Senior Engineer, Security
- Company
- Taptap Send
- Location
- New York, NY
- Work type
- Full Time
- Posted
- 2026-09-30
Job description
The Role
We are looking for a Senior Engineer, Security to join our Platform Engineering team. This is a find-and-fix role. When you find a vulnerability in our infrastructure, you write the Terraform or the application change that closes it. Where the fix belongs to another team, you drive it to completion, with the CISO supporting you.
You will report into Platform Engineering and work closely with our CISO, who sets the security agenda and is your escalation route when remediation stalls elsewhere.
Responsibilities
Fix it, don't just find it: Remediate security findings across our infrastructure, writing the Terraform and application changes that close them. Where the fix belongs to another team, drive it to completion. Run vulnerability management from Snyk, Prowler, and ASV findings through to verified fixes.
Own AWS security: Cloud posture across IAM and least privilege, network boundaries, secrets management, and logging coverage. Define the technical security baselines new services are built to, covering host hardening, WAF configuration and deployment patterns, and enforce them as code.
Find problems before anyone else does: Regular penetration testing against our own environment, ahead of the formal annual assessment carried out by our external testers. Threat modelling and security review for new services early enough to change the design, including our integrations with payment and custody providers.
Respond when it matters: Serve as technical lead for security incidents, including forensic investigation. Own and improve detection coverage in Datadog, tuning alerts for signals.
What you need
Five or more years in hands-on security engineering, with responsibility for production systems.
You write and ship code. Terraform and Python, and enough application fluency to fix what you find rather than hand it off.
Deep AWS security experience, including IAM and least privilege at organization scale, and container workloads in ECS or EKS.
Application security, including threat modelling and hands-on offensive testing against cloud and application targets.
Security incident response, including forensic investigation.
You have run vulnerability management and driven fixes through teams you do not manage; you work the finding queue on your own initiative, without being chased.
You have worked in a regulated environment and turned ISO 27001, PCI DSS, or SOC 2 requirements into engineering work.
Detection engineering in Datadog, or a comparable SIEM.
Securing CI/CD pipelines, particularly GitHub Actions.
Cryptography and secrets management in practice, including key rotation and certificate lifecycle.
Using AI coding tools to remediate at scale, and reviewing AI-generated code with a security eye
Experience with payments, cards, or digital assets.