Beyondfinance
Beyondfinance

Staff Security Automation Engineer

engineeringfull-timeRemote
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
fintech
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

The Role

As a Staff Security Engineer, you'll build and deploy the controls, automation, and log pipelines that let a lean security team cover a large and growing surface. Much of the role is hands-on: standing up controls, wiring up tooling, and building the internal tooling that makes the team and our processes better. When the work calls for custom code, you write it yourself rather than waiting on someone else.

You'll sit inside security engineering and work hands-on across our AWS environment, our SIEM, our endpoint fleet, our CI/CD systems, and our application and infrastructure repos. Where a lot of security teams find a problem and hand off a ticket, we implement the fix ourselves, and this person is a big part of how we do that at scale.

Key Responsibilities

  • Build and own our security log pipelines: get logs out of the systems that produce them, transform and enrich them, and land them in our SIEM where the team can detect and investigate. This is a large part of the role.
  • Operate and improve our SIEM: onboard new sources, and build and tune the detections and alerts the team runs on.
  • Deploy and tune security controls across our endpoint fleet of managed macOS and Windows workstations and AWS WorkSpaces virtual desktops running Windows Server.
  • Build internal tooling and automation that makes the team and our processes better, from removing manual toil in triage and remediation to giving the team capabilities it doesn't have today. When it calls for custom code, it's primarily Python.
  • Instrument our environment for security signal by integrating our tooling through their APIs and writing the connective code that ties the stack together.
  • Establish secure defaults in our Infrastructure as Code through reusable modules and policy as code.
  • Build security into CI/CD: scanning, secrets detection, and policy-as-code gates that live in the developer workflow.
  • Treat the pipelines and tooling you build as a platform you own, including their reliability and coverage.
  • Work directly in systems your team does not own: read the code or infra, make the change safely, and get it through review rather than filing a ticket.

Requirements

  • 8+ years of hands-on security engineering with a focus on automation, tooling, and instrumentation.
  • Comfortable writing custom code and scripting, primarily in Python, to build your own tooling and log pipelines from scratch. You do not have to be a career software engineer, but you are well past copy-and-paste.
  • Hands-on experience building and operating log pipelines end to end: collection, parsing, enrichment, and delivery into a SIEM.
  • Hands-on SIEM experience: onboarding sources and building or tuning detections and alerts.
  • Experience deploying and managing endpoint security across a mixed fleet of macOS and Windows workstations, including virtual desktops.
  • Hands-on Infrastructure as Code experience; Terraform required.
  • Experience building C
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply
Apply now
Staff Security Automation Engineer at Beyondfinance — Remote