Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Security Engineer image - Rise Careers
Job details

Senior Security Engineer

Who You Are:


You are a Senior Security Engineer with a strong focus on application security and a deep understanding of securing CI/CD pipelines. You are experienced in collaborating with development and DevOps teams to integrate security throughout the software delivery lifecycle. You have a proactive mindset, strong technical skills, and a commitment to staying ahead of emerging threats and vulnerabilities. Your attention to detail and ability to automate security processes make you a key partner in ensuring secure software delivery.


Does this sound like you? If so, keep reading and apply today!


What You'll Do:
  • Design and implement security controls and tools within CI/CD pipelines to protect against threats and vulnerabilities.
  • Conduct security assessments, code reviews, and penetration testing on applications and infrastructure deployed through CI/CD workflows.
  • Integrate security tools (e.g., SAST, DAST, dependency scanning) into CI/CD systems such as Jenkins, GitLab CI/CD, GitHub Actions, or CircleCI.
  • Collaborate with DevOps teams to automate security checks and ensure secure configuration of build and deployment environments.
  • Monitor and respond to security incidents related to CI/CD processes, including artifact integrity and pipeline tampering.
  • Develop and maintain documentation for secure CI/CD practices, policies, and procedures.
  • Stay up-to-date with emerging threats, vulnerabilities, and security technologies relevant to CI/CD and cloud-native environments.
  • Educate and train development teams on secure coding practices and CI/CD security principles.
  • Ensure compliance with regulatory standards (e.g., SOC 2, ISO27001) in the software delivery lifecycle.


What You Have:
  • 3+ years of experience in security engineering, DevSecOps, or a related role.
  • Hands-on experience securing CI/CD pipelines using tools like Jenkins, GitLab CI/CD, GitHub Actions, or similar platforms.
  • Proficiency with security tools such as Sonarcloud Github Security
  • Strong understanding of software development lifecycle (SDLC) and DevOps practices.
  • Familiarity with containerization and orchestration technologies (e.g., Docker, Kubernetes) and their security implications.
  • Knowledge of cloud platforms (e.g., AWS) and their security configurations.
  • Experience with scripting languages (e.g., Python, Bash) for automation and tool integration.
  • Excellent problem-solving skills and attention to detail.


Extras you bring
  • Experience with Infrastructure-as-Code (IaC) tools like Terraform or CloudFormation.
  • Familiarity with secrets management tools (e.g., HashiCorp Vault, AWS Secrets Manager).
  • Understanding of zero-trust security models and their application in CI/CD.
  • Strong communication skills to collaborate across technical and non-technical teams.
  • Ability to prioritize and manage multiple tasks in a fast-paced environment.
  • Proactive mindset with a focus on identifying and mitigating risks early in the development process.


Why Join Polly?
  • We are attacking a trillion-dollar market with gross inefficiencies and seeking to transform the way an entire industry operates 
  • You will have an impact on the design, architecture and implementation of markets that are often called the engine of US economy
  • We value drive for excellence, independent thinking, teamwork and curiosity
  • You will work with both government backed and industry leading companies to create a digital pipeline that facilitates real time trading of loans
  • We have an experienced leadership team that previously built large and impactful platforms 
  • Outstanding opportunity for professional growth and upward mobility 
  • Direct engagement with the decision makers and senior business leaders 
  • Competitive salaries
  • 100% paid medical/vision/dental/disability/life insurance 
  • Unlimited PTO
  • Hybrid environment; 3x weekly in an innovation hub in San Francisco or Dallas


Let's get to know each other.


