Logo for Drivetrain

Security Engineer

Role overview

Qualifications

  • 2+ years of experience in security engineering, application security, or a related infrastructure/security role
  • Strong understanding of cloud security fundamentals (AWS or GCP), network security, and IAM
  • Experience with secure SDLC practices — code review, dependency scanning, CI/CD pipeline security
  • Clear communicator who can translate security risk into terms non-security stakeholders understand

Responsibilities

  • Design, implement, and maintain security controls across cloud infrastructure (AWS/GCP), CI/CD pipelines, and internal systems
  • Lead application security efforts: threat modeling, secure code review, and integrating SAST/DAST tooling into the development lifecycle
  • Own vulnerability management — triage, prioritize, and drive remediation of findings from scans, pen tests, and bug bounty reports
  • Monitor for and respond to security incidents; build and maintain incident response runbooks

About the company

Drivetrain logo

Drivetrain

Computer Software / SaaS

Drivetrain is a financial planning & decision-making platform that helps businesses scale and achieve their targets predictably.

Company details

Company typeScaleup
IndustryComputer Software / SaaS
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

The Role

As a Security Engineer at Drivetrain, you'll own and evolve our security posture across product, infrastructure, and internal tooling. You'll work closely with Engineering, IT, and Compliance to make sure security is built into how we ship — not bolted on after the fact. This is a hands-on role for someone who wants to build systems and processes, not just write policy.

What You'll Do

  • Design, implement, and maintain security controls across cloud infrastructure (AWS/GCP), CI/CD pipelines, and internal systems
  • Lead application security efforts: threat modeling, secure code review, and integrating SAST/DAST tooling into the development lifecycle
  • Own vulnerability management — triage, prioritize, and drive remediation of findings from scans, pen tests, and bug bounty reports
  • Monitor for and respond to security incidents; build and maintain incident response runbooks
  • Manage identity and access controls (SSO, RBAC, least-privilege enforcement) across internal and customer-facing systems
  • Support customer security questionnaires, audits, and certifications (e.g., SOC 2, ISO 27001)
  • Partner with engineering teams to embed secure-by-design practices into new features and services
  • Evaluate and implement security tooling (secrets management, endpoint protection, cloud security posture management)
  • Educate the broader team on security best practices and champion a security-first culture

What We're Looking For

  • 2+ years of experience in security engineering, application security, or a related infrastructure/security role
  • Strong understanding of cloud security fundamentals (AWS or GCP), network security, and IAM
  • Experience with secure SDLC practices — code review, dependency scanning, CI/CD pipeline security
  • Familiarity with common frameworks and standards (OWASP Top 10, SOC 2, ISO 27001, GDPR)
  • Hands-on scripting/automation skills (Python, Go, or similar) for building internal security tooling
  • Experience responding to and documenting security incidents
  • Clear communicator who can translate security risk into terms non-security stakeholders understand

Nice to Have

  • Experience securing a SaaS product handling sensitive financial data
  • Prior experience leading a SOC 2 Type II or ISO 27001 audit from the engineering side
  • Familiarity with container security (Docker/Kubernetes) and IaC scanning (Terraform)
  • Relevant certifications (OSCP, CISSP, CCSP) — nice signal, not required

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Drivetrain

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.