AdTechTalent
Engineering19 days agoOn-site

Moloco

Senior Security Engineer

security engineeringcloud securityCI/CDautomationinfrastructure as codecontainer securityvulnerability managementcomplianceincident responseAWSGCPAzurePythonBashSASTDASTSIEMEDRDevOps

Key details

Salary

Not specified

Employment type

Full-time

Seniority

Senior

Years experience

5+

Location

Menlo Park, California, United States

Full job description

Moloco is hiring a Senior Security Engineer to enhance the security of cloud infrastructure and applications. The role involves embedding automated security testing into CI/CD pipelines, securing infrastructure-as-code, containers, and cloud environments, automating vulnerability scanning and threat response, ensuring compliance with SOC 2 and GDPR, and building incident response capabilities. Candidates must have 5+ years in security engineering, strong cloud security knowledge (AWS, GCP, Azure), experience with CI/CD pipeline security, scripting skills (Python, Bash), container security expertise, and familiarity with IAM and secrets management. Preferred qualifications include knowledge of compliance frameworks, security monitoring, SIEM/EDR tools, SAST/DAST, zero-trust networking, and threat modeling. The position is full-time, on-site in Menlo Park, CA, with competitive salary ranges based on location and comprehensive benefits including health insurance, 401(k), paid holidays, and flexible time off.

What you'll do

  • Embed automated security testing (SAST/DAST) into CI/CD pipelines
  • Implement safeguards across infrastructure-as-code, containers, and cloud environments
  • Automate vulnerability scans and real-time threat responses
  • Participate in security triage and vulnerability management
  • Ensure compliance with standards like SOC 2 or GDPR within DevOps processes
  • Automate manual security tasks to accelerate development
  • Build incident response playbooks and threat intelligence defenses

Requirements

  • 5+ years of experience as a Security Engineer or similar role
  • Strong foundation in CI/CD, automation, and cloud infrastructure
  • Strong understanding of cloud security principles (AWS, GCP, or Azure)
  • Experience securing CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Harness)
  • Familiarity with infrastructure-as-code and related security tools
  • Proficiency in scripting languages (Python, Bash, etc.)
  • Hands-on experience with container security (Docker image scanning, Kubernetes best practices)
  • Knowledge of IAM, secrets management, and secure key handling
  • Experience with vulnerability scanning, remediation workflows, and risk prioritization
  • Ability to identify and mitigate misconfigurations in cloud and IaC environments
  • Comfortable collaborating with DevOps, platform, and application teams
  • Preferred: Familiarity with compliance frameworks (SOC 2, ISO 27001, NIST)
  • Preferred: Experience with security monitoring and incident response
  • Preferred: Exposure to SIEM or EDR tools (Splunk, CrowdStrike, Google SecOps)
  • Preferred: Experience with SAST/DAST and dependency scanning tools
  • Preferred: Familiarity with zero-trust networking concepts
  • Preferred: Knowledge of threat modeling and risk assessment practices

Tech stack

AWSGCPAzureGitHub ActionsGitLab CIJenkinsHarnessPythonBashDockerKubernetesSASTDASTSIEMEDRSplunkCrowdStrikeGoogle SecOpsInfrastructure as Code

Benefits

Medical, dental, and vision insurance401(k) plan with company matchShort-term and long-term disability coverageBasic life insuranceWell-being benefits and perksUp to 12 scheduled paid holidays per yearOne Thrive Day off per quarterFlexible Time Off (FTO)Potential eligibility for bonus and equity awards

Apply now

This MVP uses a placeholder application flow. In production, this section can connect to an external apply URL or a native application form.

Similar jobs

More roles worth a look

Related opportunities based on specialty and working model so candidates can keep momentum.