Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Engineer image - Rise Careers
Job details

Security Engineer

At Instructure, we empower people to grow and succeed by creating intuitive products that simplify learning, facilitate meaningful relationships, and inspire innovation. We are revolutionizing how educational institutions manage and access their data to enhance teaching and learning. As a key contributor to the Security organization, you'll be focused on engineering initiatives across all of Instructure's products and services.


As a Security Engineer, you will be responsible for designing, implementing, and maintaining security tooling to protect our SaaS platform. You will also work closely with cross-functional teams to identify and address vulnerabilities, implement best practices, and ensure compliance with industry standards. This role is critical in upholding the trust of our customers and partners.


What you will be doing:
  • Infrastructure Security
  • Ensure secure configurations of cloud environments (e.g., AWS).
  • Develop and maintain infrastructure-as-code (IaC) security practices.
  • Design, implement, deploy, and maintain security tooling.
  • Oversight and management of  CNAPP platforms
  • Responsible for deployment, management, and maintenance of zerotrust platform(s) and supporting an overall zerotrust philosophy architecture and culture. 
  • Application Security:
  • Using static code analysis, dependency vulnerability scanning tools (Snyk) to identify and remediate vulnerabilities in application code. 
  • Management of CICD pipeline controls using Git (Github Actions) for enforcement of security controls. 
  • Collaborate with developers to identify and mitigate vulnerabilities in the software development lifecycle (SDLC).
  • Perform code reviews and provide guidance on secure coding practices.
  • Manage third-party dependency packages and container images for security and patching processes.
  • Perform vulnerability prioritization analysis based on severity and impact. 
  • Perform testing and validation application vulnerability patches. 
  • Security Operations 
  • Help build, maintain, and improve Security Orchestration and Automated Response (SOAR) practices to auto-remeidate and enrich security events. 
  • Responsible for building security altering based on relevant Indicators of Compromise (IoC) using log aggregation tools (Splunk, Observe, Sumologic) 
  • Activity participate in investigations and incident response activities, including being part of the incident response team, investigating alerts, and working with cross functional teams to resolve any active attacks or potential threats. 


Qualifications:
  • Ability to work effectively on a remote team in a collaborative, fast-paced, and dynamic environment.
  • Strong communication skills, with the ability to convey technical concepts to both technical and non-technical stakeholders.
  • A polite, professional demeanor and a commitment to fostering a positive and respectful workplace.


Required Experience & Skills:
  • Excellent problem-solving and critical-thinking skills.
  • Willingness to learn on the job and work outside of your comfort zone.
  • 3+ years of experience in a security engineering role or similar application engineering role.
  • Proficiency in securing cloud environments (AWS).
  • Strong familiarity with DevSecOps and CI/CD pipeline security.
  • Hands-on experience with security tools such as vulnerability scanners and code analysis tools. 
  • Understanding of OWASP Top 10 and overall secure application development principals. 
  • Working understanding of networking, encryption, authentication protocols, and secure application development.


Preferred Skills & Experience
  • Fluency in development languages like Java, JavaScript, Ruby, Ruby on Rails, etc  
  • Certifications such as CISSP, CEH, OSCP, or AWS Security Specialty.
  • Experience with container security (e.g., Docker, Kubernetes).
  • Knowledge of scripting languages (e.g., Python, Bash) for automation.
  • Knowledge of security frameworks (e.g., NIST, OWASP, CIS Benchmarks).
  • Contributions to open-source projects.
  • Hands-on experience with security tools such as SIEM, IDS/IPS, firewalls, and vulnerability scanners.


Get in on all the awesome at Instructure.
  • Competitive salary and 401k.
  • Medical, dental, disability, and life insurance.
  • HSA program, vision, voluntary life, and AD&D.
  • Tuition reimbursement.
  • Paid time off, 11 paid holidays, and flexible work schedules.
  • LifeStyle Spending Account


$100,000 - $185,000 a year
Depending on experience.