Polly has pioneered the next generation of mortgage capital markets technology with its cutting-edge, data-driven platform. Its enterprise-grade solutions, including the industry's only cloud-native, commercially scalable product, pricing, and eligibility (PPE) engine and first-of-its-kind Polly/™ AI platform, empower the nation's top banks, credit unions, and mortgage lenders to increase profitability, automate workflows, and revolutionize the loan officer and broker experiences. As a mortgage technology trailblazer, Polly is committed to driving meaningful value and ROI through best-in-class innovation that enables unlimited configurability, flexibility, granularity, and scalability. Polly was founded by a seasoned team of mortgage capital markets and technology experts and is headquartered in San Francisco, California. Recognized as a pioneer in mortgage capital markets, as well as in culture and career development, Polly was named to Forbes' America's Best Startup Employers in 2025. This evaluation was based on three key criteria: Employer Reputation, Employee Satisfaction, and Company Growth.


To learn more, follow Polly on LinkedIn or visit www.polly.io. Polly is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, age, color, national origin, religion, sex, gender identity, sexual orientation, marital status, pregnancy status, disability status, veteran status, or any other legally protected status. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.


Beware of recruitment scams impersonating the Polly brand or our employees. Our team communicates only through official Polly channels, and we will never ask for sensitive information over text or conduct text-only interviews. If you are ever suspicious or in doubt, reach out to us directly at peopleteam@polly.io. We care deeply about this network and your experience. 

Polly Glassdoor Company Review
4.8 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Polly DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Polly
Polly CEO photo
Unknown name
Approve of CEO

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Security Engineer, Polly

Are you an experienced Senior Security Engineer looking for your next big adventure? At Polly, we’re on the cutting edge of mortgage technology, and we need someone like you who is passionate about application security and securing CI/CD pipelines. You’ll be an integral part of our team, designing and implementing security controls, conducting thorough security assessments, and collaborating with our innovative DevOps teams. Your expertise in tools like Jenkins, GitLab CI/CD, and GitHub Actions will play a key role in ensuring our software delivery is safe and sound. We believe in a proactive approach to security; with your skills, you’ll help us automate security checks, monitor incidents, and educate our teams on secure coding practices. You’ll not only help us adhere to critical compliance standards but also stay ahead of emerging threats to keep our processes secure. At Polly, we value excellence, drive for results, and a commitment to continuous improvement. If you’re looking to make a real impact in a fast-paced, supportive environment where your contributions are noticed, this is the perfect place for you. Join us in redefining the mortgage capital markets with innovative technology and become a part of our journey today!

Frequently Asked Questions (FAQs) for Senior Security Engineer Role at Polly
What are the main responsibilities of a Senior Security Engineer at Polly?

As a Senior Security Engineer at Polly, you will design and implement security measures within our CI/CD pipelines to mitigate risks from emerging threats and vulnerabilities. Your focus will be on managing and automating the security of software delivery processes, performing security assessments, and continuously educating teams on best practices related to application security. You’ll also need to respond to security incidents and ensure compliance with important standards.

Join Rise to see the full answer
What qualifications do I need to apply for the Senior Security Engineer role at Polly?

To apply for the Senior Security Engineer position at Polly, you should have at least 3 years of experience in security engineering or DevSecOps. Proficiency with CI/CD tools like Jenkins, GitLab CI/CD, and GitHub Actions is essential, along with strong coding skills, mainly in scripting languages such as Python or Bash. Familiarity with cloud platforms and container orchestration technologies like Docker and Kubernetes will also be necessary to succeed in this role.

Join Rise to see the full answer
How does Polly support professional growth for Senior Security Engineers?

At Polly, we prioritize professional growth and development. As a Senior Security Engineer, you will have opportunities for upward mobility with direct access to decision-makers and senior leaders in the company. We also encourage continual learning and provide resources to stay updated on the latest security technologies and practices relevant to your role.

Join Rise to see the full answer
What tools and technologies will I work with as a Senior Security Engineer at Polly?

As a Senior Security Engineer at Polly, you’ll work with various tools and technologies including CI/CD platforms like Jenkins, GitLab CI/CD, and GitHub Actions. You will also utilize security tools such as SonarCloud and GitHub Security, as well as automation frameworks for CI/CD processes. Your role will also involve handling containerization tools like Docker and Kubernetes, along with cloud platforms like AWS.

