Sr Security Engineer - 11806
See all open roles at coupa software →
Likely real
- 115 open roles at this company in 30 days (mass-hiring blitz)
- no salary disclosed (correlates with ghost postings)
See your fit for this role and apply with a truthfully tailored résumé.
About the role
What You'll Do:
Design and implement multi-cloud security controls across Coupa's cloud environment, including VPC segmentation, security groups/NACLs, IAM policy design using least-privilege and permission boundaries, and Organizations/SCPs for guardrails at scale.
Build policy as code and IaC security guardrails and wire them into CI/CD as pre-merge and pre-deploy gates rather than after-the-fact reviews.
Harden containerized workloads and Kubernetes clusters — image scanning, admission control, pod security standards, network policies, and container/workload runtime detection.
Own vulnerability analysis of application packages, container images, and third-party dependencies; triage findings by exploitability and business impact rather than CVSS score alone.
Design and implement remediations — not just report findings — including secure code fixes, cloud configuration changes, and IAM policy adjustments using least-privilege principles.
Support incident response and forensics as a technical contributor — log analysis, root-cause investigation, and remediation validation using cloud-native and EDR tooling.
Partner with the Risk & Compliance team to provide technical evidence and control validation for audit frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP).
Support and mentor other security engineers — reviewing designs and remediation plans, sharing root-cause analysis techniques, and helping less experienced teammates work through complex or ambiguous findings.
Participate in the on-call/incident rotation and help continuously improve remediation and response runbooks.
What You'll Bring to Coupa:
7+ years of experience in security engineering or penetration testing, with a track record of independently owning complex assessments from scoping through remediation.
Practical experience with cloud security fundamentals (AWS, GCP, or Azure) — IAM, networking, and common misconfiguration classes — sufficient to both find and fix cloud findings.
Strong scripting/automation skills in Python, Bash, or JavaScript, with experience building or extending internal security tooling.
Experience with dependency/container vulnerability scanning tools and integrating them into CI/CD pipelines.
Working knowledge of common compliance frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP) and what auditable evidence looks like.
Critical thinking and root-cause analysis skills — comfortable digging past a scanner's output to understand and explain why a vulnerability exists.
Clear written and verbal communication skills for translating technical findings into remediation guidance for engineers and risk context for stakeholders.
Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
Relevant certifications a plus: CISSP, CCSP, CISA, or AWS/GCP security certifications
Stop applying to ghosts.
OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.
Do more with OyaPilot