CrawlJobs Logo

Senior Engineer, Application and Security Infrastructure

strava.com Logo

Strava

Location Icon

Location:
United Kingdom , London

Category Icon

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

93500.00 - 110000.00 GBP / Year

Job Description:

This role is on the Strava Security Team, which exists to protect Strava’s people, business, and data through integrated, proactive security practices. We work across all security domains, including, but not limited to, product security, vulnerability management, incident response, infrastructure, network, governance, and enterprise security.

Job Responsibility:

  • Protect a platform that supports millions of athletes by ensuring Strava’s applications and infrastructure are secure, resilient, and compliant across regions
  • Work closely with engineering, infrastructure, and security teams to design and implement secure architectures and development practices
  • Shape how Strava manages application and infrastructure risks in the EU, ensuring speed, accuracy, and consistency in remediation and governance
  • Build automated workflows that identify vulnerabilities early, enforce secure configurations, and strengthen our CI/CD and cloud security controls
  • Collaborate across Security, Engineering, Legal, and Compliance to ensure that systems, processes, and data handling meet EU regulatory standards and Strava’s global security expectations
  • Serve as the primary security point of contact for Strava Group in the EU, bridging global strategy with local implementation and compliance
  • Drive secure-by-design practices across engineering teams, including threat modeling, architecture reviews, and vulnerability management
  • Partner with Engineering and Infrastructure teams to embed automated security checks into CI/CD pipelines and infrastructure-as-code deployments
  • Coordinate regional incident response, vulnerability triage, and remediation validation in partnership with the global security team

Requirements:

  • Hands-on experience in application and infrastructure security, including code review, threat modeling, and securing cloud-native environments (AWS preferred)
  • Designed or implemented automated security controls in CI/CD pipelines using tools like Semgrep, Tenable, GHAS, Snyk, or custom scripting
  • Understand how to secure containerized and distributed environments, including Kubernetes, IAM, and network segmentation
  • Comfortable managing vulnerability management programs end-to-end — from detection and prioritization through engineering remediation
  • Familiarity with EU security and privacy frameworks (GDPR, NIS2) and know how to apply them pragmatically to cloud infrastructure and data systems
  • Collaborative and pragmatic — able to influence engineering teams through partnership, technical credibility, and clear communication
  • Communicate proactively and effectively across technical and non-technical stakeholders, ensuring alignment between EU operations and global security strategy
What we offer:

Offers Equity

Additional Information:

Job Posted:
February 20, 2026

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Senior Engineer, Application and Security Infrastructure

Senior Security GRC Engineer

The Senior Security GRC Engineer at Atlassian will be instrumental in implementi...
Location
Location
India , Bengaluru
Salary
Salary:
Not provided
https://www.atlassian.com Logo
Atlassian
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5-7+ years experience in a similar role, preferably in a large-scale SaaS/Product environment
  • Expertise and experience working in security-focused roles
  • Experience with application security, especially web applications
  • Experience in cloud security architecture and infrastructure
  • Experience providing SME knowledge and guidance to stakeholders and engineering functions
  • Experience working with internal/external audit and leadership teams
  • Solid knowledge of cybersecurity principles, risk management strategies, and IT governance frameworks
  • Strong communication and interpersonal skills, with the ability to interact with stakeholders at all levels and explain complex security concepts in an understandable way
  • Relevant certifications such as CISSP, CISM, or CRISC would be beneficial
  • Scripting experience to automate recurring tasks (JQL, SQL, Python, Go)
Job Responsibility
Job Responsibility
  • Deliver technical expertise and innovation, providing security guidance to teams and promoting the adoption of industry-leading methodologies to build secure products by default
  • Drive technical solutions in security and risk management
  • Leverage data analytics and visualization, deriving actionable insights from security governance, risk, and compliance data
  • Promote automation and tooling, encouraging the use of the latest security tools to enhance product security processes
  • Proactively identify and mitigate risks, recognizing potential security threats or compliance concerns specific to product security
  • Collaborate with product security teams, implementing security controls and best practices
  • Regularly evaluate and report, assessing the effectiveness of security controls
  • Influence and align stakeholders, working with security engineers and stakeholders to drive alignment on security initiatives
  • Stay informed on regulatory awareness and compliance, keeping up with the latest developments in legislative, regulatory, and industry security requirements
What we offer
What we offer
  • health coverage
  • paid volunteer days
  • wellness resources
  • Fulltime
Read More
Arrow Right

