AutoFi
About AutoFi
About the Role:
AutoFi is looking for a passionate and driven Senior Security Engineer. You will work closely with development teams, product managers, and third-party groups to ensure AutoFi’s products, services, cloud environments, internal systems, and vendor ecosystem are secure.
You will contribute to secure design reviews, application security standards, vulnerability management, security monitoring, incident response, threat hunting, and third-party security assessments. This role is ideal for someone who is comfortable working across both proactive and operational security functions in a fast-paced environment.
Responsibilities
-
Define, implement, and maintain security practices, standards, and controls across AutoFi’s products, services, cloud environments, and internal systems.
-
Partner with engineering and product teams to conduct security design reviews for new features, architecture changes, sensitive workflows, and production-bound implementations.
-
Design and implement security standards and secure development practices across engineering teams.
-
Champion security-related activities throughout the software development lifecycle, including secure design, threat modeling, secure coding practices, security testing, and risk-based remediation.
-
Implement, operate, and improve DevSecOps tooling and processes, including SAST, DAST, SCA, secret scanning, dependency analysis, and other application security controls.
-
Assess infrastructure, web applications, and cloud environments to help identify, prioritize, and drive remediation of security risks.
-
Triage vulnerability findings from application security tools, penetration tests, vendor assessments, external reports, and internal reviews.
-
Conduct proactive threat hunting using available telemetry from cloud environments, application logs, WAF events, identity systems, endpoint signals, and security platforms.
-
Support continuous improvement of AutoFi’s security operations processes, including alert tuning, detection logic, workflow automation, and post-incident lessons learned.
-
Assist in defining, implementing, and maintaining third-party risk management policies, procedures, standards, and assessment workflows.
-
Conduct and support vendor security assessments
-
Identify, document, and help reduce risks related to third-party vendors, SaaS platforms, integrations, service providers, and business partners.
Required Qualifications
-
6+ years of experience in security engineering, application security, cloud security, security operations, or a related security function.
-
Experience designing and implementing security controls for modern SaaS, cloud, web application, and API environments.
-
Hands-on experience with application security practices, including secure design reviews, threat modeling, secure code review, vulnerability assessment, and OWASP-based testing methodologies.
-
Strong understanding of SAST, DAST, IAST, and SCA tooling
-
Experience with web & cloud security controls/frameworks
-
Familiarity with network and web application protocols (HTTP/S, SAML 2.0, OAuth, Rest APIs)
-
Experience with SIEM platforms, alert triage, security investigations, detection workflows, and incident response procedures.
-
Familiarity with indicators of compromise, indicators of attack, threat hunting techniques, and incident escalation processes.
-
Industry experience building data-driven applications with Javascript, Node.js, and NoQSL.
-
Minimum BS/BA in Cybersecurity, Information Security, Computer Science, or relevant degree, with the ability to demonstrate sophisticated logical thought processes.
-
Ability to communicate security risks clearly to engineering, product, compliance, business, and executive stakeholders.
-
Comfortable operating in a fast-paced environment with evolving priorities and shared ownership across multiple security domains.
Preferred Qualifications
-
Experience with common threat modeling frameworks (STRIDE, DREAD, etc).
-
Experience with cloud-based Web Application Firewall solutions and web application protection strategies.
-
Familiarity with CNAPP, CSPM, CWPP, container security, runtime security, or cloud workload protection platforms.
-
Experience with source code security platforms such as GitHub Advanced Security or similar tools.
-
Experience conducting proactive threat hunting across cloud, identity, endpoint, network, SaaS, and application telemetry.
-
Familiarity with ethical hacking and penetration testing tools & methodologies.
-
Experience with AWS security best practices and native controls & services.
-
Prior Automotive or FinTech experience.
What’s in it for you:
Originally posted on Himalayas
To apply for this job please visit himalayas.app.
About this role & career path
Working in United States
The United States of America (USA), also known as the United States (U.S.) or America, is a country primarily located in North America. It is a federal republic consisting of 50 states and a federal capital district, Washington, D.C. The 48 contiguous states border Canada to the north and Mexico to the south, with the semi-exclave of Alaska in the northwest and the archipelago of Hawaii in the Pacific Ocean. The United States also asserts sovereignty over five major island territories and various uninhabited islands in Oceania and the Caribbean. It is a megadiverse country, with the world's th
Keep exploring on Get A Job.ai
Not quite the right fit? Your next opportunity is a click away.
- Browse all jobs
- More jobs by category
- Remote jobs you can do from anywhere
- Research typical pay for this role
- Set a job alert so new matches reach you first
- Upload your resume to apply faster
Hiring instead? Post a job and reach candidates searching right now.