Security Engineer
elotouchMilpitas (CA)
$130,400 per year
ApplyAbout the role
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process. Security Engineer
Regular Full-Time R & D Milpitas, CA, US
Salary Range: $130,400.00 To $179,000.00 Annually
We know touch - it's our only business. In fact, we invented the touchscreen over 50 years ago and haven't stopped since. Every 21 seconds, a new Elo touch screen is installed somewhere in the world. We obsess over details to exceed the highest quality standards. We don't just sell things. We offer solutions to tomorrow's challenges. Job Purpose & Responsibilities:
Elo is seeking an experienced Security Engineer to serve as a senior technical security leader within Software Engineering. This is a hands-on individual contributor role responsible for strengthening the security posture of Elo's Android devices, AWS cloud services, payment products, software development environments, and software supply chain. You will define and execute security engineering strategy, establish technical controls and standards, drive vulnerability remediation, and partner closely with Software Engineering, Product Security, Enterprise Security, IT, Product Management, Quality, Compliance, and external partners. The ideal candidate combines strong hands-on security engineering expertise with the ability to influence across teams and drive measurable security outcomes.
Key Responsibilities:
Define and execute the Software Engineering security strategy, roadmap, standards, and measurable objectives.
Integrate and operate SAST, SCA, secrets detection, IaC scanning, and security gates within CI/CD pipelines.
Drive software supply chain security, including dependency risk management, SBOMs, package governance, and AI-assisted development risks.
Establish code signing and artifact integrity across Android applications, firmware, BSP images, containers, payment applications, and release artifacts.
Strengthen AWS cloud security, including IAM, least privilege, MFA, encryption, network controls, logging, WAF, and security guardrails.
Improve container security, including hardened base images, vulnerability management, registry controls, and lifecycle management.
Lead Android/AOSP security activities, including CVE remediation, SELinux, Verified Boot, keystore/key attestation, and platform hardening.
Own vulnerability management across device, cloud, and payment environments, including prioritization, remediation SLAs, and validation.
Lead threat modeling, secure design reviews, penetration-test remediation, and security assessments.
Support security requirements related to PCI, EU RED/EN 18031, EU CRA, ETSI EN 303 645, NIST, and OWASP.Develop security metrics and provide technical reporting on vulnerabilities, remediation, control coverage, exceptions, and security risk.
Serve as a technical escalation point for release-blocking security findings and certification concerns.
Represent Software Engineering in security governance, audits, customer security discussions, and third-party assessments.
Provide security guidance, secure coding support, and technical coaching to engineering teams.
Minimum Qualifications:
Bachelor’s degree in computer science, Computer Engineering, Information Security, or a related technical field.8+ years of experiencein security engineering, software engineering, platform engineering, product security, or a related field.
Hands-on experience integratingSAST/SCA and security tooling into CI/CD pipelinesand driving remediation with development teams.
Strong working knowledge ofAWS security, including IAM, networking, encryption, logging, and cloud security posture management.
Practical experience with
Docker, Kubernetes, and container security .Ability to read and review code in at least two languages such asJava, Kotlin, C/C++, Python, Go, or Shell .Working knowledge ofCVE/CVSS, vulnerability management, threat modeling, and secure software development .Understanding ofcryptography, PKI, TLS, certificates, and key management .Demonstrated ability to influence and drive security outcomes across teams without direct authority.
Preferred Qualifications:
Experience implementingcode signingacross firmware, mobile, and container artifacts.
Android/AOSP securityexperience, including SELinux, Verified Boot, keystore, BSP, or platform security.
Experience withSBOM and software supply chain security, including SPDX/CycloneDX and tools such as JFrog Curation or Dependency-Track.
Experience with security platforms such asCycode, SonarQube, Fortify, Checkmarx, GitHub Advanced Security, Black Duck, Snyk, or Mend .Experience with hardened container images such asChainguard .Knowledge ofPCI-SSF, PCI-PTS, EU CRA, EU RED/EN 18031, ETSI EN 303 645, or IEC 62443 .Familiarity withOWASP Top 10, OWASP Mobile Top 10, OWASP SAMM, and NIST secure development practices .Security certifications such asCISSP, CSSLP, OSCP, GIAC, or AWS Security Specialty .Experience working within an enterprise security governance model where enterprise teams establish security guardrails and business units drive implementation.
What Success Looks Like:
In this role, you will help Elo move from reactive security remediation towardmeasurable, repeatable, engineering-driven security practices. Success includes stronger security controls, reduced vulnerability exposure, secure development pipelines, improved cloud and device security, reliable software supply chain controls, and demonstrable compliance with customer and regulatory requirements. Physical Demands Ability to lift up to OSHA single person lift requirements Ability to sit, stand, bend, or walk for prolonged periods of time Ability to travel domestically and internationally Must be able to work a standard full-time schedule
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
