Senior Security Engineer
Guidewire Software - United States
Hiring: Senior Security Engineer Company: Guidewire Software Location: United States Job Posted Time: 2026-09-16 11:56:41 Employment Type: Full-time Target Skills & Keywords : AWS, CI/CD, Change Management, CloudFormation, Configuration Management, DNS, EKS, GCP, GitHub Actions, Infrastructure as Code, Kubernetes, LLM, OWASP, Python, R, Terraform About the job Experience: •5+ years of experience in security engineering, cloud security, infrastructure security, DevSecOps, or equivalent practical experience. Required Skills: •Lead complex infrastructure security initiatives involving multiple teams, systems, and dependencies, with a primary focus on AWS cloud environments and CI/CD pipelines. •Design, implement, and operate security controls across AWS and applicable cloud platforms. •Build secure-by-default solutions using infrastructure as code, policy as code, CI/CD, and automation. •Improve cloud governance, security posture, and operational resilience through controls for cloud organization and account structure, access management integration, policy enforcement, logging and monitoring, data protection, configuration management, network security, and account lifecycle management. •Define and maintain security baselines for cloud accounts, operating systems, containers, AMIs, Kubernetes, networks, and supporting infrastructure. •Support cloud account onboarding, offboarding, inventory, configuration drift management, exception handling, and control validation. •Design and improve cloud and infrastructure network security, including network segmentation, traffic visibility, ingress and egress control, DNS, firewalls, routing, private connectivity, and related monitoring and enforcement mechanisms. •Secure CI/CD and software supply chains, including build and deployment workflows, dependencies, artifacts, containers, registries, third-party actions, secrets, and runner environments. Qualifications: •Typically 5+ years of experience in security engineering, cloud security, infrastructure security, DevSecOps, or equivalent practical experience. •Hands-on experience designing and operating secure AWS environments is required. Experience with Google Cloud Platform (GCP) is strongly preferred; experience with other cloud platforms is a plus. •Hands-on experience authoring, reviewing, testing, and troubleshooting infrastructure-as-code using Terraform, CloudFormation, or comparable technologies to deploy and manage security controls. •Hands-on experience building, securing, testing, and operating CI/CD pipelines, preferably using GitHub Actions or comparable platforms, including pipeline automation, secrets management, artifact handling, and runner security. •Hands-on scripting or programming experience, using Python, Go, or another appropriate language, to automate security tasks, integrate controls, and troubleshoot security tooling. •Practical knowledge of cloud and infrastructure networking, including segmentation, routing, DNS, firewalls, ingress and egress controls, private connectivity, and network telemetry. •Knowledge of threat modeling, secure design, vulnerability management, security testing, risk assessment, monitoring, and incident response. •Demonstrated capacity to evaluate security-control effectiveness using evidence, operational feedback, exceptions, findings, and relevant metrics. •Demonstrated experience building, operating, or contributing to security measurement and analysis capabilities, such as asset inventories, control-coverage reporting, configuration-drift analysis, attack-path analysis, or security data platforms. •Solid functional working knowledge of software supply-chain security concepts, including SBOMs, artifact signing, provenance, dependency management, secure registries, and CI/CD runner hardening, with the ability to evaluate, design, implement, or measure related controls and automation. Compensation: •$133,000 - $199,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!