Join Rise to see the full answer
Is remote work an option for the Senior Security Engineer position at Polly?

Polly offers a hybrid work environment for our employees, including the Senior Security Engineer role. You’ll have the flexibility to work three days a week in our innovation hubs located in San Francisco or Dallas, while also having the option to work remotely, ensuring a balanced work-life setup.

Join Rise to see the full answer
Common Interview Questions for Senior Security Engineer
What experience do you have securing CI/CD pipelines?

Discuss specific projects where you have integrated security measures within CI/CD pipelines. Highlight tools used, challenges faced, and how you cultivated collaboration with DevOps teams to implement security practices effectively.

Join Rise to see the full answer
Can you explain the significance of automated security checks in software delivery?

Automated security checks in software delivery pipelines are crucial as they help in identifying vulnerabilities early in the process, reducing the risk of security breaches post-deployment. Highlight experiences where automation directly improved security outcomes in your previous roles.

Join Rise to see the full answer
How do you stay updated with the latest security trends and vulnerabilities?

Share your preferred sources for keeping updated, such as industry blogs, webinars, professional groups, or certifications that you pursue. Stress the importance of continuous learning as part of a security engineer's role.

Join Rise to see the full answer
What do you understand about Infrastructure-as-Code (IaC) tools and their role in security?

Explain your experience with IaC tools like Terraform or CloudFormation and how they enhance security by allowing version control of infrastructure configurations. Give examples of how misconfigurations can lead to vulnerabilities.

Join Rise to see the full answer
Describe a time when you had to respond to a security incident.

Provide a structured response with the incident’s context, the steps you took to mitigate the issue, and the outcomes of your actions. This showcases your problem-solving abilities and experience dealing with security challenges.

Join Rise to see the full answer
How would you educate a development team about secure coding practices?

Discuss your strategy for creating training sessions or workshops that address common vulnerabilities and coding practices. Mention tools or resources you might recommend to aid developers in writing secure code.

Join Rise to see the full answer
What are the key compliance standards that affect the CI/CD process?

Identify major compliance standards such as SOC 2 and ISO27001, and discuss how ensuring compliance within the CI/CD pipeline impacts security measures, making it a priority for every release cycle.

Join Rise to see the full answer
Can you give examples of tools used for vulnerability scanning within CI/CD?

Refer to tools like SAST, DAST, and dependency scanners that you have utilized in past projects. Explain how they were integrated into the workflow and their effectiveness in identifying security risks.

Join Rise to see the full answer
What steps do you take to ensure artifact integrity and prevent pipeline tampering?

Discuss your approaches to maintaining artifact integrity, such as using checksums, signing releases, and implementing monitoring mechanisms to detect unauthorized changes in the pipeline.

Join Rise to see the full answer
How do you prioritize security tasks in a fast-paced environment?

Explain your methods for assessing risk and urgency in various tasks, and how you communicate with stakeholders to balance security with project deadlines while ensuring that critical vulnerabilities are addressed promptly.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Polly Remote No location specified
Posted yesterday

Be part of Polly's growth story as a Sales Development Representative, engaging with top executives and helping transform the mortgage industry.

Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 11 days ago
Photo of the Rise User
XMSTART Hybrid No location specified
Posted 10 days ago
Photo of the Rise User
Cognizant Remote US, New York County, NY; New York State, New York, NY
Posted 7 days ago

Cognizant is looking for an experienced AWS Enterprise Architect to drive cloud transformation and architect solutions for enterprise clients.

Polly's mission is to help capital markets and secondary teams operate smarter, more efficiently, and more profitably with best-in-class, end-to-end technology configured for each of our customers’ unique workflows and business needs.

98 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Diversity ChampionBadge Future MakerBadge Rapid Growth
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 3, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!