Senior Security Operations Engineer - (Hybrid)
HomebaseAbout the role
Hi, Future Homie!
As a Homie, you'll be part of an unstoppable team that puts customers first, embraces each day with excitement, and strives for excellence in everything you do. We’re revolutionizing the way small businesses manage their teams and grow their business. What this means for you is a shared passion for innovation and making a difference for the people we serve. So what do you say, will you join us on our mission to empower small businesses?
As a Security Engineer specializing in Operations and Cloud, you will be a critical member of our Homebase Trust and Security team, significantly contributing to the security and resilience of our cloud environments and operations. Reporting directly to the Security Engineering Manager, you will play a pivotal role in designing, implementing, and managing security solutions that protect our systems and data. You will be responsible for leading and executing a comprehensive security operations and cloud security program. We are seeking a highly skilled and motivated individual with a strong background in operations and cloud security. You will work closely with other security team members, infrastructure, and engineering teams to identify, assess, and mitigate security risks, ensuring that our infrastructure is secure, compliant, and aligned with industry best practices.
Our Trust and Security team is a critical component of our organization, dedicated to safeguarding our systems, data, and customers. We have a broad scope of responsibilities encompassing application security, security operations, governance, risk, and compliance (GRC), and corporate security. Collaborating closely with internal and external stakeholders, we are committed to delivering exceptional security and quality services and products. By upholding the highest standards, we ensure the protection of our customers' trust and confidence.
You will make an impact by
Security Operations
- Leading and maintaining our security operations and cloud security programs.
- Managing security monitoring and alerting systems.
- Developing automated response systems to streamline the detection, investigation, and remediation of security threats.
- Designing and implementing security policies and training.
- Taking a leading role in developing and overseeing the Security Incident Response Team (SIRT), acting as the primary security incident response commander to identify, manage, and mitigate security incidents.
- Joining the Security team's on-call rotation, responding to security incidents.
- Building and developing a threat intelligence program by collecting, analyzing, and sharing insights to proactively defend against emerging threats.
- Leading the project to establish a Security Information and Event Management (SIEM) system and coordinate with a managed service provider to externalize the Security Operations Center.
- Collaborating with engineering and infrastructure teams to develop and maintain comprehensive Business Continuity (BC) and Disaster Recovery (DR) plans, ensuring resilience in the face of disruptions.
Cloud Security
- Ensuring compliance with regulatory requirements and industry standards.
- Serving as the go-to expert in cloud security, providing guidance and support to the team and ensuring our cloud infrastructure remains secure.
- Continuously stay informed about industry trends, best practices, and regulatory updates, adapting our security strategies as needed.
- Embedding security best practices into the Software Development Life Cycle (SDLC) to ensure secure deployment of our applications.
- Establishing and monitoring key performance indicators (KPIs) and key risk indicators (KRIs).
- Developing and executing an internal audit plan to ensure compliance and identify opportunities for security enhancement.
- Contributing to the security architecture review program.
- Using modern approaches like “secure by default” and “zero trust” to build long-lasting, secure environments for our team and developers.
- Implementing stringent security hardening practices across our cloud environments.
- Working with the infrastructure team on secure network architectures, credential management, and network security tools like IDS/IPS, WAF, and DDoS solutions to monitor and block malicious activities
- Implementing cloud vulnerability scanning processes and enhancing vulnerability management.
- Working with engineering and infrastructure teams on logging and audit standards.
You are a bar raiser, which means you come with
- Proven experience managing AWS security.
- Experience in programming languages (Python, JavaScript, Ruby, or similar.)
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s