Senior Security Software Engineer - Cloud & Infra Security

Remote Full-time
About the position StubHub is on a mission to redefine the live event experience on a global scale. Whether someone is looking to attend their first event or their hundredth, we’re here to delight them all the way from the moment they start looking for a ticket until they step through the gate. The same goes for our sellers. From fans selling a single ticket to the promoters of a worldwide stadium tour, we want StubHub to be the safest, most convenient way to offer a ticket to the millions of fans who browse our platform around the world. About the team: StubHub Cloud & Infrastructure Security Engineering is seeking a senior engineer to enhance our security posture within the cloud and infrastructure domains. The perfect candidate will possess extensive experience in cloud security architecture, network security, and infrastructure automation, as well as a familiarity with container and operating system security. Location: Hybrid (3 days in office/2 days remote) – New York, NY or Santa Monica, CA or Aliso Viejo, CA Responsibilities β€’ Develop secure Cloud Account Architectures, focusing primarily on AWS, while understanding and navigating the trade-offs of various cloud architectures. β€’ Design and implement network security strategies that leverage security groups, NACLS, routing domains, and multi-tiered subnet architectures to ensure a defense-in-depth approach. β€’ Manage critical security logging and monitoring infrastructure for cloud-native and third-party data sources, ensuring their efficient shipping to Data Lakes and integration with visualization platforms. β€’ Operate and manage Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP), such as Wiz, Orca, Palo Alto Networks Prisma, and Rapid7 ICS. β€’ Deploy configurations and infrastructure using Infrastructure as Code (IaC) frameworks, such as Terraform, Cloud Formation, and Pulumi. β€’ Develop and implement governance strategies for infrastructure deployment that integrate security best practices and enhance developer productivity. β€’ Architect and implement workload identity services, such as SPIRE (Spiffe), in a heterogeneous multi-cloud environment. β€’ Architect and maintain PKI and secrets management platforms to ensure secure storage and access to sensitive information. β€’ Write and maintain production-quality APIs to automate security processes, benefiting infrastructure and developer workflows. Requirements β€’ Expert level experience in AWS cloud account architecture. β€’ Expert level knowledge in Network Security, including experience with AWS networking primitives: Security Groups, Network Access Control Lists (NACLS), Subnetting, Routing, and egress traffic filtering mechanisms. β€’ Expert level proficiency in Identity & Access Management (IAM) Security, including experience with architecting AWS IAM roles & policy architectures for both human and machine access. β€’ Expert level communication skills and the ability to work effectively across teams. β€’ Expert level experience deploying and maintaining configurations and infrastructure using Terraform. β€’ Expert level experience with modern CSPM and CWPP tools (e.g., Wiz, Orca, Prisma, or Rapid7). β€’ Intermediate level experience with Secrets / key Management Platforms (e.g., AWS KMS, AWS Secrets Manager, Hashicorp Vault). β€’ Expert level experience in building and implementing IaC governance strategies that combine security best practices while enabling developer productivity. β€’ Intermediate level experience in architecting & managing Spire (Spiffe) and Service Mesh services. β€’ Intermediate level proficiency in Python or Go, and Bash scripting. β€’ Intermediate level experience in container & operating system hardening. β€’ Intermediate level experience in building & maintaining Web Application Firewalls. β€’ Intermediate level familiarity with security frameworks (e.g., PCI DSS, CIS, ISO 27001, NIST CSF). Nice-to-haves β€’ Intermediate level experience in architecting & implementing internal PKI & Secrets Management services. β€’ Intermediate level knowledge of Kubernetes (K8s) Security foundations, including admission controllers, K8s Network Policies, K8s RBAC, and K8s Ingress architectures. β€’ Intermediate level proficiency in DDoS mitigation techniques using AWS Shield, CDN traffic scrubbing, and origin protection mechanisms. β€’ Intermediate level proficiency in Azure. Benefits β€’ Accelerated Growth Environment: An environment designed for swift skill and knowledge enhancement, where you have the autonomy to lead experiments and tests on a massive scale. β€’ Top Tier Compensation Package: Competitive base, equity, and upside that tracks with your impact. β€’ Flexible Time Off: Enjoy unlimited Flex Time Off, giving you the flexibility to manage your schedule and take time to recharge as needed. β€’ Comprehensive Benefits Package: Prioritize your well-being with a comprehensive benefits package, featuring 401k, and premium Health, Vision, and Dental Insurance options. Apply tot his job
Apply Now β†’

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Experienced Remote Virtual Support Data Entry Specialist – FedEx Shipments and Deliveries Administration

Remote

Experienced Data Entry Clerk Assistant – Remote Online Job Opportunity for Accurate and Organized Individuals at blithequark

Remote

Experienced Remote Live Chat Support Specialist – Flexible Part-Time Customer Service Opportunity with Competitive Pay and Growth Prospects

Remote

**Experienced Customer Service Representative – Delivering Exceptional Northern Experiences from the Comfort of Your Home**

Remote

3D Realistic Still Life Render Artist - Contract to Hire

Remote

Operations Coordinator / Remote / Full Time (579)

Remote

Employelevate | Teleworking Yelp Spam Comments Removal - Wfh

Remote

Entry Level Data Entry Clerk – Remote Work from Home Opportunity with blithequark for Career Growth and Development

Remote

**Experienced Customer Service Representative – Remote Part-Time Opportunity with arenaflex**

Remote

Experienced Retail Coach and Operations Manager Trainee - Store 5858 (USA)

Remote
← Back