remote
Senior Software Security Engineer - Everlaw
Security Engineer
Lead the technical security team to protect customer data by designing secure architectures, conducting threat modeling, and integrating security into CI/CD pipelines using Python and AWS services.
About the role
Key Responsibilities
- Design and implement security controls for the Everlaw platform, focusing on data confidentiality, integrity, and availability.
- Conduct threat modeling and risk assessments for new features and major architectural changes.
- Develop and maintain security automation scripts and tools, primarily using Python, to integrate security checks into CI/CD pipelines.
- Collaborate with engineering, product, and operations teams to embed security best practices throughout the software development lifecycle.
- Respond to security incidents, perform root‑cause analysis, and drive remediation efforts.
Requirements
- 5+ years of experience in application security or security engineering, preferably in a SaaS environment.
- Strong knowledge of cloud security concepts and hands‑on experience with AWS security services.
- Proficiency in Python for building security tooling and automation.
- Demonstrated experience with threat modeling, secure code review, and vulnerability management.
- Familiarity with DevSecOps practices and integrating security into CI/CD workflows.