About the job
Menlo Security is dedicated to empowering individuals and organizations to connect, communicate, and collaborate securely without compromise. The urgency of this mission has only intensified in the wake of COVID-19. We proudly serve a diverse clientele that includes Fortune 500 companies, 9 out of 10 of the largest global banks, and the Department of Defense.
Our work environment has evolved significantly, and we are poised to expand from 400 employees to the next chapter in our journey. We are in search of passionate individuals who embody empathy and agility. The ideal candidate is ethical, exceptionally organized, dedicated to seeing tasks through to completion, service-oriented, and open to feedback while also confident in providing guidance to others.
Menlo Security is backed by leading investors, including Vista Equity Partners, General Catalyst, JPMC, American Express, HSBC, and Ericsson Ventures, which positions us well for growth.
Role Overview
We are looking for a proactive Senior Security Engineer to join our team, with a focus on both offensive and defensive security measures, conducting penetration tests on product features, and managing the cloud architecture that supports our offerings. This role will require you to navigate a complex multi-cloud environment (AWS & GCP) that encompasses both traditional virtual machines and modern container-based architectures.
In this specialized role, you will collaborate with fellow security engineers (including Penetration Testers and Cloud Security experts) to carry out targeted assessments during specific product testing phases just prior to release. Your success will depend on your ability to stay aligned with the product roadmap and gain in-depth technical knowledge of new features, allowing you to independently set up environments and conduct thorough tests within stringent timelines.
Your responsibilities will extend beyond application security to include comprehensive infrastructure reviews, ensuring that cloud configurations, IAM policies, and orchestration layers adhere to our security standards. Speed is crucial: you must quickly identify, validate, and report vulnerabilities to uphold our release cadence. Moreover, you will act as the first line of defense against external threats, monitoring bug bounty submissions and external reports to effectively triage and address findings with utmost professionalism.

