LearningSpring.com is seeking a Senior Security Engineer to design, implement, and continuously improve the security foundation of their platform. This role involves establishing security strategies, developing cloud security standards, and ensuring security practices are integrated throughout the software development lifecycle.
Responsibilities:
- Define and implement LearningSpring's cloud security strategy across AWS infrastructure, in vendor integrations, and as a security subject matter expert for application development efforts
- Partner with Platform Engineering to build secure-by-default infrastructure using Terraform and Infrastructure as Code best practices
- Design and implement security controls across cloud infrastructure, networking, identity, secrets management, and application environments
- Integrate security throughout the software development lifecycle, including CI/CD pipelines, automated testing, dependency management, and release processes
- Lead technical efforts supporting SOC 2 certification and contribute to PCI compliance initiatives
- Conduct threat modeling and architecture reviews for new systems and major product initiatives
- Establish vulnerability management processes, including automated scanning, prioritization, remediation, and verification
- Evaluate, recommend, and implement security tools that align with the company's technology stack and risk profile
- Develop security standards, engineering guidelines, and reference architectures that enable teams to build securely
- Improve security observability through logging, monitoring, alerting, and incident response capabilities
- Partner closely with engineering teams to identify risks early and develop practical solutions that balance security with delivery velocity
- Stay informed on emerging threats and continuously improve LearningSpring's security posture through automation and engineering best practices
Requirements:
- 5+ years of experience in Security Engineering, Platform Engineering, DevSecOps, Cloud Engineering, or a closely related field
- Experience securing production workloads in AWS
- Strong understanding of cloud networking, IAM, encryption, secrets management, and infrastructure security
- Experience building Infrastructure as Code using Terraform
- Experience securing CI/CD pipelines and modern software delivery workflows
- Experience implementing Secure SDLC practices
- Hands-on experience with vulnerability management and security automation
- Experience with scripting and automation using Python or similar languages
- Experience partnering with engineering teams to perform architecture reviews and threat modeling
- Working knowledge of SOC 2 controls and experience supporting compliance initiatives
- Excellent written and verbal communication skills
- Ability to work independently while collaborating effectively across engineering teams
- Experience working within FinTech, financial services, or other highly regulated industries
- Experience supporting PCI DSS compliance
- Experience with container and Kubernetes security
- Experience implementing SAST, DAST, software composition analysis, and secrets scanning
- Experience with AWS security services such as Security Hub, GuardDuty, Inspector, CloudTrail, and IAM Identity Center
- Experience evaluating and implementing modern security platforms such as Wiz, Snyk, GitHub Advanced Security, CrowdStrike, or similar technologies
- Familiarity with policy-as-code and cloud governance frameworks
- Security certifications such as AWS Security Specialty, Security+, CISSP, or equivalent practical experience
- Working knowledge of the Drata trust management platform