At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Senior Security Engineer at Vanta, you’ll own projects with impact across the business to help us run an efficient and highly effective security team. The security team at Vanta ensures that we are a trustworthy steward of sensitive data. We also contribute subject matter expertise to the product, sales, marketing, support, and engineering functions, given the nature of our business. You’ll join Vanta’s Security organization, which provides essential security operational services, is directly involved in the software development process and building tools to make it easy for developers to ship products securely, sets policies and standards regarding enterprise-wide security requirements, and offers advisory services to enable our business to thrive while effectively managing risk. If you’re someone who has high initiative and enjoys problem solving while having impact at a high-growth company, we would love to hear from you! What you’ll do as a Senior Security Engineer at Vanta: Participate in team exercises to identify potential security risks, including threat modeling and tabletop scenarios Contribute to complex prioritization discussions around which risks are the most important to solve next Plan projects to address the risks we prioritize, and coordinate with cross-functional stakeholders across the company to execute those projects Build maintainable programs to implement operational excellence where ongoing work is needed to achieve our goals (e.g. vulnerability management) Partner with engineering teams to architect secure software, address security concerns, and build a strong security culture Build, customize, a
Jobs in United States
Security Incident Response Engineer in United States
1,152 active opportunities · Updated October 2026
Showing
15 jobs
Explore current security incident response engineer jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.
From $10K/yr
About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. About the Role You'll be the architect of our endpoint security posture across the full fleet — macOS, Windows, and BYOD mobile devices. You'll build secure-by-default controls with Terraform and GitOps, harden endpoints at scale, and automate the full device lifecycle so nothing depends on a human remembering to click the right button. You'll partner with IT, SecOps, and engineering teams to sharpen our telemetry and detections, mentor other engineers, and raise the bar on what "low-friction security" actually means. Everything you ship will be auditable, measurable, and built for the long run. We're also thinking seriously about how corporate security evolves in an agentic world — where AI agents act on behalf of employees and traditional identity and endpoint assumptions break down. You'll help us shape that answer. What You’ll Do Write and ship MDM policy as code — configuration profiles, remediation scripts, and enforcement rules across macOS, Windows, and mobile — with staged rollouts and rollback from day one Build patch automation that close
From $10K/yr
About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. About the Role The Product Security team helps make Ramp the most secure place for our customers to collect, manage, and put to work their business’ financial information. Our work centers in three areas: Ramp builds products with an eye for security Ramp detects and responds to threats before they cause harm Security powers Ramp’s growth Check out our Engineering Blog for more on our tech stack, mission and values! What You’ll Do Build security-focused application primitives and integrate them into our existing products Design and deploy platform-level mitigations to common security issues Lead remediation of prioritized issues across our technology stack: collaborating with other engineers to triage and fix vulnerabilities discovered internally, through penetration testing, and through our bug bounty program Partner with engineering teams to design and deploy solutions which are inherently secure Champion the use of tooling (linters, static analysis, posture assessment scanners, query inspectors, etc.) which help Ramp engineers build secure system
From $10K/yr
About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. About the Role The Security Engineering team helps make Ramp the most secure place for our customers to collect, manage, and put to work their business’ financial information Our work centers in three areas: Ramp builds products with an eye for security Ramp detects and responds to threats before they cause harm Security powers Ramp’s growth Check out our Engineering Blog for more on our tech stack, mission and values! What You’ll Do Drive our cloud security roadmap: review our cloud deployments to identify opportunities for improvement Design and build security-focused infrastructure primitives and integrate them into our existing products and development processes Lead remediation of prioritized issues across our technology stack Partner with infrastructure, data, and devops teams to design and deploy solutions that are inherently secure What You Need Minimum 5 years of experience building software Minimum 3 years of experience building in AWS (with Terraform) A strong sense of ownership: you need to drive projects from inception to scaling it in
