Job Board
LogoLogo

Get Jobs Tailored to Your Resume

Filtr uses AI to scan 1000+ jobs and finds postings that perfectly matches your resume

StubHub Logo

Senior Security Software Engineer - Cloud & Infra Security

StubHub

Salary not specified
Sep 16, 2025
Aliso Viejo, CA, US
Apply Now

StubHub is looking to enhance its security posture within the cloud and infrastructure domains by hiring a senior engineer with extensive experience in cloud security architecture, network security, and infrastructure automation.

Requirements

  • Expert level experience in AWS cloud account architecture.
  • Expert level knowledge in Network Security, including experience with AWS networking primitives: Security Groups, Network Access Control Lists (NACLS), Subnetting, Routing, and egress traffic filtering mechanisms.
  • Expert level proficiency in Identity & Access Management (IAM) Security, including experience with architecting AWS IAM roles & policy architectures for both human and machine access.
  • Expert level experience deploying and maintaining configurations and infrastructure using Terraform.
  • Expert level experience with modern CSPM and CWPP tools (e.g., Wiz, Orca, Prisma, or Rapid7).
  • Intermediate level experience with Secrets / key Management Platforms (e.g., AWS KMS, AWS Secrets Manager, Hashicorp Vault).
  • Intermediate level proficiency in Python or Go, and Bash scripting.

Responsibilities

  • Develop secure Cloud Account Architectures, focusing primarily on AWS, while understanding and navigating the trade-offs of various cloud architectures.
  • Design and implement network security strategies that leverage security groups, NACLS, routing domains, and multi-tiered subnet architectures to ensure a defense-in-depth approach.
  • Manage critical security logging and monitoring infrastructure for cloud-native and third-party data sources, ensuring their efficient shipping to Data Lakes and integration with visualization platforms.
  • Operate and manage Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP), such as Wiz, Orca, Palo Alto Networks Prisma, and Rapid7 ICS.
  • Deploy configurations and infrastructure using Infrastructure as Code (IaC) frameworks, such as Terraform, Cloud Formation, and Pulumi.
  • Develop and implement governance strategies for infrastructure deployment that integrate security best practices and enhance developer productivity.
  • Architect and implement workload identity services, such as SPIRE (Spiffe), in a heterogeneous multi-cloud environment.

Other

  • Hybrid (3 days in office/2 days remote) – New York, NY or Santa Monica, CA or Aliso Viejo, CA
  • Expert level communication skills and the ability to work effectively across teams.
  • Accelerated Growth Environment
  • Top Tier Compensation Package
  • Flexible Time Off