Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Engineer image - Rise Careers
Job details

Security Engineer

Remote - North America or Europe

At EngFlow, we help developers save time by accelerating software builds and tests. Our cloud-based, distributed service optimizes workflows through remote execution and caching, improving efficiency, developer productivity, and product quality.

Backed by top investors, EngFlow is redefining how companies build and ship well-tested software. Our solutions speed up builds by a factor of 10 or more, while our observability platform provides actionable insights for optimization. Founded by key contributors to Bazel, we build tools that empower engineering teams—from startups to Fortune 500 companies—to enhance developer velocity and improve build performance.

Learn more about our mission, culture, and team: EngFlow | Video

As a Security Engineer, you will report to the Head of Product Engineering, with a dotted line to the CTO. You will work closely with business and technical teams to ensure our systems remain secure, meet SOC 2 compliance, and address security concerns from prospects and customers. You thrive in a fast-paced environment, proactively tackling challenges and ensuring security remains a top priority as we scale.

Key Responsibilities

  • Define and enforce security best practices across EngFlow’s infrastructure.
  • Manage security audits, including SOC 2 / FedRAMP compliance.
  • Oversee penetration testing with external vendors.
  • Implement and maintain intrusion detection, vulnerability management, and cloud security controls.
  • Collaborate with engineering teams to enhance supply chain security.
  • Own and update the Information Security Management System (ISMS) and related documentation.
  • Address security reviews, questionnaires, and compliance inquiries from customers.
  • Participate in an on-call rotation to support escalated security issues.
  • Strong analytical skills and passion for security optimization.
  • Advanced knowledge of supply chain security and cloud security.
  • Experience managing SOC 2 / FedRAMP audits and penetration tests.
  • Expertise in intrusion detection, vulnerability tracking, and management.
  • Familiarity with at least one build system (Bazel, CMake, Maven, Gradle, Nix, Buck, etc.).
  • Experience in DevOps, DevInfra, Linux, and Unix shell.
  • Hands-on experience with at least one cloud provider (AWS, Azure, GCP, OpenShift, Oracle Cloud). Terraform experience is a plus.

We offer comprehensive medical, dental, vision benefits, 401k bonus, parental leave and generous vacation. The team is fully remote but we enjoy meeting together several times a year at exciting destinations throughout the world. We value getting the work done and having fun while doing it, and have done numerous fun team events such as chocolate, whisky and tea tastings, monthly team games, escape the room among other fun events.

Average salary estimate

$125000 / YEARLY (est.)
min
max
$100000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Engineer, EngFlow Inc.

At EngFlow, we’re on a mission to empower developers to enhance their workflows by automating and speeding up software builds and tests. As a Security Engineer, you will play a pivotal role in our dynamic, remote team, where you’ll help ensure our systems remain secure while meeting SOC 2 compliance standards. You’ll be reporting directly to the Head of Product Engineering, and collaborating closely with the CTO as well as various business and technical teams. Your responsibilities will range from defining and enforcing robust security practices to managing security audits, including FedRAMP compliance. You’ll work with external vendors on penetration testing and oversee vulnerability management efforts. By engaging with engineering teams, you will enhance supply chain security, all while maintaining our Information Security Management System (ISMS). Your analytical skills and passion for security optimization will shine as you address customer security reviews and compliance inquiries. In our fast-paced environment at EngFlow, we value proactive approaches to challenges while keeping security at the forefront as we continue to scale. With competitive benefits and a fully remote team culture, including exciting team events, EngFlow is not just about productivity but also about having fun while getting the job done. Join us on this amazing journey where you can make a significant impact in the software development landscape while growing in your career!

Frequently Asked Questions (FAQs) for Security Engineer Role at EngFlow Inc.
What are the responsibilities of a Security Engineer at EngFlow?

The Security Engineer at EngFlow is responsible for defining and enforcing security best practices, managing security audits such as SOC 2 and FedRAMP, overseeing penetration testing, and implementing intrusion detection and vulnerability management measures. It’s a multifaceted role that demands collaboration with engineering teams to enhance supply chain security and maintaining the Information Security Management System (ISMS). Additionally, the engineer addresses customer security inquiries and participates in an on-call rotation.

Join Rise to see the full answer
What qualifications are needed to be a Security Engineer at EngFlow?

To qualify for the Security Engineer position at EngFlow, candidates should have advanced knowledge of supply chain and cloud security, experience managing SOC 2 and FedRAMP audits, and strong expertise in intrusion detection and vulnerability management. Familiarity with build systems like Bazel or CMake, as well as DevOps practices and cloud environments (AWS, Azure, GCP), are also key qualifications for this role.

Join Rise to see the full answer
How does EngFlow support security compliance?

EngFlow prioritizes security compliance through rigorous management of security audits, including SOC 2 and FedRAMP. The Security Engineer is vital in overseeing these compliance measures, engaging in penetration testing with external vendors, and ensuring that the systems meet necessary security standards while addressing any concerns from prospects and customers.

Join Rise to see the full answer
What skills are essential for a Security Engineer at EngFlow?

Essential skills for the Security Engineer role at EngFlow include strong analytical capabilities, advanced knowledge of cloud security, and a passion for optimizing security practices. Furthermore, hands-on experience with Cloud providers, Terraform, and familiarity with various build systems are highly beneficial in this position.

Join Rise to see the full answer
What is the team culture like at EngFlow for remote Security Engineers?

