远程工作雷达

高级云安全工程师

Senior Cloud Security Engineer

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Beyond Finance
薪资$140,000 - $165,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间2026-08-07
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

在Beyond Finance,我们致力于帮助普通美国人摆脱不断加剧的债务困境,迈向更光明的财务未来。通过富有同理心的个性化服务、以合规和道德为核心的文化、支持用户的技术以及定制化的财务解决方案,我们已帮助超过100万客户走上更美好的未来之路。

虽然我们对已取得的成就感到自豪,但我们正在寻找新的合作伙伴,帮助我们更进一步!如果你希望加入一家以帮助人为首要目标的前瞻性、快速发展的组织,我们期待你的加入。

### 职位描述

作为高级安全工程师,你将强化我们的AWS环境和软件开发流程的安全性。Wiz中的云安全和漏洞管理是主要关注点。

你将与DevOps、工程团队和应用安全工程师合作,在基础设施、身份和CI/CD中建立预防性控制措施。工作内容为实际操作:配置工具、审查架构、加固流程,并在需要时支持应用安全工作。

### 主要职责

- 使用Wiz和AWS原生服务,在我们的AWS环境中负责云安全态势,降低IAM、网络分段、容器安全、密钥和数据暴露等方面的风险。
- 通过可重用模块、防护措施和代码即政策的方式,在基础设施即代码中建立安全默认设置。
- 与DevOps合作加固CI/CD流程。
- 在云和应用发现中运行漏洞管理:接收、优先级排序、SLA跟踪和与工程团队的修复。
- 构建可扩展程序的自动化:数据摄入、去重、优先级排序和面向开发者的流程。
- 为所负责的系统添加遥测、警报和操作手册。
- 运行和优化我们的WAF:管理规则和自定义规则、速率限制和机器人缓解。

### 要求

- 5年以上在云安全和漏洞管理方面的实际安全工程经验。
- 强大的AWS安全背景:IAM、网络、容器编排以及日志和审计。
- 实际经验在保护CI/CD流程和基础设施即代码;要求使用Terraform。
- 有运行或显著贡献于漏洞管理计划的经验。
- 了解OWASP Top 10和威胁建模。
- 能够独立工作并推动项目进展。

查看英文原文

At Beyond Finance, we've made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care,a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions, we've helped over 1 million clients on their path to a brighter future.

While we're proud of what we've already accomplished, we're searching for new collaborators to help us get to the next level! If you're looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.

### The Role

As a Senior Security Engineer, you'll harden the security posture of our AWS environment and our software development pipeline. Cloud Security and vulnerability management in Wiz are the primary focus.

You'll partner with DevOps, Engineering, and our Application Security Engineer to build preventative controls across infrastructure, identity, and CI/CD. The work is hands-on: configuring tooling, reviewing architecture, hardening pipelines, and supporting application security work where your range is needed.

### Key Responsibilities

- Own cloud security posture across our AWS environment using Wiz and AWS-native services, reducing risk across IAM, network segmentation, container security, secrets, and data exposure.
- Establish secure defaults in our Infrastructure as Code through reusable modules, guardrails, and policy as code.
- Harden CI/CD pipelines in partnership with DevOps.
- Run vulnerability management across cloud and application findings: intake, prioritization, SLA tracking, and remediation with engineering.
- Build automation that scales the program: ingestion, deduplication, prioritization, and developer-facing workflows.
- Instrument telemetry, alerting, and runbooks for the systems you own.
- Operate and tune our WAF: managed and custom rules, rate limiting, and bot mitigation.

### Requirements

- 5+ years of hands-on security engineering across cloud security and vulnerability management.
- Strong AWS security background: IAM, networking, container orchestration, and logging and audit.
- Hands-on experience securing CI/CD pipelines and Infrastructure as Code; Terraform required.
- Experience running or substantially contributing to a vulnerability management program.
- Working knowledge of OWASP Top 10 and threat modeling.
- Operates independently and drives projects without day-to-day oversight.

### Nice to Have

- Experience with our stack: Wiz, Cloudflare (WAF, Gateway, Zero Trust), GitHub Advanced Security, Spacelift, and AWS-native services.
- Hands-on WAF experience in production: writing and tuning rules, managing false positives, responding when something gets through.
- AI/ML security exposure: prompt injection, data poisoning, model abuse, and the controls that mitigate them.
- Secrets management platforms (AWS Secrets Manager, Keeper, Infisical).
- Identity security across human and non-human identities.
- PCI-regulated or financial services environment.
- Familiarity with Ruby on Rails, Python, or Go.

### The Ideal Candidate

The ideal candidate measures success by reduced risk, not tickets closed, and reaches for secure design and simplicity before another control. They think like an attacker but bring a developer mindset to their partnership with engineering, connecting the dots across cloud, identity, and pipeline rather than treating each as a separate domain. Engineers trust their technical judgment, and when something is blocked, they come with a proposed path forward.

#LI-LB2

The base annual salary range is listed below. This role is eligible for additional incentives, including an annual bonus.

Base Salary Range

$140,000—$165,000 USD

**Why Join Us?**

While you make a difference for others, we’ll work to make a difference for you, providing an uplifting, collaborative work environment and benefits that reflect your value to us. For eligible full-time employees, we offer:

- Considerable employer contributions for health, dental, and vision programs
- Generous PTO, paid holidays, and paid parental leave
- 401(k) matching program
- Merit advancement opportunities
- Career development & training

And finally, our team spirit and culture! We cultivate an environment of community, connection, and belonging across our entire organization.

_Beyond Finance does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job positions.  No fee will be paid to their parties who submit unsolicited candidates directly to Beyond Finance employees or the Beyond Finance HR team.  No placement fee will be paid to any third party unless such a request has been made by the Beyond HR team._

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级应用安全工程师

Beyond FinanceUnited States$140,000 - $165,000/年permanent2026-08-07
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

资深安全工程师

Beyond FinanceUnited States$160,000 - $195,000/年permanent2026-08-06
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

数据平台负责人工程师

Beyond FinanceUnited States$170,000 - $205,000/年permanent2026-07-28
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

双语客户服务中心代表

Beyond FinanceUnited Statespermanent2026-06-02
其他限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位