the tools and processes that detect and stop threats, partner with engineering on secure-by-design practices, and act as the front-line responder when something goes wrong.

#### **What You’ll Get to Do**

- Own design and hardening of security infrastructure across cloud environments — network segmentation, firewalls, IDS/IPS, VPNs, WAF, and endpoint detection and response (EDR)
- Lead vulnerability management end to end: run assessments and authenticated scans, triage and prioritize by exploitability and blast radius, and drive remediation SLAs with engineering
- Build and tune detection content (SIEM/SOAR rules, alerting logic) against real attack techniques — not just default vendor signatures
- Act as incident commander for security incidents: contain, eradicate, run forensics, and write the post-incident review
- Threat-model new features and infrastructure changes before they ship — catch design-level risk, not just implementation bugs
- Own IAM hygiene and cloud security posture (least privilege, key/secret management, network boundaries) across production AWS accounts
- Write, enforce, and maintain security policies and standards — own them as living controls, not documents that sit in a drive
- Own Roofr's compliance program end to end: map controls to NIST CSF 2.0, SOC 2, and CCPA/CPRA, run the audits, close the gaps, and keep evidence current between them
- Run tabletop exercises and incident playbook drills
- Push secure-by-design practices into engineering workflows — threat modeling in design review, security requirements in the SDLC, not a gate bolted on at the end

#### **What You’ll Bring to the Role**

#### Qualifications

- Bachelor's degree in computer science, IT, cybersecurity, or equivalent hands-on experience
- 5-8+ years in security engineering, incident response, or related infrastructure roles, including time as the primary or senior responder on real incidents
- Certifications are a strong plus — CISSP, OSCP, GCIH, or CEH

#### Technical

- Deep network security fundamentals — firewalls, VPNs, routing/segmentation, network boundaries, TLS, DNS, and how attackers actually abuse them
- Hands-on cloud security in AWS — IAM policy design, VPC architecture, KMS/secrets management, CloudTrail/GuardDuty or equivalent
- Real incident response experience — triage, containment, forensics, root cause, not just theory from a course
- Working knowledge of SIEM/SOAR tooling, writing detection logic (Python/Bash), and building your own tooling when nothing off-the-shelf fits
- Fluent in compliance frameworks — NIST CSF 2.0, SOC 2, and CCPA/CPRA — and translating controls into policy people actually follow
- Strong software engineer at heart — comfortable reading and writing real application code, not just scripts, so you can dig into the codebase directly instead of filing a ticket and waiting

#### Competencies

- Confident being the only security voice in the room — makes the call and owns it
- Translates technical risk into business terms leadership can actually act on
- Calm and decisive under incident pressure; documents as they go, not after
- Ownership-oriented; builds the process that doesn't exist yet instead of waiting for one
- Strong individual contributor who wants to stay hands-on — this role builds the foundation directly, it doesn't lead from the side

#### **Bonus Points:**

- Experience using AI/LLM tooling for threat intelligence — alert triage, detection summarization, or hunting workflows — not required, but a plus for a team building modern security practice from scratch
- Familiarity with GDPR — a plus as Roofr's customer base grows internationally
- Experience with PHP/Laravel — a plus for digging into Roofr's own codebase directly, not required
- Comfortable around Postgres — helpful, not required

Our compensation ranges are built using multiple market benchmarks and reflect both the scope of the role and current market data. While many hires fall within the beginning to midpoint of the band to allow for growth over time, we tailor offers based on each candidate’s experience, seniority, and demonstrated impact.

**🏠 What we offer (US + Canada)**

When you join our team, you’re not just accepting a job. You’re making a career move. Here’s how we’ll support you in doing some of the most impactful work of your career:

**🏝️ Vacation/Paid Time Off:**

- 1st week of employment is mandatory PTO! Start your journey with Roofr by decompressing and recharging - we will see you in week 2!
- 1 Friday off per month (we call those our laundry days!)
- Company wide paid shutdown for the week between Christmas and New Years
- Flexible time off
- 80% employer-paid benefits in the U.S. and 100% employer-paid premiums for Extended Healthcare and Dental in Canada
- RRSP/401k match
- Generous Parental Leave policy

**🤝 Perks:**

- We host an annual company retreat with great team building activities
- Ample learning and development opportunities to continue growing your career
- Home office setup stipend
- Internet and phone allowance
- Remote first culture
- Weekly Friday paydays!

**🤖 AI Notice**

At Roofr, we’re big fans of AI. It helps us write job descriptions that don’t put you to sleep, takes notes during interviews so we can actually listen, and even helps us track down awesome humans like you.

Feel free to use AI to prep, research, or get pumped up for your interview (we see you, ChatGPT power users 👀). But when it’s time to chat, we’d love to meet you, not your AI alter ego. Bring your real, unfiltered self, we promise we will too.

And don’t worry, a real, live human is behind every part of our process. Every application is reviewed by a real person, and you’ll always speak with real humans throughout the interview process. No bots, just good people ☺️

⚠️ **Important Notice**

We’ve been made aware of an individual impersonating Roofr using a fraudulent domain: **roofrr.com** (note the extra “r”). __Our company takes the security and privacy of job applicants very seriously. We will never ask for payment, bank details, or personal financial information as part of the application process. All our legitimate job postings can be found on our official career site. Please be cautious of job offers that come from non-company email addresses, instant messaging platforms, or unsolicited calls.__

_To ensure your application is legitimate, please apply **directly** through our official careers page: [https://roofr.com/careers](https://roofr.com/careers)._

_If you receive any suspicious messages or have questions, reach out to us at **talent@roofr.com**._

_Your safety and security are important to us — thank you for your vigilance!_

_Roofr is proud to be an equal opportunity employer. We are committed to equal employment opportunity in the workplace regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or veteran status._

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

产品增长主管

RoofrUnited States、Canada$250,000 - $300,000/年permanent4 天前
AI市场运营限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

高级收入运营专员

RoofrCanada90,000 - 105,000/年 CADpermanent11 天前
AI市场运营职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

高级人力资源专员

RoofrCanada80,000 - 95,000/年 CADcontract12 天前
职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位