Senior Security Engineer at Jobgether
$160,000–$188,000from the description
Jul 15, 2026
—
Jul 21, 2026
What this job asks for AI summary
A hands-on senior security engineering role focused on embedding security across the full software development lifecycle — from threat modeling and secure code reviews to cloud infrastructure hardening and CI/CD pipeline integration. The position spans application security, tooling implementation (SAST, DAST, SCA, SIEM), and cross-functional collaboration with engineering, product, IT, and legal teams. Best suited to an experienced software engineer with deep security expertise who is comfortable operating at both strategic and practical levels.
Senior level · 7+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 3,400 people nationally plausibly meet what this posting asks for (information security analysts). range 2,050–5,100
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
The role sits at the intersection of software engineering and security — the JD explicitly requires 7+ years of software engineering experience combined with deep security expertise. 15-1212 (Information Security Analysts) is the primary classification given the security strategy, threat modeling, vulnerability management, and compliance focus; 15-1252 (Software Developers) is a credible runner-up given the hands-on engineering, security tooling build-out, and infrastructure-as-code responsibilities.
SAST, DAST, and SCA are listed together as a single tooling requirement in the JD; they are emitted as separate skills because each is a distinct tool category, with DAST and SCA also captured individually.
Cloud platform requirement is stated as 'AWS, GCP, or Azure' — AWS is the primary skill with GCP and Azure as named alternatives.
SOC 2 and ISO 27001 appear under 'Familiarity with compliance frameworks such as…' — the word 'familiarity' and the 'such as' framing place this in preferred territory.
Security certifications (CISSP, CCSP, CSSLP, OSCP) are explicitly called 'a plus' in the posting.
Experience in startup/scale-up/high-growth environments is listed as preferred, not required — it is a contextual note rather than a named technology and is therefore not emitted as a skill.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.