Instructure Logo

Instructure

Security Engineer

Job Posted 8 Days Ago Posted 8 Days Ago
Remote
Hiring Remotely in US
Mid level
Remote
Hiring Remotely in US
Mid level
As a Security Engineer, you will design and maintain security tooling, address vulnerabilities, ensure compliance, and collaborate with teams to enhance security measures for the SaaS platform.
The summary above was generated by AI

At Instructure, we empower people to grow and succeed by creating intuitive products that simplify learning, facilitate meaningful relationships, and inspire innovation. We are revolutionizing how educational institutions manage and access their data to enhance teaching and learning. As a key contributor to the Security organization, you'll be focused on engineering initiatives across all of Instructure's products and services.


As a Security Engineer, you will be responsible for designing, implementing, and maintaining security tooling to protect our SaaS platform. You will also work closely with cross-functional teams to identify and address vulnerabilities, implement best practices, and ensure compliance with industry standards. This role is critical in upholding the trust of our customers and partners.

What you will be doing:

  • Infrastructure Security
  • Ensure secure configurations of cloud environments (e.g., AWS).
  • Develop and maintain infrastructure-as-code (IaC) security practices.
  • Design, implement, deploy, and maintain security tooling.
  • Oversight and management of  CNAPP platforms
  • Responsible for deployment, management, and maintenance of zerotrust platform(s) and supporting an overall zerotrust philosophy architecture and culture. 
  • Application Security:
  • Using static code analysis, dependency vulnerability scanning tools (Snyk) to identify and remediate vulnerabilities in application code. 
  • Management of CICD pipeline controls using Git (Github Actions) for enforcement of security controls. 
  • Collaborate with developers to identify and mitigate vulnerabilities in the software development lifecycle (SDLC).
  • Perform code reviews and provide guidance on secure coding practices.
  • Manage third-party dependency packages and container images for security and patching processes.
  • Perform vulnerability prioritization analysis based on severity and impact. 
  • Perform testing and validation application vulnerability patches. 
  • Security Operations 
  • Help build, maintain, and improve Security Orchestration and Automated Response (SOAR) practices to auto-remeidate and enrich security events. 
  • Responsible for building security altering based on relevant Indicators of Compromise (IoC) using log aggregation tools (Splunk, Observe, Sumologic) 
  • Activity participate in investigations and incident response activities, including being part of the incident response team, investigating alerts, and working with cross functional teams to resolve any active attacks or potential threats. 

Qualifications:

  • Ability to work effectively on a remote team in a collaborative, fast-paced, and dynamic environment.
  • Strong communication skills, with the ability to convey technical concepts to both technical and non-technical stakeholders.
  • A polite, professional demeanor and a commitment to fostering a positive and respectful workplace.

Required Experience & Skills:

  • Excellent problem-solving and critical-thinking skills.
  • Willingness to learn on the job and work outside of your comfort zone.
  • 3+ years of experience in a security engineering role or similar application engineering role.
  • Proficiency in securing cloud environments (AWS).
  • Strong familiarity with DevSecOps and CI/CD pipeline security.
  • Hands-on experience with security tools such as vulnerability scanners and code analysis tools. 
  • Understanding of OWASP Top 10 and overall secure application development principals. 
  • Working understanding of networking, encryption, authentication protocols, and secure application development.

Preferred Skills & Experience

  • Fluency in development languages like Java, JavaScript, Ruby, Ruby on Rails, etc  
  • Certifications such as CISSP, CEH, OSCP, or AWS Security Specialty.
  • Experience with container security (e.g., Docker, Kubernetes).
  • Knowledge of scripting languages (e.g., Python, Bash) for automation.
  • Knowledge of security frameworks (e.g., NIST, OWASP, CIS Benchmarks).
  • Contributions to open-source projects.
  • Hands-on experience with security tools such as SIEM, IDS/IPS, firewalls, and vulnerability scanners.

Get in on all the awesome at Instructure.

  • Competitive salary and 401k.
  • Medical, dental, disability, and life insurance.
  • HSA program, vision, voluntary life, and AD&D.
  • Tuition reimbursement.
  • Paid time off, 11 paid holidays, and flexible work schedules.
  • LifeStyle Spending Account

We’ve always believed in hiring the most awesome people and treating them right. We know that the more diverse we are, the more diverse our ideas will be and when we openly welcome those ideas, our environment is better and our business is stronger.

 

All Instructure employees are required to successfully pass a background check upon being hired.

Top Skills

AWS
Bash
Docker
Git
Github Actions
Kubernetes
Observe
Python
Snyk
Splunk
Sumologic

Similar Jobs

4 Days Ago
Remote
United States
Senior level
Senior level
Artificial Intelligence • Consumer Web • Machine Learning • Productivity • Sales • Software • Analytics
The Security Engineer will secure cloud environments, conduct code reviews, manage access control, set up monitoring systems, and ensure regulatory compliance.
Top Skills: AWSAzureDastGCPMfaOauthOwaspRbacSastSIEMTerraform
2 Days Ago
Remote
United States
180K-230K Annually
Senior level
180K-230K Annually
Senior level
Cybersecurity
Lead security assessments focusing on cloud-native architectures, develop custom security tools, and contribute to research and client projects. Collaborate with engineering teams to innovate in application security.
Top Skills: AWSAzureGCPGoJavaScriptKubernetesPythonRust
4 Hours Ago
Remote
Hybrid
Ames, IA, USA
Internship
Internship
Artificial Intelligence • Cloud • Internet of Things • Machine Learning • Analytics • Industrial
As a Security Engineer Intern at John Deere, you will design, develop, and integrate security technologies, improve processes, and support incident response automation.
Top Skills: AWSAzureDevops ToolsPython

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute
By clicking Apply you agree to share your profile information with the hiring company.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account