Jobs in United States

Senior Security Risk Management Framework Engineer in United States

1,941 active opportunities · Updated October 2026

Explore current senior security risk management framework engineer jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.

R
📍 New York City, NY, United States· Full-time
✓ High-confidence listingCompany trend -99.2%

From $10K/yr

Quick readStrong listing-quality and freshness signals

About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. About the Role You'll be the architect of our endpoint security posture across the full fleet — macOS, Windows, and BYOD mobile devices. You'll build secure-by-default controls with Terraform and GitOps, harden endpoints at scale, and automate the full device lifecycle so nothing depends on a human remembering to click the right button. You'll partner with IT, SecOps, and engineering teams to sharpen our telemetry and detections, mentor other engineers, and raise the bar on what "low-friction security" actually means. Everything you ship will be auditable, measurable, and built for the long run. We're also thinking seriously about how corporate security evolves in an agentic world — where AI agents act on behalf of employees and traditional identity and endpoint assumptions break down. You'll help us shape that answer. What You’ll Do Write and ship MDM policy as code — configuration profiles, remediation scripts, and enforcement rules across macOS, Windows, and mobile — with staged rollouts and rollback from day one Build patch automation that close

GitRestAIGo
P
📍 New York, New York, United States· Full-time
✓ Quality checkedCompany trend -72.3%

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. About the Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. The Security Contracts workstream is a core part of our Security Assurance and Trust Enablement program — ensuring Plaid's contractual security obligations with customers and data partners are defensible, consistent, and never a bottleneck to deal velocity, all while building trust. About the Role You will own Plaid’s Security Contracts workstream end-to-end—the DRI for how security contract reviews get done, how fast they move, and how the program improves over time. You will review security provisions in customer MSAs, DPAs, and security addenda, identify unacceptable clauses, and provide Legal and GTM with the actionable security feedback they n

AWSAIGoRust
G
📍 United Kingdom; Remote, United States· Full-time· Remote
✓ High-confidence listingCompany trend -100%

From $139.2K/yr

Quick readStrong listing-quality and freshness signals

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role You will engineer security improvements to the GitLab product as well as building and maintaining the tools we use to detect and prevent abuse on our SaaS platforms. A strong software engineering background with experience in large Ruby/Rails codebases is required. As a senior engineer on the Trust and Safety team, you will predictively identify abuse patterns and trends and build anomaly detection and prevention systems to mitigate abusive users and their activities. This role is an ideal fit for candidates with software engineering backgrounds interested in moving into security engineering. Formal

AWSGCPGitRest
C-
📍 New York, New York, United States· Full-time
✓ High-confidence listing

$145K – $170K/yr

Quick readStrong listing-quality and freshness signals

CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier—physically and digitally. With more than 43 million Members and a growing network of partners across the world, CLEAR's secure identity platform is transforming the way people live, work, and travel. Whether it’s at the airport, stadium, or throughout your everyday life, CLEAR unlocks the magic of frictionless experiences. CLEAR is seeking a Senior Security Operations Analyst III to join our SOC team to help strengthen our ability to detect, investigate, and respond to evolving security threats. In this role, you’ll lead complex investigations, improve CLEAR’s threat detection and response capabilities, and serve as a trusted security partner while helping develop the analysts and program around you. What you'll do: Lead complex investigations of security events across corporate networks, endpoints, data centers, cloud environments, and other critical systems, driving incidents from initial analysis through escalation and remediation Develop, tune, and optimize threat detection logic across SIEM, EDR, and other security platforms, proactively identifying coverage gaps, reducing false positives, and improving the fidelity of security alerts Partner with Engineering, Infrastructure, and other teams to investigate threats, identify root causes, communicate risk, and drive timely remediation and improvements to CLEAR’s security posture Apply threat intelligence, data, automation, and AI-enabled tools to identify emerging attack patterns, accelerate investigations, improve detection workflows, and strengthen decision-making while applying sound security judgment Serve as a subject matter expert and escalation point for other analysts, mentoring junior team members, sharing knowledge, and helping establish scalable processes, playbooks, and standards for threat detection and analysis Continuously evaluate CLEAR’s detection coverage against the evolving t

GitRestAIGo
R
📍 San Mateo, CA, United States· Full-time
✓ High-confidence listingCompany trend -100%

