Seesaw is a trusted elementary learning experience platform loved by millions. The Security Engineer will help scale security foundations by embedding security practices into infrastructure and development workflows, focusing on automation and building technical guardrails for secure and efficient team operations.
Responsibilities:
- Build and maintain automated security controls across AWS, CI/CD, and application infrastructure
- Develop custom security tooling to automate manual processes
- Work closely with Engineering and external bug bounty participants to mitigate vulnerabilities in the Seesaw Learning platform
- Make improvements to the Seesaw Learning platform codebase to support secure-by-default development
- Improve our infrastructure by aiding in the development of our Infrastructure-As-Code configurations
- Partner with Engineering to integrate scanning, alerting, and compliance checks into daily development workflows to shift security left
- Improve observability and detection through enhanced logging, alerting, and vulnerability pipelines
- Transitioning all normal engineering workflows to Infrastructure-As-Code to minimize AWS Console usage
- Improving vulnerability management processes across the application and infrastructure
- Developing runbooks to document manual procedures and automating wherever possible
- Deploying automated code scanning in GitHub Actions
- Hardening AWS IAM roles and policies to enforce least privilege and support cross-environment isolation
- Implementing monitoring and compliance automation using Troposphere, AWS CloudFormation, and DataDog
Requirements:
- 3+ years of experience in DevOps, Cloud Engineering, or Security Engineering roles, ideally within a small or fast-growing company
- Backend web application development experience in Python or a similar language
- Deep familiarity with AWS core services (IAM, CloudTrail, CloudFormation, ECS, Lambda, S3, KMS)
- Familiarity with application security and platform security best practices including frameworks such as OWASP
- Experience building or maintaining infrastructure with infrastructure-as-code tooling (e.g. Troposphere, Terraform, CloudFormation, AWS CDK)
- Proficiency with CI/CD automation tools (GitHub Actions, GitLab CI, or similar)
- Strong time management and organizational skills; able to balance multiple priorities and projects effectively
- Collaborative mindset and comfort working across distributed teams and time zones