Senior Security Engineer

PagerDuty is seeking a Senior Security Engineer to join our diverse, customer-fo...
Location
Location
Canada , Toronto
Salary
Salary:
137000.00 - 207000.00 CAD / Year
https://www.pagerduty.com Logo
PagerDuty
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Proficiency with Application & Product Security typically associated with 4 - 5 years of experience in a Security Engineering role working with a cloud-native, microservices environment, preferably AWS
  • Familiarity with cloud-native product technologies including: Vulnerability detection via multiple approaches including SAST, DAST, SCA, and runtime (e.g., Qualys/Nessus, Wiz, Snyk, GHAS, Semgrep, etc.)
  • CI/CD technologies and integrations (e.g., CircleCI, Buildkite, Helm, Terraform, Chef)
  • Product security event logging standards and analysis tools (e.g., SIEM such as: SumoLogic, LogRythm, or Splunk, etc.)
  • Security Incident Response & Risk Management processes and tools
  • Proficiency in at least one programming language and framework (e.g. Python, Bash, Phoenix/Elixir, Java, Ruby on Rails), typically associated with 3 - 4 years of experience with the language/framework
  • Have exceptional written, oral communication, and interpersonal skills
  • Organizational skills with the ability to successfully manage multiple priorities and deadlines
Job Responsibility
Job Responsibility
  • Embrace the role of hands-on technical lead in defining product security standards and guiding platform protections
  • Establish criteria and conduct comprehensive security reviews throughout all stages of product development to identify and address security risks
  • Perform regular threat assessments, coordinate with third-party testers for penetration testing, and conduct internal penetration testing to identify and mitigate security risks
  • Mentor and guide team members to ensure product and business objectives are prioritized in project implementations, fostering a strong documentation culture with project charters and design documents
  • Work with loosely defined requirements where you exercise your analytical skills to clarify questions, share your approach, and collaborate with the team to design and implement effective security frameworks. Maintain a strong appetite for challenging problems with a high degree of ownership
  • Participate in the team’s On-Call rotation, triaging and addressing security issues as they arise, and implement measures to prevent future occurrences
  • Enable service team security implementations by developing security-as-code constructs, including infrastructure-as-code (IaC) modules, libraries and frontend components, while creating and maintaining developer-focused documentation to promote easy adoption
  • Establish and uphold baseline standards and hardened configurations for platform components
  • Continuously enhance security frameworks by focusing on product security standards and software supply chain protections, tailored for application security in cloud-native, microservices environments
What we offer
What we offer
  • Competitive salary
  • Comprehensive benefits package from day one
  • Flexible work arrangements
  • Company equity
  • ESPP (Employee Stock Purchase Program)
  • Retirement or pension plan
  • Generous paid vacation time
  • Paid holidays and sick leave
  • Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
  • Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)
  • Fulltime
Read More
Arrow Right

Senior Security Engineer

As a Senior Security Engineer, you will play a crucial role in safeguarding Dash...
Location
Location
France , Paris
Salary
Salary:
Not provided
dashlane.com Logo
Dashlane
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Familiarity with application security best practices, including threat modeling
  • Experience operating within an SDLC program
  • An understanding of CI/CD pipelines and their security implications
  • Familiarity in Identity and Access Management (IAM) frameworks and protocols (Passkeys, SAML, OAuth, SCIM, etc)
  • Interest in enabling secure use of AI tools to drive efficiency, creativity, and impact internally
  • Communication & Collaboration: You engage and listen empathetically to others, adjusting your communication style to fit the audience and message.
  • Mentoring: You enjoy using your knowledge and experience to support and uplevel those around you.
  • Motivated Learner: You learn new technologies and processes quickly, and understand where to look for knowledge when you need it.
  • Adaptability: You are a jack or jane of all trades - you’re comfortable digging into non-technical parts of the business to provide security support and guidance.
Job Responsibility
Job Responsibility
  • Help drive the continuous improvement of Dashlane’s security program across the product and company
  • Assist with architecture design reviews, threat modeling, and technical security assessments of Dashlane’s product (application and infrastructure) to identify security risks and provide mitigation guidance
  • Ensure security best practices are integrated throughout the software development lifecycle (SDLC)
  • Build upon and scale Vulnerability Management to ensure the team can track, analyze, and manage vulnerabilities and their remediation
  • Perform risk assessments of Dashlane’s internal systems, environments, assets, and data, and implement security best practices accordingly
  • Participate in Compliance and Incident Response activities
What we offer
What we offer
  • Flex Benefits - monthly amount to be allocated to a pool of benefits of your choice.
  • Health insurance covered by Dashlane.
  • Extended time off and well-being days - add 5 days to you vacation quota, plus your birthday day off, and 4 extra days (one per quarter) to acknowledge the importance of your wellbeing.
  • Equal Parental leave - regardless of gender, up to 20 weeks fully paid leave to take care of their new baby, within the first year of birth or adoption.
  • Mentorship program - select your mentor from our internal pool and continue your learning path!
  • Flexible working hours - depending on the role, determine a schedule that fits your need, in alignment with your manager.
  • Donation matching program - give back to the community and support actions that lead to positive social impact under the historically marginalized communities. Every donation will be matched by Dashlane.
  • Mental health services through Spring Health for you and for you and family members.
  • Team buildings & seasonal social events.
  • Weekly lunch in the office and monthly happy hour and much more.
  • Fulltime
Read More
Arrow Right

