Jobs and Careers
OL

Staff Security Engineer

Olo
New York City, United StatesRemotefull_timeVerifiedPosted 11 Dec 2024

About the role

Olo is a leading SaaS platform accelerating digital transformation in the restaurant industry by helping customers deliver more personalized and profitable guest experiences. As a result, our digital ordering, payment, and guest engagement solutions enable brands to do more with less and make every guest feel like a regular.
We are looking for a skilled security professional—be it an engineer, architect, or leader—with experience in Blue or Purple Team roles  to strengthen our defenses and safeguard the systems that allow people to order food quickly and securely. We want people who are passionate about identifying risks, analyzing data, and working collaboratively to develop effective strategic mitigation measures. Our mission is to reduce risk while fostering and supporting innovation.
Reporting to the Security Engineering Manager, the Staff Security Engineer will identify risks and transform them into opportunities for improvement while also having the opportunity to design and implement robust security measures that ensure the resilience of our systems while protecting the sensitive data of our clients and their customers. Our Team thrives on solving complex problems, supporting innovation, and making a real impact. Whether you’re passionate about threat detection, automation, or building secure-by-design systems, this is a place where your skills can truly shine.
You can work remotely from anywhere in the U.S. or at Olo’s headquarters in NYC. Olo employees are typically expected to be available 9am-6pm ET.

What You'll Be Doing

  • Define architectural and technology standards that impact information, system and data security across the organization.
  • Create and update security architecture diagrams and processes utilizing industry standard frameworks.
  • Write and contribute to architecture RFC documentation.
  • Coaches other engineers in how to develop security automation to further support our internal and cross-functional teams’ workflows.
  • Define and implement leading security practices for Kubernetes clusters, serverless architectures, API guidelines, and other dev-centric workloads. 
  • Secure AWS IAM and other AWS services using Terraform.
  • Perform POV/POC evaluations of tooling and provide recommendations based on cost/benefit analysis and risk posture.
  • Proactively investigate atypical traffic, logs, and supporting data to introduce new and improved security mitigations.
  • Lead the team in all areas within incident response including: triage, investigation, and management as an incident commander.
  • Train other engineers in how to best evaluate and tune dashboarding, monitors, and alerting for security-related events while improving operational efficiencies. 
  • Set an example in excellent white-glove service across teams and stakeholders - resolving security support requests, delivering initiatives, and managing day-to-day business operations while mentoring and supporting other engineers. 
  • Drive the implementation of new technologies, processes, and automation of security activities. 
  • Develop highly available, scalable, secure solutions that exceed our internal and external customer needs.
  • Collaborate cross-functionally, with customers, and with external third-parties to help introduce appropriate risk mitigation controls while influencing stakeholders towards more risk averse approaches.
  • Build out and contribute to supporting documentation and runbooks.

What We'll Expect From You

  • Blue Team, Security Operations, Security Engineering, Security Architecture, DevOps or Operations experience.
  • Experienced with development and leading of a threat hunting program.
  • Experience with mentoring and leading members of the security team for incident response, threat detection, and threat hunting activities.
  • Experience with developing and leading the strategy and implementation of security automation and orchestration for incident response.
  • Proven experience developing and leading incident response, remediation and mitigation activities, and providing status updates and reports.
  • Experience with Kubernetes, container, and other microservices technologies
  • Experience architecting, deploying, maintaining and administering security technologies. (e.g. Anti-Malware, Intrusion Detection System (IDS), Data Leak Prevention (DLP), File Integrity Monitoring (FIM), Firewalls, Security Information and Event Monitoring (SIEM), Static Inspection, Multi Factor Authentication (MFA), Vulnerability Assessment, Web Proxies and Web Application Firewalls (WAF))
  • Experience with cloud providers and Infrastructure-as-Code (IAC) (e.g., Terraform, Ansible, CloudFormation or similar).
  • Proficient with AWS security best practices.
  • Experience with automation, develop

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Olo

View company profile →