远程工作雷达

高级安全工程师

Senior Security Engineer

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Guidewire
薪资$133,000 - $199,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间今天
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

**职位描述**

Guidewire 正在寻找一位高级安全工程师,负责设计、构建、运营和改进跨 AWS 优先、多云环境的安全基础设施和云安全能力。

该职位的核心重点是 AWS 云基础设施和 CI/CD 供应链安全,同时与其他团队合作,应对新兴的安全领域——包括保护 AI 系统(LLMs、AI 代理和 Model Context Protocol 集成),并利用现代 AI 模型和技术来增强和自动化我们的安全能力。

该职位与基础设施和平台工程、站点可靠性工程和运维、产品和应用工程、数据和分析、安全以及其他技术和业务职能合作。工程师将把安全风险转化为可扩展的控制措施、自动化、默认安全模式、标准和操作流程。

该职位期望能够独立负责复杂的工作,解决模糊的安全问题,影响利益相关者,并指导其他工程师。

**职责:**

- 领导涉及多个团队、系统和依赖关系的复杂基础设施安全项目,主要关注 AWS 云环境和 CI/CD 流水线。

- 在 AWS 和适用的云平台上设计、实施和运营安全控制措施。

- 使用基础设施即代码、政策即代码、CI/CD 和自动化构建默认安全的解决方案。

- 通过云组织和账户结构、访问管理集成、策略执行、日志和监控、数据保护、配置管理、网络安全和账户生命周期管理等控制措施,提升云治理、安全态势和运营弹性。

- 定义并维护云账户、操作系统、容器、AMIs、Kubernetes、网络和支持基础设施的安全基线。

- 支持云账户的上线、下线、库存管理、配置漂移管理、异常处理和控制验证。

- 设计和改进云和基础设施网络安全性,包括网络分段、流量可见性、入站和出站控制、DNS、防火墙、路由、私有连接以及相关的监控和执行机制。

- 保护 CI/CD 和软件供应链,包括构建和部署工作流、依赖项、工件、容器、注册表、第三方动作、秘密等。

查看英文原文

**Summary**

Guidewire is seeking a Senior Security Engineer to design, build, operate, and improve secure infrastructure and cloud security capabilities across an AWS-first, multi-cloud environment.

The core focus of this role is AWS cloud infrastructure and CI/CD supply chain security, while also partnering across teams to address emerging security frontiers—including securing AI systems (LLMs, AI agents, and Model Context Protocol integrations) and leveraging modern AI models and technologies to enhance and automate our security capabilities.

This role partners with functions across infrastructure and platform engineering, site reliability engineering and operations, product and application engineering, data and analytics, security, and other technology and business functions. The engineer translates security risks into scalable controls, automation, secure-by-default patterns, standards, and operating processes.

The role is expected to independently own complex work, solve ambiguous security problems, influence stakeholders, and mentor other engineers.

**Job Description**

#### **Responsibilities:**

- Lead complex infrastructure security initiatives involving multiple teams, systems, and dependencies, with a primary focus on AWS cloud environments and CI/CD pipelines.

- Design, implement, and operate security controls across AWS and applicable cloud platforms.

- Build secure-by-default solutions using infrastructure as code, policy as code, CI/CD, and automation.

- Improve cloud governance, security posture, and operational resilience through controls for cloud organization and account structure, access management integration, policy enforcement, logging and monitoring, data protection, configuration management, network security, and account lifecycle management.

- Define and maintain security baselines for cloud accounts, operating systems, containers, AMIs, Kubernetes, networks, and supporting infrastructure.

- Support cloud account onboarding, offboarding, inventory, configuration drift management, exception handling, and control validation.

- Design and improve cloud and infrastructure network security, including network segmentation, traffic visibility, ingress and egress control, DNS, firewalls, routing, private connectivity, and related monitoring and enforcement mechanisms.

- Secure CI/CD and software supply chains, including build and deployment workflows, dependencies, artifacts, containers, registries, third-party actions, secrets, and runner environments.

- Support asset and identity governance for applications, infrastructure, containers, service accounts, workload identities, API keys, AI agents, and MCP tools.

- Participate in AI security initiatives involving next-generation AI models, agents, and tool integrations (including Model Context Protocol / MCP), driving threat modeling, prompt injection defenses, data egress protection, guardrails, human-in-the-loop controls, monitoring, and leveraging AI models to automate and enhance security operations.

- Apply risk-based security analysis using reachability, attack paths, asset criticality, exploitability, and business impact—not severity alone.

- Validate scanning-tool and AI-generated findings, establish ownership and remediation expectations, and improve finding quality feedback loops.

- Represent Security in architecture, change management, design review, and operational forums.

- Communicate risks, trade-offs, assumptions, dependencies, and business impact to technical and non-technical audiences.

- Create standards, runbooks, architecture decision records, dashboards, documentation, and enablement materials.

- Mentor engineers and help partner teams adopt secure patterns without requiring direct management responsibility.

- Participate in on-call rotations and incident response support for cloud and infrastructure security incidents.

- Monitor emerging threats and translate relevant developments into practical improvements to Guidewire’s security controls.

#### **Required Qualifications:**

- Typically 5+ years of experience in security engineering, cloud security, infrastructure security, DevSecOps, or equivalent practical experience.

- Hands-on experience designing and operating secure AWS environments is required. Experience with Google Cloud Platform (GCP) is strongly preferred; experience with other cloud platforms is a plus.

