Senior Security Engineer

New Relic New Relic · Enterprise · Hyderabad, India · Security Governance

Senior Security Engineer at New Relic, focusing on safeguarding global infrastructure (servers, networks, cloud) and collaborating with teams to improve security risk understanding. Responsibilities include educating engineers on security best practices, providing security design guidance, performing reviews, mentoring junior members, and collaborating with various internal teams.

What you'd actually do

  1. Operates as one of the senior technical figures for the Infrastructure Assurance team and partner teams in the Asia Pacific Japan (APJ) region.
  2. Educate product/platform engineers on effectively applying security best practices related to multi-cloud, kubernetes, and internal applications and services.
  3. Provide security design guidance and perform security reviews for New Relic infrastructure and services, ensuring a secure by design model.
  4. Establish yourself as a security authority with a deep understanding of engineering and non-engineering team roadmap and priorities.
  5. Mentor/coach and remove technical roadblocks as needed for junior team members.

Skills

Required

  • Bachelor's degree in Computer Science or equivalent practical education and experience.
  • 4+ years of cloud or infrastructure engineering experience.
  • 2+ years of infrastructure security experience.
  • Experience securing infrastructure and services built in a multi-account AWS environment
  • Strong understanding of Identity and Access Management (roles, policies, SCP).
  • Experience performing security reviews and risk assessments in SaaS- and cloud-based environments.
  • Understanding of modern DevOps engineering and containerization.
  • Working understanding of common/best practice network security controls, authentication, and security protocols.
  • Working understanding of SOC 2, FedRAMP, CIS Critical 18, and PCI DSS frameworks.
  • Capability to effectively communicate with individuals of varying levels of technical expertise.
  • Ability to lead cross company objectives, work autonomously, navigate ambiguous situations, and identify innovative solutions.
  • Ability to draft/maintain clear and concise documentation.

Nice to have

  • 2+ years working with modern container technologies; Kubernetes is a bonus.
  • Ability to explain and advise on secure design and implementation of complex security problems, including the ability to dive into secure design with engineers.
  • Experience performing threat modeling.
  • Experience securing infrastructure and services built in Azure, or Google Cloud
  • Writing in and understanding an infrastructure orchestration solution, such as Terraform, Chef, or Ansible.
  • Proficiency in at least one programming language, like Python, Ruby, and/or Go.
  • Proven capability to improve various processes via automation.
  • An understanding of tradeoffs between reliability and security in a SaaS organization.

What the JD emphasized

  • 4+ years of cloud or infrastructure engineering experience.
  • 2+ years of infrastructure security experience.
  • Experience securing infrastructure and services built in a multi-account AWS environment
  • Strong understanding of Identity and Access Management (roles, policies, SCP).
  • Experience performing security reviews and risk assessments in SaaS- and cloud-based environments.
  • Understanding of modern DevOps engineering and containerization.
  • Working understanding of common/best practice network security controls, authentication, and security protocols.
  • Working understanding of SOC 2, FedRAMP, CIS Critical 18, and PCI DSS frameworks.