From $269.2K/yr

Quick readStrong listing-quality and freshness signals

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. The Security organization at Roblox is responsible for designing and engineering secure systems from inception through production. We define security standards, build scalable controls, and enable product and infrastructure teams to operate securely by default. The Application Security team partners closely with engineering teams early in the development lifecycle to drive secure architectures, establish standards, and deliver scalable security solutions. As a Senior Security Software Engineer - Application Security , you will be a hands-on engineer who designs, builds, and ships security solutions that integrate directly into developer workflows and platforms. You will play a key role in scaling application security through automation, CI/CD integrations, secure libraries, and reusable patterns. In this role, you will help define how security is embedded across the software development lifecycle at Roblox, balancing deep technical work (threat modeling, code review, penetration testing) with systemic solutions that reduce risk at scale. You will also participate in AppSec on-call rotations and contribute to security tooling and platform evolution. You will: Integrate security into CI/CD pi

JavaScriptPythonJavaAWS
R
📍 San Mateo, CA, United States· Full-time
✓ High-confidence listingCompany trend -100%

From $233.6K/yr

Quick readStrong listing-quality and freshness signals

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Security Software Engineer for Infrastructure Security you will be a part of the Information Security organization and report to the Senior Manager of Infrastructure Security. You will help shape the future of Platform Security at Roblox. We work closely with Production IAM, Network Security, and Cloud Security at Roblox. You Will: Identify security gaps and threats in our cloud and on premise infrastructure, partnering with Governance Risk and Compliance teams to create standards and policies along the way. This will help Roblox meet regulatory and compliance requirements. Harden our infrastructure by introducing secure by default configurations, designs and guardrails for all developers at Roblox. Own and drive solutions that enable Roblox engineers to design, build, and use infrastructure securely at scale. Work closely with other InfoSec teams (AppSec, D&R, GRC, CorpSec, CloudSec, NetSec) and partner with engineering teams across Roblox, specifically the Infrastructure organization, to ensure the secure outcomes of security and product driven initiatives. You Have: 5+ years of experience writing code and/or relevant technical experience. Experience with

AWSKubernetesGitLinux
H
📍 Louisville, United States
✓ High-confidence listingCompany trend +310%
Quick readStrong listing-quality and freshness signals

Become a part of our caring community *(Selected candidate will be required to live within 60 mins of one of the following metro locations OR be willing to relocate to within 12 months of hire date: Louisville KY, NYC Metro, Dallas Metro, Charlotte NC Metro, Tampa, Miami, Washington DC metro, Chicago, Boston, Atlanta, Nashville) The Senior Security Architect for AI works with EIP Department leaders and Humana enterprise stakeholders to identify, define, and develop security architecture requirements and secure designs for AI technology solutions across Humana's business, information technology, and security domains. The Security Architect leads the development of technical architecture & designs, develop security requirements, perform threat modeling and ensures alignment of security & risk imperatives with business priorities. The Security Architect is responsible for the high-level design and patterns of security program infrastructures to enable the protection of Humana tools, data, systems, and networks. Working with EIP Leaders, the security architect drives alignment between the EIP security strategy, security architecture and infrastructure, and Humana's overall business and technology strategic priorities. In this capacity, the role is responsible for planning, designing, and proposing architectural patterns or security enhancements for Humana's information security and technology infrastructures. The role works with EIP and Humana leaders to review and reconcile Humana business priorities with EIP security requirements. The role engages with relevant EIP stakeholders to identify current and emerging security threats and works to design security architecture elements to mitigate threats as they emerge. Additionally, the role actively works to identify gaps within existing EIP reference architecture and designs updates to impacted sec

Artificial IntelligenceAIRecruitment
V
📍 United States· Full-time· Remote
✓ High-confidence listingCompany trend -90%
Quick readStrong listing-quality and freshness signals

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Our Software Engineers deliver high-value products for our customers, and infrastructure that enables our business to scale. Vanta’s team and technology surface are growing quickly, and it’s essential that we invest in the right abstractions and systems to enable us to scale with our business. As a Software Engineer, you’ll be responsible for setting technical direction to enable our product and infrastructure to scale with our business, and driving complex projects across our technical stack.. Your past experience will be leveraged to enable and accelerate Vanta’s growth. Our Senior Software Engineers lead and mentor engineers, delivering high-value products for our customers and infrastructure that enables our business to scale. Our product integrates deeply with the services that present security risk to a company, pulls and analyzes data from those sources, and surfaces potential security threats to our customers in real time with guidance to remediate them. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. As a Software Engineer on the Expansion Team, you’ll play a central role in shaping Vanta’s self-serve and product-led growth motion. Instead of working horizontally across compliance workflows, this team focuses on the full post-activation lifecycle—driving retention, expansion, and revenue automation across the product. You’ll build the core systems that power Vanta’s purchasi