Senior Cloud Security Engineer

Senior Cloud Security Engineer (Infrastructure and Security) – New York – Compet...
Location
Location
United States , New York
Salary
Salary:
Not provided
weareorbis.com Logo
Orbis Consultants
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Several years of experience working in a similar role with a focus on Cloud Security in AWS
  • Experience provisioning infrastructure in AWS using Terraform, CloudFormation, CDK, or similar tools
  • Experience configuring VPCs, route tables, NACLs, Security Groups, iptables, Web Application Firewall, Config, GuardDuty, Inspector, KMS, IAM, etc.
  • In depth knowledge of AWS security best practices around systems hardening, monitoring, and incident response
  • Experience taking part in an on-call rotation
  • You are passionate about securing infrastructure, reducing risk, and protecting data!
  • You are a subject matter expert on cloud security in AWS
  • You have a solid understanding of network architecture and protocols
  • You can advise on cloud security policies and procedures
Job Responsibility
Job Responsibility
  • Serve as a cloud security subject matter expert, advise on and implementing best practices
  • Respond to security incidents and provide timely and appropriate solutions
  • Conduct cloud security risk assessments and audits
  • Conduct investigations into security incidents and potential threats
  • Take part in on call rotations for incident response and remediation
  • Assist with policy management, security audits, and due diligence for cloud security concerns
  • Advise on, configuring, and managing a variety of security tools
  • Keep informed about and respond to emerging security threats and vulnerabilities
  • Assist with cloud security reviews of potential vendors
What we offer
What we offer
  • Competitive Package
  • Opportunity to work with an Ambitious, Young, Growing Organisation
  • Fulltime
Read More
Arrow Right

Senior Cloud Security Engineer

Senior Cloud Security Engineer (Infrastructure and Security) – New York – Compet...
Location
Location
United States , New York
Salary
Salary:
Not provided
weareorbis.com Logo
Orbis Consultants
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Several years of experience working in a similar role with a focus on Cloud Security in AWS
  • Experience provisioning infrastructure in AWS using Terraform, CloudFormation, CDK, or similar tools
  • Experience configuring VPCs, route tables, NACLs, Security Groups, iptables, Web Application Firewall, Config, GuardDuty, Inspector, KMS, IAM, etc.
  • In depth knowledge of AWS security best practices around systems hardening, monitoring, and incident response
  • Experience taking part in an on-call rotation
  • You are passionate about securing infrastructure, reducing risk, and protecting data!
  • You are a subject matter expert on cloud security in AWS
  • You have a solid understanding of network architecture and protocols
  • You can advise on cloud security policies and procedures
Job Responsibility
Job Responsibility
  • Serve as a cloud security subject matter expert, advise on and implementing best practices
  • Respond to security incidents and provide timely and appropriate solutions
  • Conduct cloud security risk assessments and audits
  • Conduct investigations into security incidents and potential threats
  • Take part in on call rotations for incident response and remediation
  • Assist with policy management, security audits, and due diligence for cloud security concerns
  • Advise on, configuring, and managing a variety of security tools
  • Keep informed about and respond to emerging security threats and vulnerabilities
  • Assist with cloud security reviews of potential vendors
What we offer
What we offer
  • Competitive Package
  • Opportunity to work with an Ambitious, Young, Growing Organisation
  • Significant growth potential
  • Not corporate culture
  • Trust employees to take on a lot of responsibility and have input into the shape of growth of the organisation
  • Fulltime
Read More
Arrow Right