At EngFlow, the team culture is fully remote but vibrant. We prioritize both productivity and enjoyment, organizing fun events like team games, escape rooms, and tastings throughout the year. Our collaborative environment encourages communication and engagement among team members, fostering a sense of belonging and teamwork.

Join Rise to see the full answer
Common Interview Questions for Security Engineer
What motivated you to apply for the Security Engineer position at EngFlow?

In answering this question, highlight your passion for security and how EngFlow’s mission aligns with your values. Discuss your admiration for EngFlow's innovative approach to software development, and how you believe your skills can contribute to enhancing security measures within the organization.

Join Rise to see the full answer
How do you stay updated with the latest security trends and technologies?

A strong candidate should discuss various resources like security blogs, webinars, conferences, and online courses that they follow. Highlighting professional connections or communities can also indicate active engagement in the security field.

Join Rise to see the full answer
Can you describe your experience with managing security audits?

Here, provide specific examples of audits you’ve managed, focusing on SOC 2 and FedRAMP. Detail your role in preparing documentation, implementing security measures, and engaging with auditors, to demonstrate your hands-on experience.

Join Rise to see the full answer
What are some common security vulnerabilities you have encountered?

Discuss prevalent vulnerabilities such as cross-site scripting (XSS), SQL injection, and others. Explain how you addressed them, showcasing your analytical skills and problem-solving abilities.

Join Rise to see the full answer
How would you approach improving supply chain security at EngFlow?

Outline a strategy involving collaboration with engineering teams to assess current practices. Discuss implementing best practices and tools for monitoring supply chains, as well as training team members on security awareness to prevent vulnerabilities.

Join Rise to see the full answer
What tools and technologies are you familiar with for security management?

Mention specific tools you’ve used for intrusion detection, vulnerability management, and cloud security. Discuss how your experience with these tools supports your ability to fulfill the responsibilities at EngFlow.

Join Rise to see the full answer
Can you give an example of a time when you had to respond to a security breach?

Share a brief story detailing the situation, how you responded, the steps you took to mitigate the breach, and what you learned from the experience. This illustrates your crisis management skills and learned resilience.

Join Rise to see the full answer
How do you prioritize security tasks in a fast-paced environment?

Discuss your method for identifying critical security tasks based on risk assessment and potential impact. Highlight the importance of collaborating with teams to understand their priorities while balancing security needs.

Join Rise to see the full answer
What do you believe are the biggest challenges facing security engineers today?

Discuss challenges such as staying ahead of emerging threats, addressing the skills gap in the industry, and adapting to evolving compliance requirements. Offer insights on how you believe effective solutions can be achieved.

Join Rise to see the full answer
What do you hope to achieve as a Security Engineer at EngFlow?

Articulate your desire to help build a secure, resilient environment while contributing to EngFlow’s goals. Discuss your intention to grow professionally and collaboratively support team members in enhancing their security practices.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 4 days ago
Photo of the Rise User
Posted 11 days ago
Photo of the Rise User
MYOB Remote Melbourne, Australia
Posted 6 days ago
Photo of the Rise User
Posted yesterday
Photo of the Rise User
City of Philadelphia Hybrid 1234 Market St, Philadelphia, PA 19107, USA
Posted 3 days ago

EngFlow is a SaaS company that is redefining how companies build software and ship well-tested products. Its remote execution service speeds up software builds by a factor of 10 or more, and observabi...lity platform provides insights to optimize ...

3 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
March 22, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
10 people applied to ITSM Specialist at Datacom
Photo of the Rise User
Someone from OH, Dublin just viewed Sr. Manager UX Design Research at Visa
Photo of the Rise User
Someone from OH, Columbus just viewed Case Manager at Release Recovery
Photo of the Rise User
54 people applied to Jr SOC Analyst at IBM
Photo of the Rise User
Someone from OH, Cincinnati just viewed Recruiting Coordinator (Contractor) at Anduril Industries
Photo of the Rise User
Someone from OH, Dublin just viewed Field Support Technicians - (Phoenix) at Nordstrom
Photo of the Rise User
Someone from OH, Stow just viewed IT Asset administrator at Ergomed
Photo of the Rise User
Someone from OH, Loveland just viewed Senior Buyer (wholesale) (m/f/d) at ABOUT YOU SE & Co. KG
Photo of the Rise User
Someone from OH, Cincinnati just viewed Summer 2025 Internship: Talent at Hylant
C
Someone from OH, Cincinnati just viewed Senior Instructional Designer at CXG
Photo of the Rise User
Someone from OH, Youngstown just viewed Compliance Specialist, Anti-Corruption Program at ServiceNow
Photo of the Rise User
Someone from OH, Cleveland just viewed Finance Intern - Summer 2025 at Spectrum
Photo of the Rise User
Someone from OH, Cleveland just viewed QC Engineer at QODE
Photo of the Rise User
Someone from OH, Cleveland just viewed Getinge is hiring: UI/UX Developer in Streetsboro at Getinge
Photo of the Rise User
Someone from OH, Westerville just viewed Data analyst | Mid at Nord Security
Photo of the Rise User
Someone from OH, North Canton just viewed Researcher-NBC Sports at NBCUniversal
Photo of the Rise User
Someone from OH, North Canton just viewed Researcher-NBC Sports at NBCUniversal
Photo of the Rise User
Someone from OH, Lakewood just viewed Culture and Programs Analyst at City of Philadelphia