TypeScriptReactNode.jsRest
O
📍 San Francisco, California, United States· Full-time· Remote
✓ Quality checkedCompany trend -82%

About the Team The Industry Marketing team helps OpenAI bring frontier AI to the industries where it can create meaningful, measurable impact. We work across Product, GTM, Communications, Partnerships, Policy, Security, and Research to translate model and product capabilities into industry narratives, field motions, customer proof, and launch programs that help enterprises adopt AI responsibly. About the Role As Product Marketing Manager, Cybersecurity, you will help define how OpenAI brings frontier AI to cyber defenders. This role sits at the center of Daybreak, OpenAI’s cybersecurity initiative to help defenders see risk earlier, act sooner, and build software that is resilient by design. You will shape the market narrative, build the field-facing operating system, and coordinate cross-functional execution across product launches, customer proof, partner moments, events, and account-based campaigns. You will help senior security leaders understand how OpenAI models, Trusted Access for Cyber, Codex Security, and related workflows can support real defensive work. We’re looking for a product marketer who combines strategic narrative, technical curiosity, enterprise go-to-market judgment, and program leadership. The right person can turn fast-moving capabilities into clear positioning, credible assets, and practical field execution. In this role, you will: Own positioning and messaging for OpenAI’s cybersecurity offering, including Daybreak, Trusted Access for Cyber, Codex Security, and related product surfaces. Build field-ready assets for account directors, solutions engineers, security leaders, and executive audiences, including first-call decks, one-pagers, use-case libraries, customer stories, and proof-point packages. Translate frontier model capabilities into simple, accurate, and defensible go-to-market language for senior enterprise buyers and security practitioners. Partner with Product, Research, Security, Policy, Communications, Partnerships, and GTM to c

Artificial IntelligenceAIProcurement
M
📍 New York City, New York, United States
✓ High-confidence listingCompany trend +212.5%
Quick readStrong listing-quality and freshness signals

Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Senior Physical Security Analyst Overview • Physical security and compliance security officer, maintains and monitors physical security policies, standards, and best practices • Abides by Security guidelines relative to security standards to provide safety and security of staff and assets • Manages Security Control Center Coordinators and security operations. • Manages and administers physical security functions for company facilities to ensure the safety; security and protection of MasterCard employees and asset • Recognizes potential and realized security threats and takes reasonable action to mitigate risk or injuries to personnel and or property • Provides MasterCard Corporate Security Standard Operating Guidelines security supervisors and follows-up to ensure adherence • Manages Security officers by delegating department projects, tasks and assignments • Manages Security staff schedules to ensure proper coverage at all times Role • Interaction with employees and guests, provide direction on security policy and visitor directions as needed • Operational use of security systems • Trains and supervises Security officers with respect to the execution of established physical security policies, programs and procedures • Recommends the development and implementation of physical securi

RecruitmentCustomer Service
C-
📍 New York, New York, United States· Full-time
✓ High-confidence listing

From $225K/yr

Quick readStrong listing-quality and freshness signals

CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier—physically and digitally. With more than 43 million Members and a growing network of partners across the world, CLEAR's secure identity platform is transforming the way people live, work, and travel. Whether it’s at the airport, stadium, or throughout your everyday life, CLEAR unlocks the magic of frictionless experiences. We are seeking a Senior Product Security Engineer to serve as a technical leader and strategic contributor within our Product Security team. This role goes beyond execution — you will drive the evolution of CLEAR’s application security posture by influencing architecture, shaping security engineering processes, and mentoring team members in security and engineering. You’ll lead security initiatives across the organization and help embed security into every stage of our software development lifecycle. What you'll do: Drive security strategy and implementation across all CLEAR products and engineering teams, ensuring consistent protection of customer and business-critical assets. Partner with engineering leadership to align application security initiatives with company-wide technology and product roadmaps, balancing innovation with risk mitigation. Provide technical leadership across CLEAR’s application security initiatives, guiding architecture, design, and development to meet high security standards. Serve as a trusted advisor to cross-functional teams — including Engineering, DevOps, Product, GRC, and IT — enabling secure-by-design practices across the organization. Design and drive implementation of scalable automated security controls and testing frameworks integrated into CLEAR’s CI/CD pipelines. Lead complex threat modeling, architecture reviews, and risk assessments across high-value systems and platforms, driving meaningful security outcomes. Engage with CLEAR's customers to provide insight and support their fraud and ident

