Senior Security Engineer (FedRAMP)
- Seniority
- Senior
- Location
- San Jose, CA, USA
- Posted
- 5d ago
<div class="content-intro"><div class="elementToProof"> <p>Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.</p> </div></div><h4><strong>About the Role</strong></h4> <p><span data-contrast="auto">We’re looking for a </span><span data-contrast="auto">Senior Security Engineer</span><span data-contrast="auto"> to support the development and growth of </span><a href="https://www.veeam.com/products/veeam-data-cloud.html"><span data-contrast="none"><span data-ccp-charstyle="Hyperlink">Veeam Data Cloud (VDC)</span></span></a><span data-contrast="auto">, our cloud-native SaaS platform. This role owns hands-on security engineering for VDC’s regulated environments, starting with our FedRAMP boundary but extending to the broader set of regulated customer needs we will take on as our platform grows. VDC delivers high-trust, secure data protection services on </span><span data-contrast="auto">Microsoft Azure and AWS</span><span data-contrast="auto"> for customers in regulated industries.</span><span data-ccp-props="{"335559739":120}"> </span></p> <p><span data-contrast="auto">You’ll partner closely with product, platform engineering, and SRE to embed compliant, secure-by-design patterns into everything we ship — designing controls that satisfy NIST 800-53 today but will adapt to other frameworks as we expand. </span><span data-ccp-props="{"335559739":120}"> </span></p> <p><span data-contrast="auto">This is a role with room to shape how security engineering scales across VDC’s regulated footprint: you will own the domain end to end, work independently on complex, ambiguous problems, and set baselines, review practices, and remediation standards to keep VDC compliant and secure at scale.</span></p> <p data-pm-slice="1 1 []"><span style="text-decoration: underline;">Due to the fact that this position will deal with highly sensitive data and will support federal customers, we are only considering US citizens at this time. Security clearance is not required, but there is a slight chance it maybe requested in the future</span></p> <h4 id="id-📝JobDescription&JobPostGuidelines-WhatYou’llDo.1"><strong>What You’ll Do</strong></h4> <ul> <li><span data-contrast="auto">Champion secure design patterns that enable compliance-driven engineering across VDC’s Cloud environments, including VDC-wide standards such as supply chain security</span></li> <li><span data-contrast="auto">Support the design and onboarding of new workloads into regulated environments from a security compliance perspective</span></li> <li><span data-contrast="auto">Partner with VDC Engineering to harden shared infrastructure (e.g. VMs, containers, and operating systems) against secure baselines such as STIGs and CIS benchmarks</span></li> <li><span data-contrast="auto">Oversee and support vulnerability scanning alongside the Platform team, providing remediation guidance and tracking fixes against SLAs</span></li> <li><span data-contrast="auto">Support configuration management change control and configuration baseline compliance with Platform Engineering and SRE</span></li> <li><span data-contrast="auto">Review significant architecture changes across our regulated environments and provide security input on approvals</span></li> <li><span data-contrast="auto">Build reusable, framework-agnostic guardrails and evidence so security controls scale across FedRAMP, sovereign cloud, and emerging regulatory requirements</span></li> <li><span data-contrast="auto">Review application and platform code and identify security deficiencies</span></li> <li><span data-contrast="auto">Align commercial, government, and other product roadmaps so controls and standards carry cleanly across environments and frameworks</span></li> <li><span data-contrast="auto">Participate in an on-call rotation shared across the Security Engineering team to respond, triage, and resolve alerts to closing</span></li> </ul> <h4 id="id-📝JobDescription&JobPostGuidelines-WhatYou’llDo.1"><strong>What You’ll Bring</strong></h4> <ul> <li><span data-contrast="auto">8+ years in security engineering, with hands-on experience securing cloud environments (strong preference for experience in Azure and/or AWS)</span></li> <li><span data-contrast="auto">Experience delivering cloud products to meet regulated compliance requirements such as government (FedRAMP, CMMC, IL2/IL4/IL5, sovereign cloud), financial services (PCI-DSS), and/or healthcare (HIPAA, HITRUST)</span></li> <li><span data-contrast="none">Ability to translate specific compliance controls into concrete architecture and operational decisions (e.g., how an audit logging requirement drives log retention design, or how boundary protection requirements shape network segmentation)</span></li> <li><span data-contrast="auto">Working knowledge of NIST 800-53, including continuous monitoring, vulnerability management, and configuration management standards</span></li> <li><span data-contrast="auto">Experience hardening infrastructure to secure baselines such as STIGs or CIS benchmarks</span></li> <li><span data-contrast="auto">Strong understanding of cloud security fundamentals in identit