From $10K/yr
About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. As Ramp’s founding Privacy engineer, you will build a privacy program that powers Ramp’s growth while earning trust from customers and prospects. What You’ll Do Build privacy-focused application primitives and integrate them into our existing products Partner with other engineering teams to design and deploy solutions which are inherently privacy-centric and secure Improve, implement, and deploy data retention and anonymization strategies across our environment Track shifting legal standards (alongside with Ramp’s Privacy Counsel) and update Ramp systems and processes to match What You Need Minimum of 4 years of experience building software Minimum of 2 years of experienced focused on platform, privacy, and/or security Desire to work in a fast-paced environment, continuously grow, and master your craft Ability to turn business and product ideas into engineering solutions Nice-to-Haves Working knowledge of data-protection legal requirements Experience with Python (Flask), React, and AWS (ECS, as well as other core services) Benefits available to all
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. We are looking for a Security Operations Lead (SOC Lead) to build, mature, and operate our 24/7 detection and response capabilities across a modern cloud-native and AI-driven environment. This role leads the global SOC function—monitoring, SIEM ownership, detection engineering, alert triage, and operational readiness—while also evaluating and integrating emerging AI-based SOC products and autonomous response platforms . You will oversee monitoring across multi-cloud environments (GCP primary, AWS/Azure secondary), Kubernetes, SaaS services, endpoints, developer tools, and AI workloads . You’ll collaborate closely with Cloud Security, Compliance/GRC, SRE, Platform Engineering, IT/Endpoint teams, and AI Infrastructure to ensure our detection strategy scales and stays ahead of evolving threats. This is a hands-on leadership role perfect for someone who wants to shape the SOC of the future while solving complex challenges in a high-scale AI setting. What You’ll Do SOC Leadership & 24/7 Monitoring Lead, mentor, and scale a global SOC team responsible for 24/7 monitoring, alert intake, triage, correlation, and escalation. Build operational rigor: processes, runbooks, SLAs, metrics, and quality standards for high-scale environments. Cover monitoring across: Cloud infrastructure (GCP, AWS, Azure) Kubernetes/GKE/EKS/AKS clusters SaaS platforms (Google Workspace, GitHub, Slack, Okta, etc.) Endpoints (macOS, Linux, Windows) including EDR/XDR telemetry Developer platforms + CI/CD pipelines AI/ML systems and model-serving workflows AI-Based SOC Integration & Innovation Evaluate, adopt, and integrate AI-native SOC technologies for triaging, detection, and correlation Identify opportunities to automate triage, investigations,
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We own Plaid’s security compliance frameworks, run our audits and risk programs, and partner across the company to keep Plaid’s platform secure, resilient, and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability. The Role: You will own GRC Engineering at Plaid — a foundational, high-ownership role defining an emerging discipline from the ground up. Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field. You will: Define the discipline and the architecture — how GRC Engineering works at Plaid, not just execute with
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions. Role: You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions. You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors. You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register. You
From $139.2K/yr
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role You will engineer security improvements to the GitLab product as well as building and maintaining the tools we use to detect and prevent abuse on our SaaS platforms. A strong software engineering background with experience in large Ruby/Rails codebases is required. As a senior engineer on the Trust and Safety team, you will predictively identify abuse patterns and trends and build anomaly detection and prevention systems to mitigate abusive users and their activities. This role is an ideal fit for candidates with software engineering backgrounds interested in moving into security engineering. Formal
From $42K/yr
Security at most companies is reactive. A checkbox for auditors. A speed bump for engineers. A department that says no. That's not what we're building. The Company Sendbird is the #1 CPaaS platform for in-app communications — an enterprise-grade infrastructure company that gives businesses the APIs and SDKs to embed real-time chat, voice, and video directly into their own products. Over 4,000 brands trust us. Seven billion messages flow through our platform every month. 300 million monthly active users. We powered conversations for DoorDash, Match Group, Noom, Yahoo Sports, Rakuten, and thousands more. We were good at what we did. Really good. So we asked what comes next. With decades of leadership in communications infrastructure, the answer was clear: AI. In February 2025, we launched our AI agent for enterprise CX. Later that year, we introduced Delight.ai — and the name says everything about what we believe. AI's real promise isn't efficiency. It isn't cost savings. It's restoring what customer experience lost somewhere along the way: the feeling of being understood, of being genuinely cared for. We don't want customers to feel satisfied. We want them to feel delighted. The Product Delight.ai is the AI concierge for customer experience. Most AI agents forget you the moment the conversation ends. Ours doesn't. Delight.ai builds memory over time, learns preferences, and connects context across every channel—chat, SMS, email, voice, WhatsApp—without losing the thread. We're building AI that makes customers feel understood, seen, and remembered. Why Head of IT & Security We're an AI company handling enterprise-grade conversations at global scale, and our customers trust us with data that matters. That trust isn't a nice-to-have. It's a competitive differentiator. It's why DoorDash and Match Group chose us. It's why we've earned certifications that our competitors are still chasing. Security here means being a partner to the business, not a blocker. It mea
From $195K/yr
Here at Datadog, we think about offensive security a little bit differently. We embrace automation and AI to run adversary simulations continuously across a massive cloud-native environment, and we expect our offensive engineers to build the tooling that makes that possible. We're looking for a Senior Security Engineer who can execute sophisticated red team operations, write the code that scales them, and take an AI-first approach to offensive security engineering. At Datadog, we place value in our office culture - the relationships and collaboration it builds, and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You'll Do: Plan and execute red team engagements end-to-end, simulating real-world threat actors across cloud infrastructure (AWS, GCP), Kubernetes, CI/CD pipelines, and corporate environments Build and maintain custom offensive tooling, automation frameworks, and engagement infrastructure, treating offensive operations as a software engineering problem Develop custom payloads and evasion capabilities tailored to Datadog's environment and modern defensive controls (EDR, SIEM, network monitoring) Improve the efficiency of offensive operations through thoughtful use of automation and AI, accelerating reconnaissance, vulnerability analysis, and reporting workflows Partner with the Detection & Response team on purple team exercises to validate detection logic, improve alert fidelity, and influence threat models Translate offensive findings into concrete improvements by working directly with defensive security and engineering teams to close gaps Who You Are: You have 5+ years of hands-on experience in offensive security (red teaming, penetration testing, or adversary simulation) with a track record of operating against mature, well-defended environments You write production-quality code (Python, Go, or similar), can build your own tools, and automate your w
From $187K/yr
As a Cloud Security Engineer you will partner with different stakeholders across the organization to secure our cloud infrastructure. As part of the Platform Security organization we secure the building blocks of Datadog’s applications and infrastructure. We do this by building solutions to solve systemic risks and combine an approach of making the secure path easier and the insecure path harder to secure and accelerate the business. We regularly partner with the most bleeding edge internal products and are working to solve and build solutions to enable our safe usage of AI. We also develop AI based solutions to enable security at scale. We are looking for a Service Mesh and Kubernetes focused security specialist to help round out an incredibly strong infrastructure security focused group. You will rotate through a variety of internal projects and gain deep exposure to Datadog’s infrastructure. At Datadog, we place value in our office culture - the relationships that it builds, the creativity it brings to the table, and the collaboration of being together. We operate as a hybrid workplace to ensure our employees can create a work-life harmony that best fits them. What You’ll Do: Solve our most challenging cloud infrastructure security problems starting with our core building blocks and golden paths. Enable our engineers to build and ship secure solutions quickly. Build and extend Datadog’s Platform Security solutions. Leverage and influence the direction of Datadog’s products to secure our infrastructure, and provide internal feedback that enables our teams to improve the products for ourselves and our customers. Who You Are: You have a BS/MS/PhD in a Computer Science, Engineering or related scientific field or equivalent professional experience. Passionate about advocating for and implementing solutions to complex problems, at-scale, in a large multi-cloud environment. You don’t want to just provide security recommendations, you want to help imple
From $151K/yr
