Security Engineer II

Chewy Chewy · Retail · Plantation, FL +1

Seeking a DevSecOps Engineer II to join Chewy's technology team. The role involves securing public cloud environments by developing and integrating security tools, writing automation scripts, and implementing scalable solutions. Responsibilities include evaluating and integrating edge technologies, providing security guidance through architecture and code reviews, collaborating with various teams, ensuring applications and infrastructure meet security requirements, assisting the Security Operations Center, developing automation and observability workflows for edge services, and participating in on-call rotations.

What you'd actually do

  1. Drive the evaluation and integration of edge technologies (WAF, firewall, bot protection, content monitoring and remote access solutions) and providers, partnering with other security, infrastructure, and application teams to align controls with business and risk objectives.
  2. Provide security guidance and risk management through architecture design reviews, code reviews and standard documentation of services running in our multi-cloud environments.
  3. Collaborate with Developers, Site Reliability Engineering, Vulnerability Management, and Security Operations teams to achieve shared security goals.
  4. Develop automation, observability, and performance tuning workflows for edge services to continuously improve detection fidelity, response speed, and delivery efficiency.
  5. Engage in on-call rotation and provide operational support for security alerts, escalations, and incidents, helping to ensure 24/7 resiliency.

Skills

Required

  • Terraform or equivalent infrastructure as code language or scripting language
  • Groovy for Jenkins pipeline file development
  • AWS native security services: Guard Duty, Security Hub, Trust Advisor, Organization Delegated Administrator, IAM, KMS
  • GCP native security services: Security Command Center, IAM, Google Cloud Storage, Logs and Log Sinks
  • common technical controls across security domains (logical access, configuration management, security operations, etc.)
  • analytical and problem-solving skills
  • Cloud Security Posture Management (CSPM) platform technologies on public clouds
  • public cloud container technologies such as ECS, EKS, GKE, etc.
  • balance multiple priorities
  • team-oriented
  • customer first mindset

Nice to have

  • Python, Go or Ruby
  • commercial security tools and platforms
  • Open Policy Agent – Rego
  • Git and GitOps concepts
  • fast-paced e-commerce environment
  • investigating security incidents in public clouds (AWS, Google.)

What the JD emphasized

  • security standards
  • cloud security objectives
  • security initiatives
  • security guidance
  • risk management
  • security goals
  • security requirements
  • defensive posture
  • security alerts
  • security-first thinking