Avatar for Roofr
Roofr
Actively Hiring
All in One, Roofing CRM
  • B2B
  • Growth Stage
    Expanding market presence
  • Top Investors
    This company has received a significant amount of investment from top investors
  • +1

Senior Security Engineer

Posted: 3 days ago• Recruiter recently active
Hires remotely in
Visa Sponsorship

Not Available

RelocationNot Allowed
Hiring contact
Mariela Orozco
Employee
image

About the job

As Senior Security Engineer, you'll report to the VP of Engineering and work closely with the CTO and DevOps as part of Roofr's security guild. You'll contribute directly to improving Roofr's security posture — sharpening what's already in place and driving it forward as the company scales. You'll own the tools and processes that detect and stop threats, partner with engineering on secure-by-design practices, and act as the front-line responder when something goes wrong.

What You’ll Get to Do

  • Own design and hardening of security infrastructure across cloud environments — network segmentation, firewalls, IDS/IPS, VPNs, WAF, and endpoint detection and response (EDR)
  • Lead vulnerability management end to end: run assessments and authenticated scans, triage and prioritize by exploitability and blast radius, and drive remediation SLAs with engineering
  • Build and tune detection content (SIEM/SOAR rules, alerting logic) against real attack techniques — not just default vendor signatures
  • Act as incident commander for security incidents: contain, eradicate, run forensics, and write the post-incident review
  • Threat-model new features and infrastructure changes before they ship — catch design-level risk, not just implementation bugs
  • Own IAM hygiene and cloud security posture (least privilege, key/secret management, network boundaries) across production AWS accounts
  • Write, enforce, and maintain security policies and standards — own them as living controls, not documents that sit in a drive
  • Own Roofr's compliance program end to end: map controls to NIST CSF 2.0, SOC 2, and CCPA/CPRA, run the audits, close the gaps, and keep evidence current between them
  • Run tabletop exercises and incident playbook drills
  • Push secure-by-design practices into engineering workflows — threat modeling in design review, security requirements in the SDLC, not a gate bolted on at the end

What You’ll Bring to the Role

Qualifications

  • Bachelor's degree in computer science, IT, cybersecurity, or equivalent hands-on experience
  • 5-8+ years in security engineering, incident response, or related infrastructure roles, including time as the primary or senior responder on real incidents
  • Certifications are a strong plus — CISSP, OSCP, GCIH, or CEH

Technical

  • Deep network security fundamentals — firewalls, VPNs, routing/segmentation, network boundaries, TLS, DNS, and how attackers actually abuse them
  • Hands-on cloud security in AWS — IAM policy design, VPC architecture, KMS/secrets management, CloudTrail/GuardDuty or equivalent
  • Real incident response experience — triage, containment, forensics, root cause, not just theory from a course
  • Working knowledge of SIEM/SOAR tooling, writing detection logic (Python/Bash), and building your own tooling when nothing off-the-shelf fits
  • Fluent in compliance frameworks — NIST CSF 2.0, SOC 2, and CCPA/CPRA — and translating controls into policy people actually follow
  • Strong software engineer at heart — comfortable reading and writing real application code, not just scripts, so you can dig into the codebase directly instead of filing a ticket and waiting

Competencies

  • Confident being the only security voice in the room — makes the call and owns it
  • Translates technical risk into business terms leadership can actually act on
  • Calm and decisive under incident pressure; documents as they go, not after
  • Ownership-oriented; builds the process that doesn't exist yet instead of waiting for one
  • Strong individual contributor who wants to stay hands-on — this role builds the foundation directly, it doesn't lead from the side

Bonus Points:

  • Experience using AI/LLM tooling for threat intelligence — alert triage, detection summarization, or hunting workflows — not required, but a plus for a team building modern security practice from scratch
  • Familiarity with GDPR — a plus as Roofr's customer base grows internationally
  • Experience with PHP/Laravel — a plus for digging into Roofr's own codebase directly, not required
  • Comfortable around Postgres — helpful, not required

About the company

Roofr company logo

Roofr

Actively Hiring
All in One, Roofing CRM51-200 Employees
  • B2B
  • Growth Stage
    Expanding market presence
  • Top Investors
    This company has received a significant amount of investment from top investors
  • YC Funded
    Startup funded by Y Combinator
Learn more about Roofr image

Funding

AMOUNT RAISED
$12M
FUNDED OVER
2 rounds
Rounds
B
Undisclosed amount
Series B - Jan 2025+1

Perks

Medical, Dental and Vision start day 1
100% Remote
Your first week of employment is mandatory PTO!
1 Friday off per month (we call those our laundry days!)
Company wide paid shutdown for the week between Christmas and New Years
Ample learning and development opportunities to continue growing your career
Weekly Friday paydays!

Founders

Kevin Redman
CTO
Toronto
image
Richard Nelson
CEO
Toronto
image
View the team image

Similar Jobs

Sosuv Consulting company logo
Sosuv Consulting
We provide specialised Product, Software Development and Support services to the global fi
Deepgram company logo
Deepgram
AI speech API for transcription with human-level understanding
Scale AI company logo
Scale AI
Accelerate the development of AI applications
Meelance company logo
Meelance
Elevating Media and Entertainment Careers through Discovery and Connection