Senior Security Engineer
Collegeboard · Remote
📍 Remote - USAvia workdayFirst listed here 2026-09-19
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Collegeboard.
College Board – Technology – Cloud Security
Location: This is a fully remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office).
Type: This is a full-time position
About the Team
The College Board’s Cloud Security and Platform Engineering (CSPE) team designs, builds, and secures the cloud foundation that powers our most critical applications and services. We partner closely with product engineering, platform, risk, compliance, and application teams to design, automate, and operationalize scalable security controls, building reusable tooling and guardrails that make secure application deployments the default across AWS environments. Rather than operating as a reactive review function, we implement preventive and detective controls that reduce systemic risk while enabling teams to move quickly. Our work spans multi-account cloud architecture, identity and access management, network segmentation, automation, detection engineering, and compliance alignment. We focus on scalable, repeatable solutions that strengthen security posture across the enterprise.
About the Opportunity
As a Senior Security Engineer, you will play a critical role in strengthening the cloud security foundation that supports College Board’s enterprise platforms and services. This position focuses on building and scaling automated, preventive security controls that reduce systemic risk while enabling engineering teams to deliver quickly and confidently. You will work across cloud environments to expand automated guardrails, improve external exposure management, and reduce high-risk misconfigurations through enforceable, enterprise-wide controls. This role emphasizes secure-by-default architecture, infrastructure automation, and measurable risk reduction, ensuring security controls are consistently applied as the organization scales. In partnership with Cloud Engineering, Product Security, and Cyber Operations, you will enhance vulnerability management workflows, increase automation across intake and response processes, and strengthen detection and triage capabilities. You will help drive improved remediation velocity, clearer security posture visibility, and more efficient security operations through engineering-led solutions.
You will also contribute to the resilience and reliability of critical security platforms, ensuring continuity of monitoring and posture management capabilities while supporting modernization efforts. Success in this role means delivering durable, scalable security outcomes: stronger preventive coverage, reduced exposure windows, improved operational efficiency, and measurable improvements in enterprise security posture.
In this role, you will:
Strengthen Cloud Guardrails and Preventive Controls (40%)
Design, implement, and operationalize automated preventive and detective guardrails across enterprise cloud environments.
Build and enforce enterprise-wide controls that prevent or automatically remediate high-risk misconfigurations.
Improve protection coverage for internet-facing systems by validating asset inventories and expanding enforcement mechanisms.
Continuously evaluate control effectiveness through telemetry, compliance validation, and risk trend analysis.
Partner with cloud platform teams to embed secure-by-default infrastructure patterns into reusable modules and deployment workflows.
Advance Vulnerability Management and Security Automation (35%)
Enhance vulnerability management processes to improve prioritization, remediation velocity, and cross-team accountability.
Increase automation across vulnerability intake, enrichment, ticketing, and response workflows to reduce manual triage burden.
Design and deliver engineering solutions that improve detection quality and response speed in collaboration with Cyber Operations.
Translate security requirements into scalable technical implementations using infrastructure-as-code and automation frameworks.
Measure and report on workflow efficiency and risk reduction outcomes using operational metrics.
Improve Security Posture Visibility and Platform Resilience (25%)
Implement standardized, automated security checks across prioritized security domains to strengthen baseline posture.
Enable measurable security maturity tracking through telemetry-backed reporting and posture metrics.
Support continuity of cloud security monitoring and posture management during tooling transitions or modernization efforts.
Strengthen reliability, scalability, and resilience of critical security platforms to reduce operational risk.
Contribute to documentation, engineering standards, and continuous improvement practices that promote long-term maintainability.
About you, you have:
5+ years of experience in security engineering, cloud security, or security architecture, with demonstrated ownership of initiatives that scale across multiple teams and environments.
Designed and secured cloud-native architectures, including multi-account AWS environments, microservices, serverless workloads, and API-driven systems.
Have deep experience with AWS security fundamentals, including IAM strategy (least privilege, cross-account access, federation), KMS, Secrets Manager, S3, logging/monitoring, and preventive guardrails using Organizations and SCPs.
Implemented security controls using Infrastructure as Code (Terraform, CloudFormation, CDK) and support policy-as-code approaches to enforce standards at scale.
Understand secure system design across multi-tier architectures and can perform threat modeling to identify systemic risks before they reach production.
Experienced in securing Linux-based systems and cloud infrastructure, with practical expertise in hardening, logging, identity design, and network segmentation.
Translate regulatory and compliance requirements (e.g., FERPA, PCI DSS, SOC 2, NIST) into practical technical controls and automated ev
More Remote jobs
Remote jobs · Browse all locations