Jobs and Careers
CO

Senior Security Engineer

CompanyCam
Remote (U.S.), United StatesRemotefull_timeVerifiedPosted 25 Apr 2025
💰 $170,000/yr($130,000/yr$170,000/yr)

About the role

Hi, we’re CompanyCam.

We’re a simple-to-use photo documentation and productivity app for contractors of all commercial and home services industries. Packed with intuitive functionality, CompanyCam facilitates unparalleled communication and accountability across a contractor’s entire business. We’re committed to providing a consumer-grade, game-changing experience that helps our users build trust within their company and with their customers.

But don’t let that corporate description fool you—the people behind our buttoned-up product are laid-back (but hardworking), genuine, and kickass, and you could be one of them! 

The Role

We’re seeking a Senior Security Engineer to drive security engineering and compliance initiatives across our app. In this role, you'll partner with engineering teams to design, implement, and automate security controls that meet rigorous compliance standards (SOC 2, GDPR, and CCPA). You’ll own security architecture decisions, vulnerability management, and lead efforts to ensure that we stay ahead of evolving threats.

If you're passionate about scalable security engineering, proactive compliance, and empowering developers to ship secure products, we want to hear from you.

Location: Candidates must permanently and currently reside in the United States. Employees are not required to work in the office or relocate to Lincoln, Nebraska, for this opportunity, but occasional travel to HQ will be required.

Working At CompanyCam

Our engineering team is remote-first, spanning every time zone in the United States. We welcome people from all backgrounds and really don't care whether or not you have a CS degree or even a high school diploma. All that matters is that you're not an a**hole and you're good at what you do.

At CompanyCam we’re driven to produce work with meaningful outcomes. That means not just dumping features and “improvements” but being able to reflect and learn from our outputs. We’re actively working to center our work on continuous discovery habits (CDH) as outlined by Teresa Torres.

Okay, that’s how we identify work to do, but how do we actually work? We take a flexible approach, pulling from Agile, Sprints, Kanban, and even Shape Up. Rather than being overly prescriptive, we provide guardrails and just enough constraints to keep teams moving. Each team is expected to collaborate, iterate, and refine their best practices to produce high-quality work.

Our teams are made up of a product manager, a product designer, a QA engineer, a senior developer and an appropriate number of engineers for the scope of your team. We also believe in intentional downtime. After delivering projects, we carve out explicit time for teams to recoup, explore self-directed work, and focus on what matters to them—whether that’s learning new skills, tackling pet projects, or finally fixing that bug that’s been nagging you.

We protect our engineers' time, treat them like adults, and trust them to get their work done. We’re also big on not overworking people. Put in your eight hours of focused, quality work and then TURN. SLACK. OFF. No nights and weekends.

What You’ll Do

  • Create or contribute to tooling that supports secure code delivery and infrastructure as code validation
  • Design and enforce access control mechanisms aligned with least privilege and segregation of duties across infrastructure, applications, and data layers
  • Provide guidance on security best practices for product, platform, and infrastructure teams to align development with compliance requirements
  • Partner with product and engineering to ensure appropriate handling of sensitive data, including encryption, retention, and secure deletion policies
  • Build automated playbooks for security incident response and partner with teams on real-world incident handling
  • Conduct proactive threat detection and response activities, including investigation and forensics as needed
  • Maintain visibility into third-party and supply chain risks through vendor assessments and open source review
  • Report on vulnerability trends and remediation metrics across environments
  • Lead compliance-related training initiatives, ensuring teams understand security policies and regulatory requirements
  • Contribute to security education for engineers through documentation, secure development guidance and internal training.

What You’ll Bring

  • 5+ years of hands-on experience in a security engineering or infrastructure security role
  • Strong experience with cloud-native platforms (AWS preferred)
  • Hands-on with

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CompanyCam

View company profile →