- Experience designing or operating cloud security capabilities, including cloud governance, access management integration, policy enforcement, logging and monitoring, data protection, network security, configuration management, and cloud account lifecycle controls.

- Hands-on experience authoring, reviewing, testing, and troubleshooting infrastructure-as-code using Terraform, CloudFormation, or comparable technologies to deploy and manage security controls.

- Hands-on experience building, securing, testing, and operating CI/CD pipelines, preferably using GitHub Actions or comparable platforms, including pipeline automation, secrets management, artifact handling, and runner security.

- Hands-on scripting or programming experience, using Python, Go, or another appropriate language, to automate security tasks, integrate controls, and troubleshoot security tooling.

- Practical knowledge of cloud and infrastructure networking, including segmentation, routing, DNS, firewalls, ingress and egress controls, private connectivity, and network telemetry.

- Experience securing containers and Kubernetes platforms, preferably EKS or an equivalent platform.

- Knowledge of threat modeling, secure design, vulnerability management, security testing, risk assessment, monitoring, and incident response.

- Ability to evaluate security-control effectiveness using evidence, operational feedback, exceptions, findings, and relevant metrics.

- Demonstrated experience building, operating, or contributing to security measurement and analysis capabilities, such as asset inventories, control-coverage reporting, configuration-drift analysis, attack-path analysis, or security data platforms.

- Working knowledge of identity and access-control concepts, including authentication, authorization, privileged access management, identity governance, zero-standing privilege, workload and non-human identities, and secrets management, with the ability to apply these concepts when evaluating, designing, implementing, or measuring controls across cloud, infrastructure, CI/CD, and operational workflows.

- Working knowledge of software supply-chain security concepts, including SBOMs, artifact signing, provenance, dependency management, secure registries, and CI/CD runner hardening, with the ability to evaluate, design, implement, or measure related controls and automation.

- Working knowledge of foundational AI security concepts (e.g., LLM risks, prompt safety) and an eagerness to apply AI capabilities to security automation.

- Ability to own complex work, manage ambiguity, make trade-offs, identify risks, and deliver outcomes across multiple teams.

- Strong written and verbal communication skills, including the ability to explain complex security concepts in business terms.

#### **Preferred Qualifications:**

- Hands-on experience or deep knowledge of AI-security risks and controls, including LLMs, AI agents, MCP, AI gateways, prompt injection defense, sensitive-data leakage, and applying advanced AI models/tools to improve security operations.

- Familiarity with NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, ISO/IEC 42001, or comparable frameworks.

- Relevant certifications such as AWS Security Specialty, CISSP, GIAC, or equivalent practical expertise.

The US base salary range for this full-time position is $133,000 - $199,000. Your base pay will depend on your experience, skills, education, training, and location among other factors. All full-time positions or part-time roles working 30 hours or more a week at Guidewire are eligible for benefits that support their health and well-being including health, dental, and vision insurance, paid time off, and a company sponsored retirement plan. In addition, some roles may be eligible for the annual company bonus plan, commissions, and/or long term incentive awards which are contingent on a variety of factors including, but not limited to, company and employee performance.

Disability Accommodations and Guidewire’s Appeals Process. Guidewire provides accommodations to the hiring process to create a fair opportunity for candidates with disabilities to contend for open positions. Accommodation requests should be directed to Accommodations@guidewire.com. If things do not go as hoped, we invite you to use our appeals process. Guidewire promises to independently review any denied accommodation and any decision not to offer you the position. The appeals process is the same in either case. Within five business days of receiving a notice of denial of an accommodation, or receiving a notice of your non-selection for a vacancy, e-mail Accommodations@guidewire.com to make an appeal. Guidewire will assign a new decision-maker to review the request and/or hiring decision, who will then notify you in writing of a decision within 10 business days.

**About Guidewire**

Guidewire is the platform P&C insurers trust to engage, innovate, and grow efficiently. We combine digital, core, analytics, and AI to deliver our platform as a cloud service. More than 540+ insurers in 40 countries, from new ventures to the largest and most complex in the world, run on Guidewire.

As a partner to our customers, we continually evolve to enable their success. We are proud of our unparalleled implementation track record with 1600+ successful projects, supported by the largest R&D team and partner ecosystem in the industry. Our Marketplace provides hundreds of applications that accelerate integration, localization, and innovation.

For more information, please visit www.guidewire.com and follow us on Twitter: @Guidewire_PandC.

Guidewire Software, Inc. is proud to be an equal opportunity and affirmative action employer. We are committed to an inclusive workplace, and believe that a diversity of perspectives, abilities, and cultures is a key to our success. Qualified applicants will receive consideration without regard to race, color, ancestry, religion, sex, national origin, citizenship, marital status, age, sexual orientation, gender identity, gender expression, veteran status, or disability. All offers are contingent upon passing a criminal history and other background checks where it's applicable to the position.

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级客户成功经理

GuidewireUnited States$136,000 - $221,000/年permanent今天
AI市场运营职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

AI工程师-应用AI

GuidewireUnited States$176,000 - $288,000/年permanent昨天
AI开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

全球实践副总裁 - 专业服务

GuidewireUnited States、Canada、Italy、Ireland、Spain、Gpermanent7 天前
AI职能支持限定地区(需当地身份)日间重叠约 2 小时,需偶尔早起或晚睡

技术项目管理,Guidewire 安全

GuidewireCanada120,000 - 150,000/年 CADpermanent11 天前
AI开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位