San Jose, CA

Salary
Posted
Jul 20, 2026
Location
San Jose, CA
Last confirmed open
Jul 23, 2026

What this job asks for AI summary

A senior individual-contributor security engineering role focused on hardening multi-cloud infrastructure (AWS and GCP), Kubernetes workloads, and CI/CD pipelines for a digital commerce business. Day-to-day work covers cloud security configuration, container and service-mesh policy, identity and access management, endpoint/XDR monitoring, incident response, and establishing governance guardrails around AI tooling adoption. Best suited to an experienced cloud and DevSecOps practitioner comfortable with broad, end-to-end ownership on a small team.

Senior level · 5+ years

Must have (5)
AWSGCPKubernetesPython, PowerShell or Shell ScriptingClaude
Nice to have (18)
Azure Entra IDSSOIstioArgoCDMicrosoft Defender XDROAuth or Openid ConnectTerraformGitHubAWS WAFGCP Cloud ArmorEKSGKEGitHub ActionsDependabotMicrosoft 365n8nCISSP, Cism, Aws Security Specialty, Cks or OscpSOC 2, Iso 27001, Pci Dss or Gdpr

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
GCP13%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Python51%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

This role is based in Costa Rica (hybrid, near San Jose) — the US-based flag is set to false; US compensation benchmarks do not apply.

SOC classification is a genuine judgment call: the role's primary work is security analysis, threat detection, incident response, and DevSecOps governance (15-1212), but it also involves substantial hands-on infrastructure operation across Kubernetes, cloud platforms, and identity systems, which overlaps with 15-1244. 15-1212 was chosen because security analysis and policy enforcement are the stated primary mandate.

The 'Demonstrated experience in at least 3 of the following' clause means none of the listed sub-skills (Azure Entra ID, Istio, ArgoCD, Microsoft Defender XDR, OAuth/OIDC, Terraform, GitHub) is individually required — all are marked preferred accordingly.

Scripting/automation is required; Python is listed first with PowerShell and Bash as named alternatives — captured as one skill with alternatives.

AI tool experience (Claude, OpenAI, or similar) is explicitly required; Claude is listed as primary with OpenAI as a named alternative.

Security certifications (CISSP, CISM, etc.) and compliance frameworks (SOC 2, ISO 27001, PCI-DSS, GDPR) appear under Preferred Qualifications.

n8n appears both in the responsibilities narrative and under Preferred Qualifications — marked preferred.

No compensation figures are stated in the posting.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