We’ve always believed in hiring the most awesome people and treating them right. We know that the more diverse we are, the more diverse our ideas will be and when we openly welcome those ideas, our environment is better and our business is stronger.

 

All Instructure employees are required to successfully pass a background check upon being hired.

Instructure Glassdoor Company Review
3.3 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Instructure DE&I Review
3.5 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of Instructure
Instructure CEO photo
Steve Daly
Approve of CEO

Average salary estimate

$142500 / YEARLY (est.)
min
max
$100000K
$185000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Engineer, Instructure

Join the amazing team at Instructure as a Security Engineer, where we empower individuals to grow and succeed by crafting user-friendly products that simplify learning and foster innovation! You'll dive deep into protecting our SaaS platform with your expertise, ensuring the security of our cloud environments like AWS. Your role will focus on designing and implementing robust security toolings, identifying vulnerabilities, and besting industry standards for compliance. In this remote position, you will collaborate with various teams to maintain a zero-trust philosophy and ensure secure software development lifecycles. You're not just creating secure systems; you are building trust with our customers and partners, and that's a critical mission! If you have a knack for problem-solving and some experience in security engineering or application engineering, this might be the perfect opportunity for you to grow your skills and contribute to a dynamic environment. Get ready to take charge in security operations by enhancing our security protocols and automating responses to incidents. With fantastic benefits, a competitive salary ranging from $100,000 to $185,000 based on experience, and a culture that celebrates diversity and creativity, Instructure is where you can truly shine. Ready to embark on this exciting new journey?

Frequently Asked Questions (FAQs) for Security Engineer Role at Instructure
What are the primary responsibilities of a Security Engineer at Instructure?

As a Security Engineer at Instructure, your role encompasses designing, implementing, and maintaining security tooling to protect our SaaS platform. You'll ensure secure configurations of our cloud environments, manage third-party dependencies, conduct code reviews, and collaborate closely with development teams to strengthen our security protocols throughout the software development lifecycle.

Join Rise to see the full answer
What qualifications are needed to become a Security Engineer at Instructure?

To thrive as a Security Engineer at Instructure, you'll need at least 3 years of experience in a similar role. Familiarity with securing cloud environments, specifically AWS, DevSecOps, and CI/CD pipeline security are crucial. Additionally, strong problem-solving skills, communication abilities, and a commitment to continuous learning are essential for this position.

Join Rise to see the full answer
How important is collaboration in the Security Engineer role at Instructure?

Collaboration is key for a Security Engineer at Instructure. Working closely with cross-functional teams, you'll identify and address vulnerabilities, ensuring a secure development environment. Your ability to convey technical concepts to both technical and non-technical stakeholders enhances teamwork and strengthens our security posture across the organization.

Join Rise to see the full answer
What tools does a Security Engineer at Instructure use?

Instructure's Security Engineers utilize various tools, including vulnerability scanners like Snyk, code analysis tools, CI/CD security management tools, and log aggregation tools such as Splunk and Observe. These tools help in identifying vulnerabilities, managing incidents, and automating security measures effectively.

Join Rise to see the full answer
What benefits does Instructure offer to its Security Engineers?

Instructure offers an attractive benefits package for its Security Engineers, including a competitive salary range of $100,000 to $185,000, medical and dental insurance, a 401k plan, tuition reimbursement, paid time off, and flexible schedules. This supportive environment ensures that you can thrive both personally and professionally while working remotely.

Join Rise to see the full answer
Common Interview Questions for Security Engineer
Can you describe your experience with securing cloud environments?

When answering this question, focus on specific projects where you've secured cloud environments like AWS. Discuss the strategies you used, such as implementing security best practices, monitoring for vulnerabilities, and managing compliance with industry standards.

Join Rise to see the full answer
How do you approach vulnerability management in the CI/CD pipeline?

Outline your process for integrating security into the CI/CD pipeline, mentioning tools you’ve used for scanning and remediation. Emphasize the importance of early detection and continuous monitoring of vulnerabilities throughout the development lifecycle.

