Senior Security Infrastructure Engineer
Sezzle
IndiaremotePosted 8 days ago
Skill Required
Security-EngineeringInfrastructure-SecurityDevSecOpsCloud-SecuritySecurity-OperationsSr.-Infrastructure-Security-EngineerSecurity-Infrastructure-EngineerSenior-Cloud-Infrastructure-Security-EngineerInfrastructure-Security-EngineerSecurity-EngineerSenior-Infrastructure-EngineerSenior-Information-Security-EngineerInfrastructure EngineerSecurity EngineersecuritySOCEngineeringKubernetesautomationObservabilitybuildingISO 27001Embedded Cfintechetc.)designLinuxCI/CDOWASPCloudSIEMAWSandElasticsearchCICDAIFulltime
Key highlights
- $5,000 - $9,500 per month (Gross in USD)
- 6+ years of experience required
- Hands-on security operations with exploratory and design work
- Must have experience working with Claude or equivalent large language model tools
- Senior-level principal development role
Role overview
With a mission to financially empower the next generation, Sezzle is revolutionizing the shopping experience beyond payments, blending cutting-edge tech with seamless, interest-free installment plans that make shopping smarter and more accessible. The company is building an innovative, dynamic team passionate about creating more than just a transaction but a truly unique shopping journey, driving real impact on merchant sales through increased conversions and higher order values. As they continue to shape the future of fintech and retail, Sezzle is building infrastructure and capabilities to redefine how people discover, interact with, and purchase the things they love.
Responsibilities
- Lead and operate vulnerability management across infrastructure, platforms, and applications - including internal scans, dependency analysis, and external findings, validating true positives and driving remediation with engineering teams
- Build, operate, and mature SIEM/XDR capabilities, including log ingestion, detection rule development, alert tuning, and investigation workflows
- Investigate and respond to security incidents across cloud infrastructure and applications, performing root cause analysis and driving long-term fixes
- Design and implement detection strategies for suspicious activity, including data exfiltration patterns using application and database telemetry
- Lead and contribute to threat modeling exercises and security design reviews to identify risks early and strengthen architecture
- Apply deep expertise in AWS and Kubernetes to design, secure, and improve resilient and secure cloud infrastructure at scale
- Drive infrastructure and CI/CD hardening initiatives, with a focus on reducing software and container supply chain risk
- Lead efforts to implement and improve dependency and container supply chain risk detection systems and controls
- Partner closely with engineering teams to remediate vulnerabilities and improve secure development and deployment practices
- Support and implement security controls aligned with PCI DSS, SOC 2, and other compliance requirements
- Develop and implement automation (including AI where appropriate) to improve efficiency in security operations, detection, and response
- Triage and validate external security findings, distinguishing true positives and coordinating remediation
Requirements
- 6+ years of experience in security, software, or infrastructure engineering, with hands-on experience securing cloud-based production systems and working with real-world security challenges
- Experience contributing to threat modeling and security design reviews for modern systems
- Strong hands-on experience in vulnerability management, including scanning, triage, validation, remediation coordination, and verification
- Experience working with SIEM platforms (e.g., Wazuh, Splunk, ELK) for detection engineering, monitoring, and incident response
- Practical experience triaging findings from vulnerability scanners and bug bounty programs
- Strong knowledge of AWS, Linux, and Kubernetes infrastructure, including security architecture, hardening, and operational best practices
- Experience improving infrastructure security, including CI/CD hardening and mitigating software supply chain risks
- Experience with container and dependency security tools (e.g., Snyk, Trivy, Grype, etc.)
- Ability to investigate issues directly using logs, cloud tooling, and system-level data
- Knowledge of common security vulnerabilities and mitigation strategies (OWASP, SANS, etc.)
- Working knowledge of compliance frameworks such as PCI DSS and SOC 2
- Demonstrated experience working with Claude or equivalent large language model tools is required; candidates must be comfortable leveraging AI to enhance productivity, research, and communication
Nice to have
- Experience designing and tuning detection rules, reducing alert noise, and improving investigation workflows
- Strong understanding of cloud-native security controls, including IAM, network segmentation, and container security
- Familiarity with log-based detection, telemetry pipelines, and security analytics use cases
- Experience designing secure CI/CD workflows that reduce exposure to vulnerable dependencies and untrusted artifacts
- Ability to assess application and infrastructure risk and translate findings into actionable improvements
- Experience aligning technical security work with regulatory and compliance expectations
- Experience using automation and AI to reduce manual effort and improve consistency at scale
Additional details
- The salary range for this role is $5,000 - $9,500 per month (Gross in USD)
- Sezzle's Technology Stack: Languages: Golang, Typescript, Python; Frontend: Typescript - React and React Native; Backend: Golang; Database: MySQL, Postgres, Elasticsearch; DevOps & Cloud: AWS, Kubernetes; Version Control: Git; CI/CD: Gitlab; Testing: Developer and AI-driven, focus on automated end-to-end, integration, and unit tests; Open Source: Sezzle is focused on using open source, and we build what we can before buying!
- For this principal development role, with 6+ years of experience, the compensation range is $5,000 - $9,500 USD based on experience level per month and in gross amount
- Sezzle is not defined by a certain set of perks designed to give the illusion of the traditional startup culture, but rather, it is the visible example living in every employee that we hire
- Remote position; #Li-remote #full-time