Vanilla is seeking a Senior Security Engineer to enhance its security posture across infrastructure, product, and operations.
The role involves collaboration with engineering, legal, and compliance teams to ensure systems meet high standards, particularly SOC 2 frameworks.
The engineer will proactively identify vulnerabilities, improve internal security processes, and assist with customer-facing security discussions.
This position is remote, but candidates must reside in specific states including CA, CO, CT, DE, FL, GA, ID, IL, IN, KY, MA, MD, ME, MN, NC, NH, NJ, NY, OH, OK, PA, RI, SC, SD, TX, UT, VA, WA, and WA D.C.
Requirements:
Candidates must have 12+ years of experience in software engineering, infrastructure, or technical operations, with a strong foundation in system design and development.
A minimum of 8 years of hands-on experience in a security engineering role focused on application, infrastructure, or cloud security in a modern tech environment (SaaS or fintech preferred) is required.
A deep understanding of securing Web Applications, APIs, and SaaS platforms, including authentication, access control, and data protection is essential.
Strong familiarity with cloud security, particularly in AWS, including tools like GuardDuty, WAF, IAM, and security best practices is necessary.
Proficiency in Infrastructure-as-Code and modern deployment workflows (Terraform, Helm, GitOps) is required.
Experience with container orchestration and security (Kubernetes, EKS) is needed.
Demonstrated experience with security assessments, including threat modeling, secure code review, vulnerability detection, and remediation is expected.
Candidates should have experience working within compliance frameworks (e.g., SOC 2, ISO 27001) and collaborating with legal, compliance, and engineering teams.
Clear and effective communication skills are required to explain technical security concepts to both technical and non-technical audiences.
A BS in Computer Science, Security, or equivalent professional experience is necessary.
Candidates must be legally authorized to work in the United States without the need for sponsorship now or in the future.
Benefits:
The position offers a flexible paid time off policy along with 10 company-wide paid holidays.
Parental leave is provided, with 4 weeks for all full-time employees and up to 12 weeks for birthing parents.
Medical, dental, and vision benefits coverage is available for employees and their families.
Employees become eligible for 401K after one month of employment.
Free estate planning documents are provided to employees.
There is a budget for learning & development and home office setup.
Paid parking or transit is available for hybrid and in-office employees.