Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small. Coupa AI is informed by trillions of dollars of direct and indirect spend data across a global network of 10M+ buyers and suppliers. We empower you with the ability to predict, prescribe, and automate smarter, more profitable business decisions to improve operating margins.
Why join Coupa?
🔹 Pioneering Technology: At Coupa, we're at the forefront of innovation, leveraging the latest technology to empower our customers with greater efficiency and visibility in their spend.
🔹 Collaborative Culture: We value collaboration and teamwork, and our culture is driven by transparency, openness, and a shared commitment to excellence.
🔹 Global Impact: Join a company where your work has a global, measurable impact on our clients, the business, and each other.
Learn more on
Life at Coupa blog and hear from our employees about their experiences working at Coupa.
The Impact of a Senior Security Engineer at Coupa
Coupa's Security Engineers keep our enterprise, product, platform, and customer data safe. As a Senior Security Engineer, you'll take ownership of complex, ambiguous security problems end to end — building cloud security controls, setting engineering standards, and partnering closely with Engineering, IT, and Compliance to ship durable, automated security tooling rather than one-off fixes. You'll set the technical standard for how the team remediates and automates, and you'll be a go-to resource other engineers turn to when a finding needs real root-cause analysis instead of a quick workaround
What You'll Do:
Design and implement multi-cloud security controls across Coupa's cloud environment, including VPC segmentation, security groups/NACLs, IAM policy design using least-privilege and permission boundaries, and Organizations/SCPs for guardrails at scale.
Build policy as code and IaC security guardrails and wire them into CI/CD as pre-merge and pre-deploy gates rather than after-the-fact reviews.
Harden containerized workloads and Kubernetes clusters — image scanning, admission control, pod security standards, network policies, and container/workload runtime detection.
Own vulnerability analysis of application packages, container images, and third-party dependencies; triage findings by exploitability and business impact rather than CVSS score alone.
Design and implement remediations — not just report findings — including secure code fixes, cloud configuration changes, and IAM policy adjustments using least-privilege principles.
Support incident response and forensics as a technical contributor — log analysis, root-cause investigation, and remediation validation using cloud-native and EDR tooling.
Partner with the Risk & Compliance team to provide technical evidence and control validation for audit frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP).
Support and mentor other security engineers — reviewing designs and remediation plans, sharing root-cause analysis techniques, and helping less experienced teammates work through complex or ambiguous findings.
Participate in the on-call/incident rotation and help continuously improve remediation and response runbooks.
What You'll Bring to Coupa:
7+ years of experience in security engineering or penetration testing, with a track record of independently owning complex assessments from scoping through remediation.
Practical experience with cloud security fundamentals (AWS, GCP, or Azure) — IAM, networking, and common misconfiguration classes — sufficient to both find and fix cloud findings.
Strong scripting/automation skills in Python, Bash, or JavaScript, with experience building or extending internal security tooling.
Experience with dependency/container vulnerability scanning tools and integrating them into CI/CD pipelines.
Working knowledge of common compliance frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP) and what auditable evidence looks like.
Critical thinking and root-cause analysis skills — comfortable digging past a scanner's output to understand and explain why a vulnerability exists.
Clear written and verbal communication skills for translating technical findings into remediation guidance for engineers and risk context for stakeholders.
Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
Relevant certifications a plus: CISSP, CCSP, CISA, or AWS/GCP security certifications
At Coupa, we are 100% committed to creating and nurturing an environment that supports your physical, mental, and community well-being . We offer a comprehensive suite of benefits designed to help you and your family thrive:
Global Well-Being Perks (For All Employees Globally)
- Global Wellness Days: Enjoy two designated, company-wide paid wellness days off each year (typically the first Friday in March and the last Friday in September) so the entire global team can unplug, step away, and recharge together .
- Birthday Time-Off: Celebrate your day! Coupa provides a paid day off on your birthday or another day of your choice within your birthday month .
- Volunteer Time Off (VTO): Giving back is in our DNA. We offer 40 hours of paid VTO annually to support the community initiatives and volunteer programs you are passionate about .
- Employee Assistance Program (EAP): Access free, confidential, 24/7/365 counseling and resources for emotional support, work-life solutions, financial advice, legal guidance, and support for new parents .
- Business Travel Protection: Travel with peace of mind. Zurich Travel Assist provides medical, safety, pre-trip planning, and emergency support during any business travel .
- Referral Bonus Program: Share the Coupa experience! Receive generous monetary referral bonuses when you successfully refer talented friends or acquaintances who are hired into open roles .
Please note: In addition to these global well-being perks, Coupa offers highly competitive, location-specific benefits packages (which include comprehensive medical/dental insurance, retirement/pension plans, and life or accident protection) tailored to your primary work location. Your recruiter will walk you through the specific regional benefits package for this role during the interview process.
Coupa complies with relevant laws and regulations regarding equal opportunity and offers a welcoming and inclusive work environment. Decisions related to hiring, compensation, training, or evaluating performance are made fairly, and we provide equal employment opportunities to all qualified candidates and employees.
Please be advised that inquiries or resumes from recruiters will not be accepted.
By submitting your application, you acknowledge that you have read
Coupa’s Privacy Policy and understand that Coupa receives/collects your application, including your personal data, for the purposes of managing Coupa's ongoing recruitment and placement activities, including for employment purposes in the event of a successful application and for notification of future job opportunities if you did not succeed the first time. You will find more details about how your application is processed, the purposes of processing, and how long we retain your application in our Privacy Policy.