Join Rise to see the full answer
What are some common security vulnerabilities you encounter in application code?

Discuss common vulnerabilities like SQL injection, cross-site scripting (XSS), and insecure direct object references. Explain how you identify these through static and dynamic analysis tools, and how you guide developers to fix them.

Join Rise to see the full answer
How do you ensure compliance with security standards?

Talk about your approach to maintaining compliance, which may include regular audits, aligning with frameworks like NIST or OWASP, and implementing security policies that adhere to industry standards while fostering a culture of security within the team.

Join Rise to see the full answer
Can you give an example of a significant security incident you managed?

Be prepared to describe a real incident, detailing the steps you took in investigation, mitigation, and communication. Highlight the lessons learned and how it influenced future security protocols or practices.

Join Rise to see the full answer
What tools and frameworks are you proficient in?

List specific tools relevant to security engineering, such as SIEM, vulnerability scanners, and any programming or scripting languages you’re familiar with. Explain how you've used them to enhance security measures in previous roles.

Join Rise to see the full answer
How do you stay updated on the latest security threats and trends?

Share your strategies for staying informed, like following industry blogs, participating in professional forums, attending webinars and conferences, and studying new compliance regulations and security strategies.

Join Rise to see the full answer
What strategies do you use to promote a security-first mindset in development teams?

Discuss your approach to fostering a security culture through training, regular code reviews, and creating open lines of communication to discuss security concerns. Highlight how collaboration improves both security and overall product quality.

Join Rise to see the full answer
How do you handle external dependencies' security?

Talk about your process of auditing and managing third-party libraries and dependencies, emphasizing the use of tools for checking for vulnerabilities and the importance of regularly updating these dependencies to mitigate risks.

Join Rise to see the full answer
Why do you want to work at Instructure as a Security Engineer?

Craft a response that connects your values with Instructure’s mission to enhance learning through technology. Discuss how you can contribute to their security initiatives and why you’re excited about being part of a company focused on empowering growth through innovation.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Instructure Remote Remote from Washington, Oregon, Idaho or Montana, United States
Posted 5 days ago
Health Savings Account (HSA)
Dental Insurance
Vision Insurance
Disability Insurance
Flexible Spending Account (FSA)
Family Medical Leave
Paid Holidays

Join Parchment as a Regional Sales Manager to lead new sales in the Northwest for our education technology suite.

Photo of the Rise User
Posted 5 days ago
Health Savings Account (HSA)
Dental Insurance
Vision Insurance
Disability Insurance
Flexible Spending Account (FSA)
Family Medical Leave
Paid Holidays

Instructure seeks an experienced Senior Account Executive to drive sales in their K-12 software solutions across Washington, Oregon, and Arizona.

Posted 2 hours ago

Join CommonSpirit Health as an IT Technical Analyst to enhance healthcare services through technology.

Photo of the Rise User

Join Visa as a Cybersecurity Engineer to work in Network Security Monitoring and help enhance their security tools.

Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Slip Robotics Remote No location specified
Posted 4 days ago

Join Slip Robotics as an IT Manager - ERP Systems and help shape the future of logistics through innovative automation solutions.

Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
City and County of San Francisco Hybrid San Francisco International Airport, San Francisco, CA, United States
Posted 6 days ago

Join SFO as a Senior ITT Manager to lead technology services for enhanced airport operations.

Photo of the Rise User
Posted 5 days ago

Join Credit Genie as a Senior Security Engineer to safeguard our financial wellness platform while working in a collaborative environment.

Our mission is to inspire everyone to learn together. We work toward this goal by focusing on openness, relationships, equality, ownership, and simplicity. These values apply across the board: to our software and services; our coworkers, customers...

177 jobs
MATCH
Calculating your matching score...
BENEFITS & PERKS
Health Savings Account (HSA)
Dental Insurance
Vision Insurance
Disability Insurance
Flexible Spending Account (FSA)
Family Medical Leave
Paid Holidays
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 2, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!