This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The senior security engineer role provides a unique opportunity to shape the security and resilience of GoodLeap systems, services, and operational processes. In this role, you will work closely with product, engineering, IT, and business teams within GoodLeap to design, build, implement, and operate security and fraud monitoring, detection, and response capabilities.
Job Responsibility:
Lead, participate in, and contribute to security and fraud monitoring, detection, and response activities, inclusive of investigations, threat hunting,etc. Create playbooks for specific incident response scenarios
Identify potential misuse and abuse cases in enterprise systems, propose solutions to detect these scenarios, and identify and implement monitoring and detection solutions for such scenarios
Support or develop components of the security analytics platform
Support embedded (product) security team
Support general security operations team with vulnerability management, tools management, and more
Requirements:
Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences
Expertise with EDR solutions/platforms, such as CrowdStrike, S1, Palo Alto Cortex EDR
Experience with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus)
Proven ability to establish credibility and build trust with business, engineers, and operational staff
Experience designing, configuring, and implementing security and fraud monitoring for core enterprise systems, e.g., ERP, HCM, Salesforce
Experience working with and creating solutions based AI and ML toolsets – e.g., creation of AI skills, agents, MCP clients, vibe coding
Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases
Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK
GitHub and GitHub Actions
artifact management
and secrets management tools like Doppler and HashiCorp Vault
Passionate about learning new technologies
Prior experience interfacing and supporting teams outside of security – e.g., internal product teams and other cross-functional areas
Proficiency in writing automation scripts in multiple languages and integrating with REST/GraphQL APIs to orchestrate workflows between security tooling and third-party cloud/SaaS platforms, automating detection, response, and operational processes
Experience engaging with vendors in design partnerships
Experience overseeing vulnerability and threat management at the platform and application levels
Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement
Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution