Senior Security Engineer, Infrastructure & Automation

Webflow Webflow · Enterprise · CA · Remote · Engineering

Senior Security Engineer, Infrastructure & Automation at Webflow, focusing on hardening cloud environments (AWS/GCP), embedding security into CI/CD, and building internal security platforms and automation for vulnerability detection and remediation. The role involves collaborating with infrastructure and security teams, securing Kubernetes, and responding to cloud security incidents. A key aspect is experimenting with agentic and AI-assisted approaches for security operations.

What you'd actually do

  1. Perform infrastructure security reviews across cloud services, network design, IAM, and platform components.
  2. Design, implement, and maintain secure AWS and GCP infrastructure following best practices (least privilege, network segmentation, encryption, monitoring).
  3. Partner with infrastructure and platform teams to embed security controls in CI/CD pipelines, infrastructure as code, and containerized environments.
  4. Own the cloud security posture management (CSPM) strategy, ensuring continuous compliance and automated detection of misconfigurations.
  5. Experiment with and operationalize agentic and AI-assisted approaches to security detection, analysis, and response as the threat landscape evolves.

Skills

Required

  • Cloud security
  • Infrastructure engineering
  • Security automation
  • AWS
  • GCP
  • Kubernetes
  • Containerized workloads
  • Infrastructure as code (Pulumi, Terraform, CloudFormation)
  • Network security concepts
  • Automation script authoring (Python, Go, Javascript, Typscript)
  • Security platforms and APIs

Nice to have

  • Security Operations
  • CI/CD pipeline security
  • Threat modeling
  • Risk assessments

What the JD emphasized

  • secure AWS and GCP infrastructure
  • security controls
  • cloud security posture management (CSPM)
  • security automation
  • agentic and AI-assisted approaches
  • 5+ years of experience
  • AWS and GCP services and security controls
  • Kubernetes and containerized workloads
  • infrastructure as code
  • network security concepts
  • 3+ years of automation script authoring for security tasks