Vanta
Senior Security Engineer
Job Summary
The Senior Security Engineer at Vanta is responsible for identifying and addressing security risks through activities such as threat modeling, penetration testing, and vulnerability management. The role involves collaborating with cross-functional teams to review project plans, develop security tools, and deliver training to bridge knowledge gaps. The engineer will contribute to security policies, standards, and architectural discussions to ensure secure product development and operational excellence. A strong emphasis is placed on independent ownership, communication skills, and experience with security testing methods.
Required Skills
Benefits
Job Description
At Vanta, our mission is to secure the internet and protect consumer data. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it.
As a Senior Security Engineer at Vanta, you’ll own projects with impact across the business to help us run an efficient and highly effective security team. The security team at Vanta ensures that we are a trusted and trustworthy steward of sensitive data. We also contribute subject matter expertise to the product, sales, marketing, support, and engineering functions, given the nature of our business.
You’ll join Vanta’s Security organization, which provides essential security operational services, is directly involved in the software development process and building tools to make it easy for developers to ship products securely, sets policies and standards regarding enterprise-wide security requirements, and offers advisory services to enable our business to thrive while effectively managing risk. If you’re someone who has high initiative and enjoys problem solving while having impact at a high-growth company, we would love to hear from you!
What you’ll do as a Senior Security Engineer at Vanta:
Participate in team exercises to identify potential security risks, including threat modeling and tabletop scenarios
Contribute to complex prioritization discussions around which risks are the most important to solve next
Plan projects to address the risks we prioritize, and coordinate with cross-functional stakeholders across the company to execute those projects
Build maintainable programs to implement operational excellence where ongoing work is needed to achieve our goals (e.g. vulnerability management)
Collaborate with engineers to review project plans and pull requests for potential security concerns and improvements
Build, customize, and run tools to increase the maturity of our security program without adding undue friction to the company’s operations
Support ongoing bug bounty and penetration testing programs
Establish and maintain a network of security champions
Understand security knowledge gaps of the development organization and help to deliver training to address gaps
Provide input into architectural discussions to enable teams to innovate in a secure and repeatable manner
How to be successful in this role:
A track record of independent ownership of areas of responsibility
Experience with threat modeling, red teaming, penetration testing, or other means of identifying security issues
Some experience writing code, and an ability to read code to find security flaws
Strong collaboration and communication skills, with deep developer empathy
Highly organized project management skills
What you can expect as a Vantan:
Industry-competitive compensation
100% covered medical, dental, and vision benefits with dependents coverage
16 weeks fully-paid parental Leave for all new parents
Health & wellness and remote workplace stipends
Family planning benefits through Carrot Fertility
401(k) matching
Flexible work hours and location
Open PTO policy
11 paid holidays in the US
Offices in SF, NYC, Dublin, and Sydney
To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.
#LI-remote
At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply.
About Vanta
We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security.From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged.
Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent.
Vanta
Vanta automates the complex and time-consuming process of SOC 2, HIPAA, ISO 27001, PCI, and GDPR compliance certification. Automate your security monitoring in weeks instead of months.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.