Staff Security Engineer
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 1d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 19d ago
The date the source published, not the day we noticed it (2026-09-21). Last seen at its source just now.
We have tracked this listing since 9 Oct 2026 (1 days). The employer's own board has carried it every time we have read it, most recently just now.
Is it remote?
Pasadena, California, United States; Remote; San Francisco, California, United States; Washington, District of Columbia, United States
That is the location the employer filed this posting under. Quoted as written — we do not re-word the source's own location.
Who may apply?
United States
The description states no restriction of its own. This is the source's own tag.
Pay
$175k–250k/yr
Read out of the job description by us, not from a structured field. Shown in the posting's own currency and period; we never convert.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
Greenhouse employer's own board first seen 1d ago · last seen just now
The listing
Primer exists to make the world a safer place. We do this by providing trusted decision-ready AI to the world's most critical organizations. Our software enables leaders, operators, and analysts to better understand the changing world around us in real time and make informed decisions when the stakes are high. Primer has offices in San Francisco, Pasadena, CA and Arlington, VA. For more information, please visit https://primer.ai/
As a Staff Security Engineer, you will be a valuable member of the IT and Information Security teams, managing and improving the organizational security posture. You will help protect sensitive data by implementing and continuously monitoring a secure cloud architecture. You will work with the security toolchain in cloud environments and support the development of security best practices and standards. Your responsibilities will also include managing vulnerability scanning and remediation efforts, responding to security alerts under supervision, and leading in root cause analysis. You will own the DAST and SAST solutions and be a key member of the incident response processes, tracking cyber actions from initial detection to final resolution.
Role Responsibilities - How You Will Make an Impact
- Analyze the organizational security posture and pursue improvements on a continuous basis
- Implement and manage security solutions and controls for cloud-based infrastructure, platforms, and applications
- Administer and harden identity and access management through Okta, including SSO, MFA, lifecycle automation, and conditional access policies. privilege IAM, network segmentation, and cloud security posture management(CSPM)
- Tighten theh the IT team to broaden the Zero Trust framework
- Collaborate with cross-functional teams, including DevOps, IT, and development teams, to integrate security into the software development lifecycle (SDLC) and DevSecOps practices
- Own remediation of security assessment findings and ensure identified control gaps are tracked, implemented, validated and documented through closure.
- K8s line to admission control, RBAC, pod hardening, and runtime sensors on EKS
- Own secure code review practices on GitHub, including branch protection rules, required status checks, GitHub Advanced Security (secret scanning, CodeQL,Dependabot), and pull request security gates.
- Build and maintain CI/CD pipelines with integrated security scanning (SAST, DAST,SCA, container image scanning) so vulnerabilities are caught before production.
- Lead and maintain SOC 2 (Type I/II) and CMMC compliance efforts: control implementation, evidence collection, audit readiness, and coordination with auditors.
- Run continuous vulnerability monitoring and management across cloud, endpoints, and applications, triaging findings and driving remediation with engineering teams against SLAs
- CrowdStrike Falcon end to end: EDR, incident response, detections and queries in NG-SIEM, Spotlight vulnerability program with reporting. AF, DDoS protection, DNS security, bot management, and Zero Trust network access.
- Maintain infrastructure as code (Terraform, CloudFormation/ARM/Bicep) with security policy-as-code checks baked into deployment pipelines.
- Monitor for security incidents, respond to alerts, and support incident response and root-cause analysis.
- Terraform in production: security posture on terraform-aws IAM, S3, ECR, and SG
- Scripting in Python or Go plus Bash. DAST automation, Okta sync, S3 auto-remediation, and CVE fixes in services
- Third-party risk: reviewing new vendors and tools before purchase, like the Pipl and CodePunch reviews
- Conduct security assessments and audits of cloud environments to identify and remediate security vulnerabilities and misconfigurations
- Respond to security alerts and conduct root cause analysis
- Perform incident response and track cyber actions from initial detection to final resolution
What We Are Looking For
- 10+ years of experience in Security and Cloud Operations
- Strong written and oral communication skills
- Hands-on experience with AWS and Azure
- Direct experience with intrusion prevention systems
- Experience with system logging and SIEM technologies
- Experience with cloud native security tools (e.g., IAM, WAF)
- Knowledge of incident response processes and practices
- Hands-on experience with vulnerability management tools, technologies, and methods
- Proven ability to integrate security practices into IT and/or DevOps environments
- Experience streamlining security processes
Nice To Have:
- Knowledge of Python and Golang
- AWS Certified Security – Specialty (or AWS Solutions Architect Professional)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500) or Cybersecurity Architect Expert (SC-100)
- ISC2 Certified Cloud Security Professional (CCSP) or CISSP
- Experience working with government customers, particularly within the U.S. Department of Defense (DoD) or other federal environments, including familiarity with government security and compliance requirements.
The annual cash compensation range for this position is US $175,000 to US $250,000. Final compensation will be determined based on experience and skills and may vary from the range listed above.
Primer works closely with the U.S. defense and intelligence establishment. Any offer of employment is conditioned on an applicant or employee being able to meet any applicable government contract requirements. The company may rescind any offer of employment to an applicant or terminate an employee if the applicant or employee is unable to perform the functions of the position in compliance with applicable government contracts or if an applicant or employee makes a false attestation of compliance.
What We Offer
We are a series D funded company with investors from Addition, USIT, Lux Capital, Amplify Partners, Addition Capital, Bloomberg Beta, and others. We are intentional around building a diverse and inclusive team of subject matter experts to better advocate for the needs of our users.
We care a lot about our work and about the well being of our team. We encourage everyone to work at a sustainable pace and have a flexible vacation policy for team members to utilize, Wellness Days and 100% paid leave for parents of growing families.
We offer competitive compensation and comprehensive benefits. This includes full medical, dental, and vision coverage, fertility benefits through Carrot, mental health coverage on demand with Headspace Care+, Gympass+ Membership via Wellhub, One Medical Membership, 401(k), remote work stipends, and monthly internet allowance.
Primer is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. Please see the United States Department of Labor's EEO poster and EEO poster supplement for additional information.
If you need assistance or accommodation due to a disability, you may contact us at info@primer.com.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.