Job Description
Job Description
Description :
Do you see threats where others see business as usual—and love turning that sixth sense into concrete defenses? We’re looking for a Security Engineer to guard every layer of RTA’s tech stack and culture. Reporting to our Head of Infrastructure & SRE, you’ll shape policies, stand up tooling, and partner with every department to keep our customers’ fleets—and our reputation—safe. If you can translate “zero-day” into plain English, herd vulnerability scans like a pro, and still crack a smile over coffee-break memes, you might be the peanut butter to our jelly. Read on and apply!
What We’re Looking For
We’re looking for a service minded protector who measures success by how secure and empowered others feel, and who is comfortable with healthy conflict without having thin skin. This person should embody being humble, hungry, and smart in the Patrick Lencioni sense, and be a true hands-on doer who can write a policy in the morning and script a GuardDuty alert after lunch. They need to be a team player who is just as willing to lift boxes, clean floors, or hold doors if that is what it takes to get the job done.
Specifically for This Role, Someone Who
- Is a security thought-leader. Owns projects, tasks and can assess the right solutions for the right job. Also can personally execute and deliver sustainable enhancements to strengthen security postures.
- Has solid experience hardening AWS environments (VPCs, Security Groups, IAM, GuardDuty).
- Runs endpoint security with tools like SentinelOne and tunes a Kroll (or similar) SIEM for signal over noise.
- Translates complex security security threats into understandable remediations, while communicating the potential risk level, likelihood and impact.
- Manages Qualys (or equivalent) scans, tracks remediation, and coordinates annual external vulnerability & penetration tests.
- Implements and maintains SAST / DAST pipelines to catch issues before they ship.
- Drives patch management (e.g., WSUS for Windows) and assesses third-party dependencies for risk.
- Leads SOC 2 (and future frameworks) evidence gathering, controls mapping, and auditor wrangling.
- Partners with development teams to incorporate security scanning and vulnerability assessment within CI / CD pipelines.
- Champions the Security-as-a-Service mindset of utilizing repeatable processes, automation and solution sustainability.
- Develops easy-to-follow policies, runs security awareness training, and communicates risk in plain language to execs and engineers alike.
Key Responsibilities
Hunt & Fix : Own the vulnerability-management cycle : Qualys scans, prioritization, and verification of fixes across cloud and on-prem assets.Protect & Detect : Deploy, fine-tune, and monitor SentinelOne, GuardDuty, SIEM dashboards, and log pipelines.Automate & Integrate : Embed SAST / DAST checks into CI / CD (GitHub Actions) and champion “security as code.”Govern & Guide : Write, update, and socialize security policies and playbooks that are actually readable.Comply & Report : Shepherd yearly SOC 2 evidence, coordinate external pen-tests, and deliver clear metrics to leadership.Educate & Collaborate : Run lunch-and-learns, tabletop exercises, and partner with Product, Engineering, and Support so security is everyone’s job.Bonus Points : AWS Certified or related, CISSP, SSCP, CCSP, OSCP, CEH, or comparable.Tools : Terraform / CloudFormation for secure IaC, experience with Kubernetes RBAC, or prior work in regulated environments (PCI, HIPAA, etc.).Qualifications
5+ years in security engineering, cloud security, or a closely related field.
Demonstrated track record securing AWS workloads and modern DevOps pipelines.
Excellent written & verbal communication
The Bottom Line
We want an ideal team player with an almost frightening intensity around customer service and a passion for protecting others. If you’re ready to keep RTA’s mission rolling safely—and have some fun doing it—click apply! We’ve asked you four times now, and you’re still reading—bonus points for being thorough. Time to be the Pepper to our Potts and make our security posture unbeatable.
#LI-AE1
Requirements :