Security Operations Engineer

Posted 2 days ago

magnitude consultingNew York (NY)

SENIORITY

Manager

SALARY

$150 K–$185 K

Apply

About the role

Security Operations Engineer
Location: New York City
Compensation: $150K–$185K base + bonus + equity We’re partnering with a high-growth technology business looking to add a Security Operations Engineer to its growing Security function. This is a hands-on security role focused on identifying, understanding and driving remediation of security risks across cloud and corporate environments. It is not a traditional SOC position or a heads-down software engineering role. You’ll work closely with Dev Ops, SRE, Application Security, Product Engineering, GRC and IT teams — identifying security issues, understanding the risk they create, and working with the relevant teams to get them resolved.
What You’ll Be Doing: Monitor cloud environments for security risks, misconfigurations, exposed assets, excessive permissions and emerging vulnerabilities. Work with CSPM/CNAPP and other cloud security tooling to identify and investigate potential risks. Partner closely with Dev Ops and SRE teams around cloud infrastructure, CI/CD pipelines and infrastructure-as-code. Identify vulnerabilities and configuration issues and help engineering teams understand the risk and appropriate remediation. Support security incident investigation, remediation and documentation. Contribute to vulnerability management, attack surface management and broader security operations. Work across Security, Engineering, Dev Ops, GRC and IT to improve security practices. Help assess and improve the security tools and processes used across the organisation. Contribute to and maintain internal security tooling, including Python-based tools. As the function grows, there is potential to take on additional responsibility and potentially help build or lead a small Security Operations team.
What We’re Looking For: Experience within cloud security, security operations, infrastructure security, Dev Sec Ops or a related security engineering environment. Experience working within a corporate or enterprise environment. Strong understanding of cloud security across AWS and/or Azure. Experience identifying cloud misconfigurations, vulnerabilities, permissions issues and infrastructure security risks. Exposure to CSPM/CNAPP platforms such as Wiz, Upwind or similar technologies is highly desirable. Understanding of CI/CD, SDLC, Git, Terraform and modern Dev Ops workflows. Experience with vulnerability management and/or attack surface management. Security incident investigation and remediation experience. Coding or scripting experience, ideally Python. Strong communication skills and the ability to work effectively with Dev Ops, SRE and Engineering teams. The Profile We’re looking for someone who can look at a cloud or engineering environment, identify where the security risk sits, understand why it matters and communicate that effectively to the teams responsible for fixing it. You do not need to be the engineer personally deploying every fix. The important part is having enough technical understanding to challenge, advise and work effectively with engineering teams to drive remediation. We’re particularly interested in people who are naturally curious about security and technology and continue developing their knowledge outside of their day-to-day responsibilities. This is a strong opportunity for someone looking to take ownership within a growing Security Operations function, with genuine longer-term leadership potential.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this