Senior Cloud Security Engineer

Senior Cloud Security Engineer (Infrastructure and Security) – New York – Compet...
Location
Location
United States , New York City
Salary
Salary:
Not provided
weareorbis.com Logo
Orbis Consultants
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Several years of experience working in a similar role with a focus on Cloud Security in AWS
  • Experience provisioning infrastructure in AWS using Terraform, CloudFormation, CDK, or similar tools
  • Experience configuring VPCs, route tables, NACLs, Security Groups, iptables, Web Application Firewall, Config, GuardDuty, Inspector, KMS, IAM, etc.
  • In depth knowledge of AWS security best practices around systems hardening, monitoring, and incident response
  • Experience taking part in an on-call rotation
  • You are passionate about securing infrastructure, reducing risk, and protecting data!
  • You are a subject matter expert on cloud security in AWS
  • You have a solid understanding of network architecture and protocols
  • You can advise on cloud security policies and procedures
Job Responsibility
Job Responsibility
  • Serve as a cloud security subject matter expert, advise on and implementing best practices
  • Respond to security incidents and provide timely and appropriate solutions
  • Conduct cloud security risk assessments and audits
  • Conduct investigations into security incidents and potential threats
  • Take part in on call rotations for incident response and remediation
  • Assist with policy management, security audits, and due diligence for cloud security concerns
  • Advise on, configuring, and managing a variety of security tools
  • Keep informed about and respond to emerging security threats and vulnerabilities
  • Assist with cloud security reviews of potential vendors
What we offer
What we offer
  • Competitive Package
  • Opportunity to work with an Ambitious, Young, Growing Organisation
  • Significant growth potential
  • Not corporate culture
  • Trust employees to take on a lot of responsibility and have input into the shape of growth of the organisation
  • Fulltime
Read More
Arrow Right

Senior Cloud Security Engineer

Senior Cloud Security Engineer (Infrastructure and Security) – New York – Compet...
Location
Location
United States , New York
Salary
Salary:
Not provided
weareorbis.com Logo
Orbis Consultants
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Several years of experience working in a similar role with a focus on Cloud Security in AWS
  • Experience provisioning infrastructure in AWS using Terraform, CloudFormation, CDK, or similar tools
  • Experience configuring VPCs, route tables, NACLs, Security Groups, iptables, Web Application Firewall, Config, GuardDuty, Inspector, KMS, IAM, etc.
  • In depth knowledge of AWS security best practices around systems hardening, monitoring, and incident response
  • Experience taking part in an on-call rotation
  • You are passionate about securing infrastructure, reducing risk, and protecting data!
  • You are a subject matter expert on cloud security in AWS
  • You have a solid understanding of network architecture and protocols
  • You can advise on cloud security policies and procedures
Job Responsibility
Job Responsibility
  • Serve as a cloud security subject matter expert, advise on and implementing best practices
  • Respond to security incidents and provide timely and appropriate solutions
  • Conduct cloud security risk assessments and audits
  • Conduct investigations into security incidents and potential threats
  • Take part in on call rotations for incident response and remediation
  • Assist with policy management, security audits, and due diligence for cloud security concerns
  • Advise on, configuring, and managing a variety of security tools
  • Keep informed about and respond to emerging security threats and vulnerabilities
  • Assist with cloud security reviews of potential vendors
What we offer
What we offer
  • Competitive Package
  • Opportunity to work with an Ambitious, Young, Growing Organisation
  • Fulltime
Read More
Arrow Right

Senior Security Engineer

The Senior Security Engineer will provide hands-on technical leadership within t...
Location
Location
United Kingdom , Leeds; Thame
Salary
Salary:
65000.00 - 75000.00 GBP / Year
pexa.co.uk Logo
PEXA UK
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Proactive, can-do attitude to get things done quickly and efficiently
  • Strong collaboration and communication skills
  • Willingness to contribute ideas to the security programme
  • Demonstratable first-hand experience in achieving organisational adherence to security best practices
  • Experience in the practical protection of a remote working laptop estate and SaaS cloud solutions
  • Experience in identity and access management solutions
  • Experience in device business automation and updates
  • Experience in the security aspects of cloud web application hosting and defence measures like WAF
Job Responsibility
Job Responsibility
  • Maintenance and Operational Security: Ensure all security solutions remain operationally effective
  • Ensure technical teams timely patch applications, systems, software, and hardware
  • Maintain and audit secure configurations for devices, applications, and cloud environments
  • Access Control and Identity Management: Conduct regular user and privileged account reviews
  • Manage and monitor Privileged Identity Management (PIM) profiles and elevated access accounts
  • Coordinate with IT and HR for onboarding/offboarding
  • Tool, Infrastructure, and Encryption Management: Maintain and optimise security infrastructure and tools
  • Oversee encryption key and certificate management
  • Work with vendors and internal teams to ensure tools remain current
  • VPN, Network & Firewall Security: Design, configure, and maintain secure VPN and Zero-Trust network solutions
What we offer
What we offer
  • Your growth: We encourage you to hit your personal and professional learning and development goals with our tailored programs and tools
  • Your wellness: We care about your holistic wellbeing
  • Your work/life blend: We want to help you create your ideal work/life blend
  • Fulltime
Read More
Arrow Right