Skip to main content
Later

Senior Security Engineer

RemoteUnited States, Canada, Chile only
Published
Role
Security
Experience
Senior
Employment
Full-time
$145k–$175k/yr
Check eligibility

Open to US, CA, CL only. Set where you work from to check your eligibility.

No BS summary

Senior security engineer with 5-7+ years in security engineering or software engineering with a strong security focus. Needs hands-on application, cloud/infrastructure, CI/CD, vulnerability management, SOC 2/compliance, SIEM/monitoring, and IaC security experience. Role is remote but posted for the United States, with listed US and Canada locations.

Core skills

CI/CDSOC 2Cloud security

Required skills

API securityInfrastructure-as-CodeOWASPNISTCIS ControlsISO 27001SIEMSOARTerraformCloudFormationC#

Optional skills

AWS Security HubAzure Security CenterGCP Security Command Center

What you'll do

  • Assess and continuously improve Later's overall security posture across applications, infrastructure, cloud environments, corporate systems, vendor tooling, and business workflows.
  • Define and implement scalable security standards, best practices, and guardrails that support SOC 2 readiness through practical, automated, and auditable solutions.
  • Partner with Engineering, Infrastructure, IT, Product, Legal, People, Finance, and business leaders to align security priorities with company goals, risk reduction, and delivery timelines.
  • Translate SOC 2 and related compliance requirements into sustainable technical and operational controls, procedures, and evidence collection practices.
  • Identify security gaps across the company, prioritize remediation efforts, and help teams make pragmatic, risk-based decisions.
  • Support company-wide security awareness, secure operating practices, and adoption of security controls across business teams.
  • Build and maintain internal security tools, automation, and services that support secure development, compliance workflows, vulnerability management, corporate security operations, and operational visibility.
  • Design and implement security controls within CI/CD pipelines, including secure build and deploy patterns, security scanning, dependency management, container scanning, and secret management.
  • Support application security efforts, including secure design reviews, threat modeling, code review guidance, API security, microservices security patterns, and remediation planning.
  • Improve cloud infrastructure and corporate systems security through hardening, monitoring, configuration review, Infrastructure-as-Code security scanning, access reviews, and secure operational patterns.
  • Collaborate with technical and business teams to identify vulnerabilities and control gaps, explain impact clearly, and drive effective remediation.
  • Strengthen security observability and response readiness through logging, alerting, detection engineering, incident response improvements, and company-wide security process maturity.
  • Partner with teams across the company to identify, understand, and fix security issues in a collaborative, non-blocking way.
  • Provide pragmatic security guidance on designs, implementations, vendor tools, operational practices, and business workflows.
  • Communicate security risks, tradeoffs, and recommendations clearly across technical and non-technical audiences.
  • Embed security into development workflows, corporate systems, and company operating practices without slowing teams unnecessarily.
  • Support SOC 2 and related compliance efforts through automation, well-defined controls, reliable evidence practices, and cross-functional coordination.

What they require

  • 5-7+ years of experience as a Security Engineer or Software Engineer with a strong security focus.
  • Proven ability to build and operate production-quality software, automation, and internal tooling.
  • Strong understanding of application security, infrastructure security, cloud security, secure CI/CD practices, and corporate security controls.
  • Hands-on experience with vulnerability management, secure software development, threat modeling, remediation workflows, and operational security improvements.
  • Experience with security frameworks and standards such as OWASP, NIST, CIS Controls, SOC 2, and ISO 27001, and the ability to apply them in production and business environments.
  • Experience supporting SOC 2 compliance efforts through practical, automated, and auditable controls.
  • Familiarity with cloud security platforms such as AWS Security Hub, Azure Security Center, or GCP Security Command Center.
  • Experience with SIEM/SOAR tools, logging and monitoring platforms, detection workflows, and practical incident response processes.
  • Experience with Infrastructure-as-Code security scanning for tools such as Terraform or CloudFormation.
  • Ability to translate complex security concepts into clear, actionable guidance for technical and non-technical audiences.
  • Experience collaborating closely with engineering, IT, compliance, and business teams to improve security outcomes.
  • Familiarity with C#, modern backend systems, cloud-native architecture, and SaaS business tooling.
  • Driven by Impact: deliver results that matter, prioritize high-value work, meet deadlines, and adapt quickly while keeping outcomes clear.
  • Strategic & Customer-Centric: anticipate risks and opportunities, connect decisions to long-term growth, and build trust through proactive insights.
  • Curious & Growth-Oriented: seek knowledge, ask sharp questions, and apply learnings fast, challenging the status quo with a mindset of improvement.
  • Collaborative & Resilient: thrive in change by staying resourceful, solution-focused, and positive, removing roadblocks, sharing insights, and keeping morale high.
  • Accountable & Honest: own your work, hold yourself and others to a high bar, and use transparent feedback to drive growth.
  • Emotionally Intelligent: build trust through empathy and collaboration, foster inclusion, and inspire others with grit, optimism, and integrity.

Benefits

  • All permanent team members are eligible to participate in various benefits plans as part of their overall compensation package.
  • Inclusive, supportive place to do the best and most rewarding work of your career.
  • For select positions, open to hiring fully remote candidates.

Later is an influencer marketing company that combines creator relationships, trusted intelligence, expert guidance, an AI-powered platform, and proprietary data to help brands run influencer campaigns.

🇺🇸 United StatesMarketingMid-size
$145k–$175k/yr