Seesaw Learning is a trusted platform used by millions of educators and families worldwide, focused on delivering joyful learning experiences for elementary students. They are seeking a Senior Security Engineer to lead their security strategy, engage in hands-on engineering, and ensure security is integrated across all aspects of the organization.
Responsibilities:
- Own and drive the company’s security strategy, roadmap, and overall posture
- Serve as the internal expert on security best practices and risk management
- Partner cross-functionally to ensure security is embedded across engineering, product, IT, and legal
- Lead threat modeling, secure code reviews, and architecture reviews
- Define and enforce secure coding standards and vulnerability management processes
- Drive adoption of SAST, DAST, SCA, and other security tooling
- Build and maintain security tooling, automation, and infrastructure as code
- Implement security controls across application, API, and infrastructure layers
- Partner with engineers on authentication, authorization, and data protection
- Own vulnerability scanning, patching, and incident response processes
- Strengthen cloud security (IAM, networking, secrets, logging, monitoring)
- Integrate security into CI/CD pipelines and automate security gates
- Partner with Legal to develop and maintain security policies and standards
- Lead or support compliance efforts (e.g., SOC 2, ISO 27001)
- Stay ahead of evolving regulatory requirements
Requirements:
- 7+ years of hands-on software engineering experience
- Strong experience in application security (threat modeling, code review, SDLC integration)
- Experience securing cloud environments (AWS, GCP, or Azure), including IAM and networking
- Ability to operate both strategically and tactically—setting direction while staying hands-on
- Strong communication skills; able to translate security concepts into clear, actionable guidance
- Experience with compliance frameworks (SOC 2, ISO 27001)
- Familiarity with security tooling (SAST, DAST, SCA, SIEM, vulnerability management)
- Experience building security programs in startup or high-growth environments
- Relevant certifications (CISSP, CCSP, CSSLP, OSCP), though not required