Senior Security Engineer, Infrastructure & Cloud Security
Senior Security Engineer, Infrastructure & Cloud Security
Why We Have This RoleAs Qualtrics continues to expand the Experience Management (XM) SaaS platform, we must ensure that we’re protecting our customers and their data by building and operating secure systems. With over one thousand software & system engineers contributing to Qualtrics XM every day, we have a large attack surface to evaluate and secure. This role is critical to this mission.
Qualtrics is seeking an experienced security engineer/architect with a passion for security and demonstrated expertise in cloud and infrastructure security. The selected candidate will provide technical leadership and subject matter expertise within the Infrastructure Security team and across the product engineering organization.
The Infrastructure Security team is responsible for measures to improve and ensure the security of infrastructure used to operate and deliver Qualtrics SaaS products. The team’s scope includes cloud (IaaS/PaaS), workload orchestration (Kubernetes, Nomad), containers, data stores and server OS, as well as CI/CD and related systems. Infrastructure Security works in collaboration with other teams within the Information Security organization, including application security, vulnerability management, network security, security operations and incident response, and security assurance. The team also partners with our infrastructure (i.e., SRE) and platform engineering and developer experience teams.
How You’ll Find Success- You will define infrastructure and cloud security program strategy and architecture, identify and remediate risks, recommend and drive specific improvements
- Collaborate effectively with the Qualtrics engineering organization and fellow security team members; socialize security risks, solutions and and architecture
- Mentor and support a team of skilled security engineers to help them
How You’ll Grow
- Solve challenging security, technical and process challenges which require creative thinking and continuous learning
- Learn new technologies, cloud platforms/services and other infrastructure being introduced regularly within the organization in order to provide accurate and comprehensive security guidance
- Develop and exercise project management and leadership skills to execute on the program roadmap
- Review system designs and implementations, and consult with engineers across the organization to identify and/or avoid security issues through alignment with security standards and best practices; document and ensure security issues are appropriately remediated
- Leverage your accumulated subject matter expertise of Qualtrics systems and infrastructure to propose design patterns and drive architectural improvements which address classes of security flaws in the platform
- Develop and implement the cloud & infrastructure security architecture and contribute to program strategy and roadmap plans
- Document and improve cloud/infrastructure standards and guidelines
- Promote DevSecOps principles and implement Infrastructure as Code (IaC) scanning and policy enforcement to ensure new systems deployed via Terraform, AWS CloudFormation, Code Development Kit or similar methods are secure and compliant with standards and guidelines
- Deliver training and provide mentoring to engineers and staff on security topics
- Perform the selection, design, development, implementation and management of automated security testing tools (e.g., cloud security posture management (CSPM), network/host/image vulnerability scanners); maintain relationships with product vendors
- Leverage development and automation skills to solve security problems, integrate security systems, streamline processes and replace manual work
What We’re Looking For On Your Resume
- Bachelor’s degree in Computer Science, Cybersecurity or a related field
- Over 5 years of relevant work experience
- Experience as a senior security engineer in infrastructure or cloud security
- Multiple years of experience managing and securing AWS services and workloads
- Experience leading multi-month security projects and initiatives that require collaboration with teams across an organization
- Sound understanding of cloud security vulnerabilities, defense techniques and security best practices, including AWS-specific security practices and present-day threats
- Strong working knowledge of AWS services and security concepts including Service Control Policies (SCPs), Identity and Access Management (IAM), VPCs, ELBs, CloudTrail, and security groups
- Experience with modern cloud infrastructure, including EC2, Linux-based operating systems, docker containers, workload orchestration (Kubernetes, Nomad), data stores (relational DBs, NoSQL and document DBs (Elasticsearch), object stores (S3)), event streaming (Kafka)
- Knowledge of system and infrastructure hardening and monitoring best practices
- Experience managing vulnerability scanning tools and/or CSPM
Bonus Points
- Experience with assessing/securing the infrastructure of large, complex SaaS applications
- One or more relevant security certifications (AWS Certified Security - Specialty, CCSP, CCSK, GCSA, AWS Certified Solutions Architect or DevOps Engineer)
- Experience with securing Azure and/or Google Cloud Platform (GCP)
- Prior full time SRE, cloud engineering or software development experience
- Experience with agile methodologies for project management
- We work with a wide array of modern technologies and need to scale our solutions to tens of thousands of end points, thousands of engineers, and worldwide data centers and cloud environments
- We emphasize establishing a career development plan and will help you to find meaningful work assignments, learning opportunities and mentorships which will aid your growth and developmentWe work closely with our peer platform security teams and enjoy coming together in person and remotely to build relationships and have fun
- Qualtrics pays 100% of the healthcare benefit premiums for employees and their dependents.
- Catered lunches, free snacks and drinks
- Full time employees receive an annual experience bonus after their first year of employment. Qualtrics Experience Bonus is a program designed to provide experiences to our employees they might not otherwise have.
- We spend 10% of our time on individual engineering growth activities every quarter
- Quarterly book budget to continue learning and quarterly fitness budget