Nue.io is seeking a highly motivated Staff Security Engineer to join their DevSecOps team and help build and operate the security foundation of their platform and engineering systems. The role involves hands-on work in automating security controls, improving infrastructure, and collaborating with engineering teams to enhance security practices.
Responsibilities:
- Drive secure-by-default patterns across the organization through reusable libraries, templates, guardrails, and paved-road workflows, improving security posture across cloud infrastructure, the application stack, and developer workflows
- Lead practical threat modeling for new product capabilities, platform changes, and high-risk workflows, translating findings into clear engineering actions
- Help define the security tooling strategy across application security, cloud security, detection, and developer workflows, evaluating and integrating tools that meaningfully reduce risk without slowing delivery
- Improve software supply chain security across build systems, dependencies, container images, secrets, and deployment processes
- Design, build, and operate security automation and production-quality tooling for identity and access management, secrets management, vulnerability management, and policy enforcement
- Harden AWS environments, containerized workloads, and CI/CD pipelines, using AI-assisted tooling to accelerate work where it genuinely helps
- Build and maintain detection and alerting for meaningful security events across endpoints, cloud infrastructure, application logs, audit trails, and identity systems
- Partner with engineering teams to review architecture, application design, infrastructure changes, and operational patterns with a focus on reducing exploitable risk
- Support compliance and audit needs through engineering-driven controls, evidence automation, logging, and repeatable operational practices
- Own hands-on incident response, including triage, containment, root cause analysis, remediation, and post-incident follow-through
- Participate in on-call rotations for high-severity security and platform incidents and build and test response procedures for scenarios such as credential compromise, privilege escalation, and exposed secrets
Requirements:
- Bachelor's degree in Computer Science, Engineering, or equivalent practical experience
- 8+ years of experience across software engineering, infrastructure engineering, platform engineering, SRE, DevOps, security engineering, or related roles in production SaaS environments
- 3+ years of hands-on experience in security engineering, platform security, cloud security, or related security-focused roles
- Strong hands-on experience securing cloud-native environments on AWS
- Proven ability to write code for automation, integrations, internal tooling, and operational workflows using languages such as Python, Go, JavaScript, or Bash
- Experience operating in a DevSecOps or platform-adjacent model where security is embedded into delivery pipelines and engineering workflows
- Strong experience with identity and access management, secrets handling, key management, logging, auditability, and least-privilege design
- Experience building or operating security controls for CI/CD, infrastructure as code, containerized systems, and developer platforms
- Practical experience with security monitoring, detection engineering, alert tuning, and incident response
- Ability to assess real-world risk and prioritize pragmatic fixes over theoretical perfection
- Experience partnering with engineering teams to improve security architecture, code patterns, infrastructure posture, and operational readiness
- Demonstrated ability to use AI-assisted development tools to accelerate investigations, automate repetitive work, and improve engineering effectiveness while maintaining strong judgment
- Comfortable working in a fast-paced startup environment with a small, high-impact team
- Excellent communication and collaboration skills, able to explain trade-offs clearly and drive consensus without becoming a bottleneck