JavaScriptPythonJavaCI/CD
P
📍 San Francisco, California, United States· Full-time
✓ High-confidence listingCompany trend -100%
Quick readStrong listing-quality and freshness signals

Who Are We? Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. The Opportunity The Security GRC team is responsible for the overall security posture of Postman by ensuring compliance with applicable regulations and contractual obligations and maintaining effective and efficient governance, risk, and compliance programs. In addition, the Security GRC team is directly involved with supporting and enabling Sales and driving security and compliance initiatives to further the growth of Postman. We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role focused on designing and operating GRC tooling, integrations, and AI-assisted workflows that reduce manual effort while improving security assurance. The ideal candidate has experience implementing and maturing compliance programs, including SOC 2, ISO 27001, HIPAA, GDPR, CCPA, and FedRAMP, and can translate security and risk requirements into practical engineering solutions. As a senior member of the Security GRC team, you will partner with Security, Engineering, IT, Legal, Sales, and other stakeholders to

JavaScriptPythonJavaAI
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -82%

About the role We’re looking for an engineering manager to lead a team building software systems that detect and prevent harmful misuse of frontier AI models—before incidents occur. This is a builder’s role: you’ll lead engineers shipping production services, detection pipelines, and mitigation mechanisms that protect frontier model integrity and reduce high-severity misuse risk. While this work intersects with frontier model development, security and risk, we’re explicitly seeking someone with a software engineering foundation who is comfortable building reliable systems that can operate at billions of users scale. In this role you will: Lead a team of software engineers building detection + mitigation systems for frontier model misuse, with an emphasis on model IP protection / distillation detection and emerging risk surfaces from autonomous agents. Set the technical roadmap and execution strategy: prioritize, design, ship, iterate, measure impact. Build production systems: services, pipelines, tooling, instrumentation, and automation that scale with frontier model usage. Partner deeply with Research and Product to translate evolving model capabilities into concrete tests, signals, and mitigations that can be deployed at scale. Drive strong engineering fundamentals: architecture, reliability, monitoring, performance, and operational excellence. Hire and grow an exceptional team across backend, data systems, and applied ML engineering domains as needed. Anticipate what breaks at scale as agentic workflows become more capable. You might thrive in this role if you: Experience building systems in adversarial, fast-evolving environments Are comfortable with ambiguity and novelty Have experience adjacent to security (e.g., abuse prevention, fraud, integrity, platform defense, auth/identity, malware/spam, adversarial environments) Communicate clearly and build trust quickly with senior stakeholders—pragmatic, collaborative, and calm under scrutiny. Significant experience

AWSRestAIRust
S
📍 Bellevue, Washington, United States· Full-time· Remote
✓ High-confidence listingCompany trend -92.9%
Quick readStrong listing-quality and freshness signals

At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Senior Software Engineer for our Anti-Abuse team within Security Foundations. This team is responsible for protecting Snowflake and our customers from abuse on the Snowflake platform — building foundational security primitives across a complex multi-cloud environment to combat fraud, account takeovers, data exfiltration, and AI security threats at the scale of Snowflake’s hyper-growth. AS A SENIOR SOFTWARE ENGINEER, SECURITY FOUNDATIONS AT SNOWFLAKE, YOU WILL: Design, build, and scale security-by-default capabilities that protect Snowflake products across a complex multi-cloud environment Develop intelligent security platforms and services that leverage AI/ML and risk scoring to identify, prioritize, and respond to security threats and policy violations Build real-time detection and prevention systems to defend against account compromise, AI abuse, and data exfiltration through adaptive enforcement and granular policy controls Create security intelligence and monitoring capabilities that detect suspicious account & user activity, generate actionable insights, and enable timely response Partner across Security, Engineering, and Product teams to define security strategy, influence product design, and drive adoption of secure engineering practices Raise the

JavaScriptPythonJavaSQL
G
📍 United States· Full-time· Remote
✓ Quality checkedCompany trend -100%

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Senior Product Manager , you will own GitLab's Secret Detection offering and the Vulnerability Research function that produces the detection content across security products. Secret Detection is one of the highest-signal, highest-volume security capabilities on the platform. Leaked credentials are the most common initial access vector in real breaches, and as AI agents write, commit, and configure more of the software, the surface area for exposed secrets grows faster than the number of humans watching it. You will own the full loop: detect a secret with high precision, tell the customer whether it i

GitRestAIGo
🔔

Get new senior security risk management framework engineer jobs in United States by email

Daily job updates · Unsubscribe anytime