This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
NetBox Labs is seeking a Senior Security Engineer with a strong DevSecOps mindset to lead the technical backbone of our security program - bringing together automation, infrastructure security, and proactive threat detection. This hands-on role will architect and operate systems that secure our code, cloud, supply chain, and collaboration environments, driving visibility, resilience, and trust across everything we build.
Job Responsibility:
Enable and guide teams to adopt DevSecOps practices, ensuring security is built into CI/CD and infrastructure pipelines through shared standards, tooling, and best practices
Work with IT Manager on company identity and access management: IdP configuration, user/group organization, and automation via cross-platform synchronization and SAML
Administer and automate GitHub Enterprise and JFrog management (users, teams, org policies, and compliance) using IaC
Operate and tune SIEM, DLP, and centralized logging systems
define and maintain detection and alerting rules
Review audit logs and security telemetry across cloud, SaaS, and developer systems for anomalies and compliance issues
Work with IT Manager to build automated onboarding/offboarding and access reviews aligned with least-privilege principles
Collaborate with platform, product, and engineering teams to design secure-by-default workflows, infrastructure, and deployment practices, ensuring consistent security controls across products
Conduct risk assessments, tabletop exercises, and threat simulations in concert with engineering and operations teams, ensuring security readiness is collaborative and integrated
Lead and coordinate penetration testing efforts, including scoping, vendor engagement, and remediation tracking
Support SOC 2 and related compliance efforts through control validation and evidence collection
Help respond to and complete customer and vendor security questionnaires, collaborating with compliance and engineering teams to ensure accurate and timely answers
Requirements:
5+ years in security, IT, DevSecOps, or platform engineering roles
Deep understanding of identity management, SSO, and federation (Google Workspace, Okta, Auth0, OIDC/SAML)
Experience managing and automating users, groups, org policies, and compliance controls on systems like AWS, GCP, GitHub Enterprise, and JFrog
Experience implementing and improving software supply chain security, including integrating security into CI/CD pipelines (e.g., GitHub Actions)