Job description
NovaSec Solutions is seeking a Senior Cybersecurity Engineer to join our security team in San Francisco. You will design, implement, and operate security controls across cloud and onâpremises environments to protect critical assets and data.
We value pragmatic security, collaboration, and continuous learning. This role offers the opportunity to influence security architecture, incident response, and risk management at scale in a fastâgrowing organization.
What you'll do is drive secureâbyâdefault practices, partner with product and platform teams, and help mature our security posture across the whole lifecycle from design to operation.
Location: San Francisco, CA / Hybrid. Competitive salary, strong benefits, and career growth.
Responsibility
- Design, implement, and operate security controls across cloud (AWS, Azure, GCP) and onâprem environments.
- Lead and respond to security incidents, conducting rootâcause analysis and driving remediation.
- Perform threat modeling, risk assessments, and security architecture reviews for new products and features.
- Develop and enforce secure coding guidelines; participate in code reviews and vulnerability remediation.
- Build, tune, and monitor SIEM (e.g., Splunk, Elastic) and EDR solutions to detect and prevent threats.
- Collaborate with DevOps and SRE teams to implement CI/CD security tooling and IaC security checks.
- Conduct regular penetration testing and vulnerability management activities; manage remediation timelines.
- Mentor junior engineers and promote security awareness across engineering teams.
Qualification
- Bachelor's or Masterâs degree in Computer Science, Cybersecurity, or a related field; or equivalent practical experience.
- 5+ years of handsâon cybersecurity engineering experience in modern architectures.
- Proven expertise in cloud security (IAM, network security, identity, encryption) and secure software development lifecycle.
- Strong knowledge of threat modeling, incident response, and digital forensics principles.
- Handsâon experience with SIEM, EDR, cloudânative security tools, and vulnerability management.
- Excellent communication skills and ability to work crossâfunctionally with product, platform, and risk teams.
- Industry certifications such as CISSP, CISM, or equivalently recognized credentials are a plus.
- Ability to thrive in a fastâpaced environment and manage multiple priorities with strong problemâsolving skills.