MeridianLink

Security Engineer

MeridianLink United States · $104K–$140K/yr

Software Development · 501-1,000 employees

Yesterday
Remote security Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Security Engineer is responsible for safeguarding company and client data by managing security policies, tools, and compliance initiatives. They will also automate security processes, maintain AWS infrastructure defenses, and participate in an on-call rotation for incident management.

What they look for

Security operations Incident response Threat intelligence Vulnerability management AWS security IAM KMS WAF GuardDuty CloudWatch TypeScript Python REST APIs SAML Infrastructure as code Terraform

Requirements

Candidates must have a bachelor's degree in computer science or a related field along with 2-4 years of relevant experience. Proficiency in AWS security services, scripting languages like Python or TypeScript, and knowledge of authentication protocols are required.

Benefits

Medical insurance Dental insurance Vision insurance Life insurance Disability insurance Flexible paid time off Paid holidays 401(k) plan with company match Remote work

Full description

The Security Engineer in the Security Operations and Compliance team is responsible for safeguarding internal company data and client information, including consumer credit data and PII. This position involves managing information security policies, processes, and tools; overseeing vendor risk management; and ensuring compliance with internal policies, government regulations, and customer requirements. As part of the MeridianLink Security team, the Security Engineer will engage in problem-solving, automating processes, and enhancing the trustworthiness of our services. Responsibilities include maintaining the security of a serverless AWS platform using services such as WAF, IAM, KMS, GuardDuty, and CloudWatch, and focusing on developing, deploying, and executing controls and defenses to ensure the security, compliance, and risk mitigation of the firm's technology infrastructure and data assets.

Responsibilities

  • Collaborate with the MeridianLink Security team to improve automation and detection initiatives for resilient solutions.
  • Build and enhance security tooling, automated checks, and CI/CD pipeline controls for internal tools and services.
  • Analyze internal metrics and alerting workflows to reduce false positives and accurately focus engineering efforts.
  • Develop repeatable processes and build playbooks to efficiently resolve incidents.
  • Participate in a weekly on-call rotation as the primary incident responder/incident manager.
  • Implement validated security strategies for AWS-based serverless infrastructure and authentication surfaces, including SAML single sign-on with online-banking identity providers.

Qualifications: Knowledge, Skills, & Abilities

  • Bachelor's degree in computer science or related field and 2-4 years of related experience or equivalent work experience.
  • Experience in Security Operations, security monitoring, Incident Response, and Threat Intelligence.
  • 3+ years of work experience as a Security Engineer or related position.
  • 2+ years of experience in cybersecurity technologies, focusing on areas such as vulnerability management, security monitoring, data logging, and IAM.
  • 1+ years' experience with AWS security services, such as WAF, GuardDuty, IAM, KMS, and CloudWatch.
  • 2+ years of experience in tool integrations and REST APIs, as well as TypeScript or Python experience.
  • Proficiency in networking technologies, network security, and network monitoring solutions.
  • Knowledge of security systems, including authentication and single sign-on (SAML, OIDC/OAuth), web application firewalls, and intrusion detection and notification systems.
  • Familiarity with infrastructure as code, such as Pulumi, SST, or Terraform, and public cloud platforms, such as AWS.

Similar roles