Staff Security Engineer, Cloud and Product Security

Lob
United States
Workplace: RemoteFull timeUSD 197,500 - 220,000 annuallyFunction: CybersecurityExperience: 8+ yearsSkills: ["Collaboration","Communication","Automation-minded","Incident response leadership","Security program building"]

Own the engineering side of security as the first hire in a newly split security function. You’ll secure Lob’s AWS cloud environment, detection and response (SIEM), application/product security (vulnerability management, threat modeling, secure SDLC), and technical assurance via annual penetration testing. Partner with Platform, Logistics, and IT, manage a security contractor, build automation and high-signal detections, and produce technical evidence for SOC 2, HIPAA, and Microsoft SSPA—without owning questionnaires or the audit itself.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Lob
Lob
2 days ago

Staff Security Engineer, Cloud and Product Security

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Own the engineering side of security as the first hire in a newly split security function. You’ll secure Lob’s AWS cloud environment, detection and response (SIEM), application/product security (vulnerability management, threat modeling, secure SDLC), and technical assurance via annual penetration testing. Partner with Platform, Logistics, and IT, manage a security contractor, build automation and high-signal detections, and produce technical evidence for SOC 2, HIPAA, and Microsoft SSPA—without owning questionnaires or the audit itself.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Manager level

Key Responsibilities

  • •Own cloud infrastructure security for Lob’s AWS environment, including CNAPP and cloud misconfiguration risk.
  • •Build and run detection engineering on the SIEM, defining alert triage, runbooks, and severity criteria.
  • •Lead application and product security: vulnerability management across SCA/SAST/DAST and container scanning, plus threat modeling and security architecture reviews.
  • •Own technical incident response activities, including escalation paths, tabletop exercises, and post-incident reviews.
  • •Manage and mentor the application security contractor, routing remediation work into engineering teams and improving secure SDLC and assurance workflows.

Pay and Benefits

Salary: USD 197,500 - 220,000 annually
Equity and Bonus:Equity

Key Requirements

  • •8+ years in security engineering with meaningful depth in cloud security.
  • •Hands-on expertise with AWS security services, IAM design, and infrastructure as code.
  • •Detection engineering experience: written and tuned detections with reduced false positives.
  • •Real incident response experience as a responder or lead.
  • •Fluency in application security to review findings, assess severity, and discuss exploitability with engineers.
Experience:8+ years
Skills:CollaborationCommunicationAutomation-mindedIncident response leadershipSecurity program building
Languages:English
Tech Stack:AWSIAMInfrastructure as codeCNAPPTerraformNomadCloudflareWAFSIEMEndpoint detectionVulnerability managementSCASASTDASTContainer scanningThreat modelingSecure SDLCPenetration testingAI

Company Brief

Lob
Provides APIs to automate printing and mailing of physical mail (postcards, letters, checks) and address verification, enabling developers and businesses to integrate direct mail into applications and workflows.
Industry: API Platforms
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Funding: Series D
Headquarters: San Francisco, United States
Founded: 2013
WebsiteLinkedIn