Skip to main content
Lob

Staff Security Engineer, Cloud and Product Security

RemoteUnited States only
Published
Role
Security
Experience
Staff
Employment
Full-time
Company size
Mid-size
$197.5k–$220k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Staff-level security engineer with 8+ years in security engineering and deep cloud security experience. Must be hands-on with AWS security, IAM, infrastructure as code, detection engineering, incident response, and application security. US remote only in listed states.

Core skills

AWS SecurityDetection EngineeringApplication Security

Required skills

AWSIAMInfrastructure as CodeSIEMSCASASTDAST

Optional skills

SOC 2 Type 2HIPAAMicrosoft SSPANomadKubernetesCloudflareCloudflare Zero TrustWAF

What you'll do

  • Own the engineering side of security: cloud infrastructure, detection and response, application security, and incident response.
  • Partner with the dedicated GRC counterpart without absorbing audit, compliance, and customer trust ownership.
  • Report directly to the CTO, manage the application security contractor, and work day to day with Platform, Logistics, and IT teams.
  • Own the security posture of the AWS environment, including the CNAPP program and cloud misconfiguration risk.
  • Review infrastructure changes across Terraform, Nomad, and the Cloudflare edge.
  • Own WAF strategy and tuning at the domain level.
  • Work with Platform engineers so security is designed in rather than reviewed at the end.
  • Build and own the detection engineering practice on the SIEM, moving from noisy alert channels to curated, high signal detections.
  • Define alert triage ownership, runbooks, and severity criteria.
  • Own security incident response, including escalation paths, tabletop exercises, and post incident reviews.
  • Partner with IT on endpoint detection and endpoint vulnerability coverage.
  • Own the vulnerability management program across SCA, SAST, DAST, and container scanning.
  • Manage and mentor the application security contractor, and route remediation work into engineering teams effectively.
  • Perform threat modeling and security architecture review for new products and major changes.
  • Improve secure SDLC practice in a high velocity, AI-assisted engineering org.
  • Technically own the annual independent penetration test: scoping, findings triage, remediation routing, and retest coordination.
  • Produce the technical evidence the GRC counterpart needs for SOC 2, HIPAA, and Microsoft SSPA, without owning the audit itself.
  • Build tooling and automation rather than process and spreadsheets.
  • Apply AI to security operations where it creates real leverage.
  • Contribute technical input and evidence to GRC, without running the program.

What they require

  • 8 or more years in security engineering, with meaningful depth in cloud security.
  • Hands on expertise with AWS security services, IAM design, and infrastructure as code.
  • Demonstrated detection engineering experience: you have written detections, tuned them, and cut false positive rates.
  • Real incident response experience as a responder or lead, not just as a plan author.
  • Fluency in application security sufficient to review findings, judge severity, and argue exploitability with engineers.
  • Track record of shipping security improvements through other teams by earning trust rather than filing tickets.
  • Comfort as the senior technical security voice in an organization without a large security team.
  • Preferred: Experience supporting SOC 2 Type 2, HIPAA, or Microsoft SSPA from the engineering side.
  • Preferred: Container and orchestration security, particularly Nomad or Kubernetes.
  • Preferred: Cloudflare, including Zero Trust and WAF.
  • Preferred: Experience in a company handling regulated or consumer-identifiable data at scale.
  • Preferred: Prior experience mentoring or managing engineers or contractors.

Benefits

  • Annual base salary and RSUs.
  • Equity, perks and competitive benefits.
  • Remote working opportunities in AZ, CA, CO, DC, FL, GA, IA, IL, MA, MD, MI, MN, MT, NE, NC, NH, NJ, NV, NY, OH, OR, PA, RI, TN, TX, UT, and WA.
  • Progressive, fun-spirited, and mentally stimulating environment.
  • Executive access, a clean mandate, and a function you are helping design rather than inherit.

Lob

Lob is transforming the way businesses use direct mail with a modern logistics and fulfillment engine that helps businesses build and scale personalized direct mail programs.

LogisticsMid-size

Details

Apply routeGreenhouse
$197.5k–$220k/yr