Lacework
Lacework

43 Lacework Jobs Hiring Near You

Infrastructure Security Engineer

Seattle, WA · On-site

$162K/yr

... Lacework, or equivalent) with a strong opinion on what good looks like. • Identity first security mindset and demonstrated ability to build identity and access management solutions at scale. • ...

Senior Security Engineer II

Aventura, FL · On-site

$110K - $151K/yr

Proven experience with a CNAPP or similar cloud security tool (e.g., Wiz, Orca Security, Lacework, Upwind). * Proficiency in at least one programming language (e.g., Python, Go) for automation.

Devops Engineer SR

Dallas, TX · On-site +1

$128K - $165K/yr

NetworkPolicies, Pod Security Standards, admission policy enforcement, CrowdStrike Falcon, Lacework, kube-bench, and cert-manager with Let's Encrypt ACME * Support data infrastructure including Cloud ...

Senior Security Engineer II

Boston, MA · On-site

$176K - $196K/yr

Proven experience with a CNAPP or similar cloud security tool (e.g., Wiz, Orca Security, Lacework, Upwind). * Proficiency in at least one programming language (e.g., Python, Go) for automation.

Lacework * AI Tools: Cursor, Claude, Gemini, Eddy (our in-house cloud agent harness) About this role This role sits at the intersection of growth, product development, and marketing. You'll have the ...

Senior Security Engineer II

Seattle, WA · On-site

$176K - $196K/yr

Proven experience with a CNAPP or similar cloud security tool (e.g., Wiz, Orca Security, Lacework, Upwind). * Proficiency in at least one programming language (e.g., Python, Go) for automation.

Lacework * AI Tools: Cursor, Claude, Gemini, Eddy (our in-house cloud agent harness) About this role This role sits at the intersection of growth, product development, and marketing. You'll have the ...

Lacework AI Tools: Cursor, Claude, Gemini, Eddy (our in-house cloud agent harness) About these roles At Headway, we're building a national network of therapists who accept insurance - and making ...

Lacework AI Tools: Cursor, Claude, Gemini, Eddy (our in-house cloud agent harness) About these roles At Headway, we're building a national network of therapists who accept insurance - and making ...

Engineering Manager (Growth)

New York, NY · On-site

$222K - $278K/yr

Lacework * AI Tools: Cursor, Claude, Gemini, Eddy (our in-house cloud agent harness) About this role This role sits at the intersection of growth, product development, and marketing. You'll have the ...

Lacework * AI Tools: Cursor, Claude, Gemini, Eddy (our in-house cloud agent harness) About this role This role sits at the intersection of growth, product development, and marketing. You'll have the ...

Lacework • AI Tools: Cursor, Claude, Gemini, Eddy (our in-house cloud agent harness) About these roles At Headway, we're building a national network of therapists who accept insurance - and making ...

Showing results 21-40

Infrastructure Security Engineer

Opendoor

Seattle, WA • On-site

$162K/yr

Full-time

Re-posted 21 days ago


Job description

Job Summary:
Opendoor is on a mission to empower homeowners and streamline the homeownership process. As an Infrastructure Security Engineer, you will be responsible for ensuring the security of Opendoor's cloud infrastructure while implementing innovative security solutions and mentoring engineers on best practices.
Responsibilities:
• Own the security architecture of our production cloud environment - AWS at the core, spanning multiple accounts, Kubernetes clusters, Terraform-managed infrastructure, and the identity plane that ties everything together.
• Evaluate, build out and operate our cloud security visibility and protection platform ensuring it’s deeply integrated into engineering workflows to drive the automated remediation of infrastructure risks.
• Define and drive our zero trust access strategy, integrating device trust and identity-aware proxies to provide seamless, secure access to Opendoor infrastructure.
• Harden our Kubernetes environment including RBAC, admission policies, workload identity, runtime protection, image signing, and base-image strategy on top of our Bottlerocket and Karpenter foundation.
• Build new agentic detection and response workflows using AWS native primitives that close the loop from alert to investigation to remediation.
• Drive a shift-left cloud security strategy within our pipelines using Terraform/Terrakube, GitHub Actions, Elastic Container Registry so that misconfigurations get caught at commit time.
• Partner with the Infrastructure team on cloud-native security decisions: VPC architecture, ingress, secrets management (Vault), service identity, and how Okta extends into AWS, Azure, and GCP.
• Run our cloud detection engineering: GuardDuty, Security Hub, CloudTrail, VPC flow logs — tuned for signal, integrated with Datadog and our incident response playbooks.
• Set the bar for what "secure by default" looks like for AI-maximalist engineering — vibe-coded apps, MCP servers, and agent-driven workflows that touch production cloud infrastructure.
• Mentor engineers across Opendoor on cloud security patterns, and turn the patterns you see into automated guardrails.
Qualifications:
Required:
• Deep conviction that AI and automation should eliminate manual work and increase the team's impact, and a track record to prove it. You’ve built agentic systems that replaced reactive security work, not just configured off-the-shelf tools.
• Comfort operating with high autonomy in ambiguous environments. You’ve defined what “good” looks like in a domain where no playbook existed, you’re energized by that, not unsettled by it.
• Business enablement security mindset. You measure success by business impact and informed risk taking, not by tickets opened or compliance checklists completed.
• 5+ years of cloud or infrastructure security experience, with deep AWS expertise - you can read a CloudTrail event, write a service control policy, and explain why a particular identity trust policy is dangerous, all in the same conversation.
• Strong skills in at least one of Go, Python, or TypeScript, with the ability to read and write Terraform and shell scripts. You are a builder.
• Hands-on Kubernetes security experience — RBAC, network policies, admission control, workload identity, image and supply-chain security.
• Experience deploying and operating cloud posture and workload protection tooling (Wiz, Prisma, Orca, Datadog, CrowdStrike Falcon Cloud, Lacework, or equivalent) with a strong opinion on what good looks like.
• Identity first security mindset and demonstrated ability to build identity and access management solutions at scale.
• Humility and genuine curiosity. You're as excited to learn from engineers across product and infrastructure and enable their work as you are to write detections or design guardrails.
Preferred:
• Experience designing or operating Zero Trust Network Access (Cloudflare Access, Tailscale, Twingate, Google BeyondCorp, etc.)
• Detection engineering background with a threat modeling and adversarial mindset - writing detections that actually fire on real attacker behavior without burying the team in noise.
• Experience securing AI and machine learning pipelines, agent frameworks, or MCP-style integrations that touch production data.
• Familiarity with SOC 2, SOX, or other compliance frameworks in cloud environments and an instinct for when compliance work creates real security value.
• Open source contributions to cloud security tooling (Cartography, Prowler, ScoutSuite, Falco, Kyverno, Open Policy Agent, Checkov, etc.)
Company:
Founded in 2014, Opendoor’s mission is to power life’s progress one move at a time. Founded in 2014, the company is headquartered in Tempe, USA, with a team of 1001-5000 employees. The company is currently Late Stage.