Security Operation Engineer

A technology company focused on cybersecurity solutions and infrastructure protection.
$140,000 - $220,000
Security
Mid-Level Software Engineer
In-Person
3+ years of experience
Cybersecurity

Description For Security Operation Engineer

Windsurf is seeking a Security Operations Engineer to strengthen their security infrastructure and lead their vulnerability management initiatives. This role combines technical expertise with program management, focusing on maintaining a robust security posture through proactive measures and third-party security programs. The position offers an opportunity to work with modern security tools and frameworks while managing critical security operations.

The role demands a security professional with strong technical background who can handle vulnerability management, threat modeling, and penetration testing coordination. You'll be responsible for establishing and managing a bug bounty program, supporting compliance efforts, and working closely with engineering teams to enhance security measures.

This is an excellent opportunity for a security professional looking to make a significant impact in a company that values security excellence. The position offers competitive compensation including equity, and requires working from the Mountain View headquarters. The ideal candidate will bring both technical depth and program management skills to help scale and improve security operations.

The role requires a US person (citizen or green card holder) and involves working with various security frameworks and tools. You'll be part of a team that values security best practices and continuous improvement, with opportunities to work on diverse security challenges across cloud and on-premises environments.

Last updated 5 minutes ago

Responsibilities For Security Operation Engineer

  • Develop and manage comprehensive vulnerability management program
  • Create and maintain threat models for GCP, cloud, and onprem linux systems
  • Coordinate and oversee penetration testing engagements with external vendors
  • Establish and manage bug bounty program, including triage of submissions
  • Support security compliance efforts with technical knowledge and documentation
  • Track and report on security metrics and KPIs
  • Collaborate with engineering teams to remediate security findings

Requirements For Security Operation Engineer

  • 3+ years of experience in security operations or vulnerability management
  • Experience managing vulnerability scanning tools and processes
  • Strong understanding of threat modeling methodologies
  • Experience coordinating penetration testing engagements
  • Technical knowledge to address complex security inquiries
  • Understanding of common security frameworks (SOC 2, ISO 27001, etc.)
  • US person - Natural Citizenship or Green Card
  • Position requires in office 5 days a week

Benefits For Security Operation Engineer

Equity
  • Equity

Interested in this job?

Jobs Related To Windsurf Security Operation Engineer

Systems Development Engineer, Amazon Foundational Security Services

Systems Development Engineer role at Amazon Security, focusing on developing and maintaining security services for Amazon's cloud and retail platforms.

Software Development Engineer, BlackWatch Proactive Security

AWS Shield Infrastructure team seeks Software Engineer for DDoS defense, offering competitive pay, benefits, and opportunity to work on critical security infrastructure.

Software Development Engineer II, AWS Security

AWS Security Software Development Engineer position focusing on building scalable security solutions and automated permission management systems.

Software Development Engineer II, AWS Web Application Firewall (WAF)

AWS seeks Security Engineer to develop and maintain Web Application Firewall, building distributed systems for real-time attack prevention across global infrastructure.

Security Engineer, Dedicated Security Team

Security Engineer role at Amazon focusing on cybersecurity threat mitigation, security solution development, and acquisition security diligence.