About the role
You will own the technical implementation, operation, and testing of security controls across infrastructure and internal systems. This includes managing vulnerabilities, operating security monitoring, automating security tasks, and leading technical incident response.
What they look for
Requirements
The role requires proven experience in technical security within a production SaaS or cloud environment, along with strong Linux and networking fundamentals. Candidates should have practical knowledge of security frameworks like SOC 2 or ISO 27001 and the ability to automate operational tasks.
Full description
About Semaphore
Semaphore is a remote-first software company helping engineering teams build, test, and deliver software with confidence. Our customers rely on Semaphore Cloud and our self-hosted enterprise products to run critical development workflows securely and reliably.
We maintain SOC 2 Type 2 and ISO 27001:2022 compliance and are hiring a Security Engineer to own the technical side of our security program.
About the role
You will be the technical owner of information security across our infrastructure and internal systems. You will work closely with Engineering, Infrastructure, and our Compliance Manager to turn security and compliance requirements into practical, reliable controls.
This is a hands-on role. You will investigate vulnerabilities, operate security monitoring, improve infrastructure and access controls, automate recurring work, and lead technical remediation. Our Compliance Manager owns the ISMS, policies, audit coordination, and legal or regulatory interpretation; you will own the implementation, operation, and testing of the technical controls behind them.
We care more about demonstrated ownership and sound judgment than a specific number of years or a previous job title.
What you will own
- Run the vulnerability-management lifecycle: scanning, triage, prioritization, remediation, exceptions, and verification.
- Operate and improve security monitoring and SIEM tooling, including alert quality, dashboards, detection rules, and integrations.
- Investigate security alerts and lead the technical response to security incidents.
- Improve the security of Linux hosts, cloud infrastructure, networks, firewalls, containers, and internal services.
- Own technical controls for identity and access management, least privilege, just-in-time access, secrets, and certificates.
- Automate patching, evidence collection, recurring control checks, and other security operations.
- Coordinate penetration tests and drive technical findings through remediation and verification.
- Translate SOC 2 and ISO 27001 control requirements into effective technical implementations.
- Produce clear technical evidence for internal and external audits in partnership with the Compliance Manager.
- Maintain security runbooks, system documentation, risk-based priorities, and operational metrics.
- Help engineering teams make practical security decisions without adding unnecessary process.
What we are looking for
- Proven ownership of technical security in a production SaaS, cloud, hosting, or infrastructure environment.
- Strong Linux systems, networking, and cloud-security fundamentals.
- Hands-on experience with vulnerability management, patching, hardening, and remediation at scale.
- Experience operating SIEM or security-monitoring systems and investigating security events.
- Practical understanding of IAM, privileged access, secrets management, certificates, and network controls.
- Ability to automate operational work using Python, Bash, infrastructure-as-code, or similar tools.
- Experience participating in incident response and communicating clearly during high-pressure situations.
- Working knowledge of ISO 27001, SOC 2, or similar security-control frameworks.
- Strong written and spoken English and comfort working independently in a remote, asynchronous team.
- Good risk judgment: the ability to distinguish urgent security problems, acceptable exceptions, and low-value processes.
Nice to have
- Experience with Wazuh or a comparable SIEM/security-monitoring platform.
- Experience with Teleport, PAM, or just-in-time access systems.
- Experience securing large Linux server fleets or hybrid cloud/on-premise environments.
- Familiarity with CI/CD systems, build infrastructure, containers, and software supply-chain security.
- Experience supporting SOC 2 or ISO 27001 audits from the technical-control side.
- Relevant certifications such as Security+, CISSP, CISM, GIAC, or ISO 27001, although certification is not required.
What success looks like
Within your first six months:
- Technical security operations have a clear owner, documented priorities, and reliable response expectations.
- Vulnerability findings are consistently triaged, remediated, or explicitly accepted based on risk.
- Security monitoring is stable, actionable, and connected to an effective incident-response process.
- Recurring patching, access-control, and evidence-collection work is increasingly automated.
- Engineering and Infrastructure teams receive clear, practical guidance and security issues reach closure.
- Technical controls and audit evidence are reliable enough that compliance work does not depend on senior engineers doing manual follow-up.
How you will work
You will work closely with the Engineering and Infrastructure teams and partner with the Compliance Manager. The Compliance Manager owns governance, policies, the ISMS, audit coordination, and regulatory interpretation. You own the design, implementation, operation, testing, and remediation of technical security controls.
This role is an individual-contributor position with broad ownership and direct influence on how Semaphore protects its systems, customers, and company data.
Similar roles
-
Security Engineer
Applied Network Solutions Inc Linthicum, Maryland, United States · $100K–$200K/yr
-
Security Engineer with Akamai WAF
Syncreon Consulting New York, New York, United States
-
Cyber Security Engineer
UL Solutions Northbrook, Illinois, United States · $96K–$130K/yr
-
OT Network & Security Engineer
Vulcan Elements Research Triangle Park, North Carolina, United States
-
Senior Security Engineer, Access Security
Google New York, New York, United States · $174K–$252K/yr
-
Senior Security Engineer
Zepz United Kingdom