JOBSEARCHER

Senior Security Engineer

LaterMillbrae, CAL6 LeadSeptember 22nd, 2026
Overview As a Senior Security Engineer at Later, you strengthen company-wide security through hands-on engineering and cross-functional collaboration. You’ll embed security into products, pipelines, and operations, focusing on application, cloud, and infrastructure security, vulnerability management, and compliance readiness. You’ll partner with engineering, product, IT, legal, and business teams to mature SOC 2 and related controls with automated, evidence-ready processes. This role blends defender mindset with software engineering skills to drive measurable security improvements at scale. Compensation / Benefitssalary ranges disclosedremote-friendly optionsoffice locations in Boston, MA; Vancouver, BC; Vancouver, WAparticipation in benefits plansdiversity and inclusion commitmentequal opportunity employer ResponsibilitiesAssess and improve security posture across apps, cloud, and corporate systemsDefine scalable security standards and guardrails aligned with SOC 2 readinessTranslate compliance requirements into technical controls and evidence practicesIdentify gaps, prioritize remediation, and guide risk-based decisionsBuild internal security tools and automation to support compliance, vulnerability management, and security operationsDesign and implement secure CI/CD patterns, including dependency management and secret handlingSupport application security through threat modeling, reviews, and remediation planningImprove cloud and corporate security via hardening, IaC scanning, and access reviewsEnhance security observability, logging, alerting, and incident response maturityCollaborate with teams to communicate risks and embed security into workflows without slowing deliverySupport SOC 2 and related compliance with automated controls and evidence practices Key requirements5-7+ years of security or software engineering with a security focusProven ability to build/operate production-quality software, automation, and internal toolingStrong knowledge of application, infrastructure, cloud security, CI/CD security, and corporate controlsHands-on experience with vulnerability management, threat modeling, and remediation workflowsFamiliarity with frameworks like OWASP, NIST, CIS Controls, SOC 2, ISO 27001 and applying them in productionExperience supporting SOC 2 compliance with automated, auditable controlsFamiliarity with cloud security platforms (AWS, Azure, GCP), SIEM/SOAR, logging/monitoringIaC security scanning (Terraform, CloudFormation)Ability to translate complex security concepts for technical and non-technical audiencesExperience collaborating with engineering, IT, compliance, and business teamsFamiliarity with C#, modern backend systems, cloud-native architecture, and SaaS toolingcollaborativecommunicationproblem-solvingapplication securityinfrastructure securitycloud security