AdTechTalent
Engineering2 months agoOn-site

Moloco

Senior Security Engineer

security engineeringcloud securityCI/CDautomationinfrastructure as codecontainer securityvulnerability managementcomplianceincident responseAWSGCPAzurePythonBashSASTDASTSIEMEDRDevOps

Key details

Salary

Not specified

Employment type

Full-time

Seniority

Senior

Years experience

5+

Location

Menlo Park, United States

Full job description

Moloco is hiring a Senior Security Engineer to enhance the security of cloud infrastructure and applications. The role involves embedding automated security testing into CI/CD pipelines, securing infrastructure-as-code, containers, and cloud environments, automating vulnerability scanning and threat response, ensuring compliance with SOC 2 and GDPR, and building incident response capabilities. Candidates must have 5+ years in security engineering, strong cloud security knowledge (AWS, GCP, Azure), experience with CI/CD pipeline security, scripting skills (Python, Bash), container security expertise, and familiarity with IAM and secrets management. Preferred qualifications include knowledge of compliance frameworks, security monitoring, SIEM/EDR tools, SAST/DAST, zero-trust networking, and threat modeling. The position is full-time, on-site in Menlo Park, CA, with competitive salary ranges based on location and comprehensive benefits including health insurance, 401(k), paid holidays, and flexible time off.

What you'll do

  • Embed automated security testing (SAST/DAST) into CI/CD pipelines
  • Implement safeguards across infrastructure-as-code, containers, and cloud environments
  • Automate vulnerability scans and real-time threat responses
  • Participate in security triage and vulnerability management
  • Ensure compliance with standards like SOC 2 or GDPR within DevOps processes
  • Automate manual security tasks to accelerate development
  • Build incident response playbooks and threat intelligence defenses

Requirements

  • 5+ years of experience as a Security Engineer or similar role
  • Strong foundation in CI/CD, automation, and cloud infrastructure
  • Strong understanding of cloud security principles (AWS, GCP, or Azure)
  • Experience securing CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Harness)
  • Familiarity with infrastructure-as-code and related security tools
  • Proficiency in scripting languages (Python, Bash, etc.)
  • Hands-on experience with container security (Docker image scanning, Kubernetes best practices)
  • Knowledge of IAM, secrets management, and secure key handling
  • Experience with vulnerability scanning, remediation workflows, and risk prioritization
  • Ability to identify and mitigate misconfigurations in cloud and IaC environments
  • Comfortable collaborating with DevOps, platform, and application teams
  • Preferred: Familiarity with compliance frameworks (SOC 2, ISO 27001, NIST)
  • Preferred: Experience with security monitoring and incident response
  • Preferred: Exposure to SIEM or EDR tools (Splunk, CrowdStrike, Google SecOps)
  • Preferred: Experience with SAST/DAST and dependency scanning tools
  • Preferred: Familiarity with zero-trust networking concepts
  • Preferred: Knowledge of threat modeling and risk assessment practices

Tech stack

AWSGCPAzureGitHub ActionsGitLab CIJenkinsHarnessPythonBashDockerKubernetesSASTDASTSIEMEDRSplunkCrowdStrikeGoogle SecOpsInfrastructure as Code

Benefits

Medical, dental, and vision insurance401(k) plan with company matchShort-term and long-term disability coverageBasic life insuranceWell-being benefits and perksUp to 12 scheduled paid holidays per yearOne Thrive Day off per quarterFlexible Time Off (FTO)Potential eligibility for bonus and equity awards

Apply now

Ready to take the next step in your career? Click the button below to continue to the application process.

Similar jobs

More roles worth a look

Related opportunities based on specialty and working model so candidates can keep momentum.