MongoDB’s Security Product Management team is seeking a Staff Product Manager to own security, compliance, and public sector product strategy within Atlas for Government (A4G). In this role, you will be a key member of the security product management team, helping make data security a market differentiator that enables MongoDB to win in enterprise and regulated industries. You will lead product strategy and execution for capabilities and programs that support federal compliance requirements and broader regulated-industry needs. You will work across Engineering, Compliance, Legal, Security, and Go-to-Market teams to translate complex regulatory and customer requirements into clear product investments, roadmaps, and outcomes. This role is suited for a candidate who can orchestrate multiple interlinked product areas, own cross-team product and architectural trade-offs, and align senior stakeholders around multi-year bets. You will be expected to identify opportunities and dependencies that cut across team boundaries, bring clarity to ambiguous problem spaces, and establish reusable ways of working that help MongoDB deliver secure, compliant platform capabilities for public sector and other regulated markets. You will partner closely with senior engineering and business leaders to evaluate trade-offs, sequence investments, and bring clarity to decisions that balance customer impact, execution risk, and long-term business value. This role can be based out of of our offices or remotely in the United States. The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. Our FedRAMP program requires that anyone who is accessing customer data or metadata inside the Authorization Boundary be a US Person on US Soil. Responsibilities Security and Compliance Product Strategy Own the public sector compliance roadm
From $151K/yr
The Role MongoDB is seeking a Staff Product Manager to lead strategic initiatives across Identity and Security. In this role, you will serve as the senior product leader shaping the next generation of authentication, authorization, and access control across MongoDB Atlas, the core database engine, and emerging developer platforms. You will lead the strategy for non-human identity—spanning workload identity federation, zero-trust passwordless access, Model Context Protocol (MCP) integrations, and autonomous AI agentic identity. You will partner closely with engineering, UX, product marketing, and enterprise customers to build identity experiences that are enterprise-grade, seamless for developers, and secure by default. Responsibilities Set and champion a multi-year product strategy across interrelated identity areas, aligning dependencies and investments to MongoDB’s broader objectives Identify cross-cutting customer and market opportunities, build business cases for investment, and bring a clear point of view to senior stakeholders Lead workload identity federation and programmatic access initiatives across cloud and enterprise identity environments Define secure authorization approaches for AI agents and MCP clients, including delegation, identity lifecycle, policy, and administrative controls Drive developer-first access management, ensuring security controls enhance rather than obstruct developer velocity Partner with engineering, design, GTM, and cross-functional leadership to validate enterprise requirements, prioritize initiatives, and measure feature adoption Stay ahead of evolving cloud security paradigms, emerging standards (e.g., SPIFFE/SPIRE, O4AA), and AI access patterns to guide executive decision-making Represent MongoDB’s security and identity vision at industry events, customer advisory boards, and executive briefings Demonstrate creativity, an innovative spirit, and a bias towards action Requirements 8+ years (or equivalent experience) in Pro
About Pinterest: Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product. Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work. Creating a career you love? It’s Possible. At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we’re looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities, we’ll explore your foundational skills and how you collaborate with AI. Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here . Pinterest’s Security team is seeking an experienced Security Software Engineer to help keep our 619 million monthly active users safe from real-world threats. You will build tooling, product enhancements, and work with teams to improve our overall security posture and enhance our secure development lifecycle. We are looking for a candidate with a passion for security and innovation, who will research and develop new solutions to secure our products. What you'll do: Design and build out our rules, processes, and platform for our secure development lifecycle. Deliver and review code that is well-documented, tested, and operable. Work cross function to architect scalable and secure solutions to a variety of Pinterest’s problems. Conduct regular security assessments including design reviews. Help rework our existing controls to address increased pro
Other cities to consider
More places hiring for this role
Get new security incident response engineer jobs in United States by email
Daily job updates · Unsubscribe anytime