Retour à la recherche
Logo de Federato
FederatoSource d’offres vérifiée

Senior Security Engineer

Offre en anglais
  • Sur place
  • Publié 3 juin 2026
  • 1 poste

180 000 $ US–225 000 $ US / année

Ouvre un site externe

Connectez-vous pour enregistrer ce poste
Type d’emploi
Temps plein
Niveau d’expérience
Expérimenté · 5+ ans

Résumé du poste

Federato [https://www.federato.ai/] is on a mission to defend the right to efficient, equitable insurance for all. We enable insurers to provide affordable coverage to people and organizations facing the issues of today - the climate crisis, cyber-attacks, social inflation, etc. Our vision is understood and well funded by those behind Salesforce, Veeva, Zoom, Box, etc. Federato is the only AI-native platform that spans the full policy lifecycle and changes the way insurance work gets done. Better decisioning is built-in, not bolted on: insurers' unique portfolio goals, strategies, rules, and…

Détails du poste

Federato [https://www.federato.ai/] is on a mission to defend the right to efficient, equitable insurance for all. We enable insurers to provide affordable coverage to people and organizations facing the issues of today - the climate crisis, cyber-attacks, social inflation, etc. Our vision is understood and well funded by those behind Salesforce, Veeva, Zoom, Box, etc. Federato is the only AI-native platform that spans the full policy lifecycle and changes the way insurance work gets done. Better decisioning is built-in, not bolted on: insurers' unique portfolio goals, strategies, rules, and appetite are part of the workflow so underwriters win the right deals, faster. From the moment a submission hits an underwriter’s inbox, AI is put to work, triaging submissions with a focus on high-appetite business, delivering real-time feedback on the portfolio, and consolidating workflows into a single proven system. Federato drives better business outcomes. WHAT YOU'LL DO * Contribute to our application security program. Work with our SAST, DAST, and SCA tooling, triage and prioritize vulnerabilities, and partner with engineering teams to drive remediation. Participate in threat modeling and secure design reviews on new products and services. * Share incident response on-call. Investigate, contain, and resolve security incidents alongside the rest of the team. Help refine our runbooks, detection coverage, and post-incident process. * Help harden our cloud and Kubernetes environment. Contribute to security posture across GCP and GKE: IAM and least-privilege, secrets management, container and supply chain security, and IaC guardrails (Terraform). * Build detections and security automation. Engineer high-signal detections from cloud, identity, and application telemetry. Automate the toil of vuln triage, access reviews, SaaS posture, questionnaire workflows so the team scales. * Streamline customer security work. Help respond to customer security questionnaires and audits, and build internal tooling and a knowledge base so this scales as deal volume grows. * Strengthen business continuity and DR. Help assess threats to continuity, contribute to DR plans, and run real exercises against them. * Help drive a security culture across engineering. Pair on developer training, secure-coding guidance, and standards work to make the secure path the easy path. Who We Hope You Have: * 5+ years of hands-on experience managing cloud infrastructure and automation. * Experience in achieving SOC2 Type II, ISO 27001, or similar certifications * Experience with Node.js or Python for backend services in a microservices architecture. * 3+ years of experience with cloud providers, preferably Google Cloud Platform (GCP). * Solid experience with cloud security on GCP or AWS, including IAM, Kubernetes, and IaC. * Knowledge of asynchronous processing, message queues (e.g., Kafka, Pub/Sub), and event-driven architecture for backend applications. * Experience focused on the internal engineer team success $180,000 - $225,000 a year Final offer amounts are determined by multiple factors including candidate location, experience and expertise and may vary from the amounts listed above. Total compensation package does include stock options, benefits and additional perks. Here at Federato, your capabilities are important, but culture fit is essential. We move fast, are eager to listen to our users, take a first principles approach to solving problems, and value learning and the ability to change our minds. Most importantly, we're here to have fun. Our ability to make a difference starts with our people. We would love to work with you! We are an equal-opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender expression, sexual orientation, age, marital status, veteran status or disability status. We will provide reasonable accommodation to individuals with disabilities to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation at talent@federato.ai [talent@federato.ai]

Ce que vous ferez

Contribute to the application security program by managing vulnerability tooling, performing threat modeling, and handling incident response. Harden cloud and Kubernetes environments while building security automation and detections to scale operations.

Exigences

Requires 5+ years of experience in cloud infrastructure and automation, with at least 3 years specifically in GCP. Proficiency in Node.js or Python and experience with security certifications like SOC2 or ISO 27001 is expected.

Avantages

• Stock Options • Benefits • Additional Perks

Compétences indiquées

  • Kubernetes · Souhaitée
  • Node.js · Souhaitée
  • API REST · Souhaitée
  • Zoom · Souhaitée
  • management · Souhaitée
  • Process · Souhaitée
  • Eager · Souhaitée
  • Amazon Web Services · Souhaitée
  • Google Cloud · Souhaitée
  • Salesforce · Souhaitée
  • Customer · Souhaitée
  • Python · Souhaitée

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Application Security
  • SAST
  • DAST
  • SCA
  • Threat Modeling
  • Incident Response
  • Cloud Security
  • Kubernetes
  • GCP
  • Terraform
  • Node.js
  • Python
  • IAM
  • SOC2 Type II
  • ISO 27001
  • Event-Driven Architecture

D’autres postes auxquels postuler directement

Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.

Voir tous les postes à candidature simplifiée