Senior Security Engineer
Indexed description
LearningSpring is seeking a Senior Security Engineer to design, implement, and continuously improve the security foundation of our platform. This role is ideal for an engineer who enjoys building secure systems from the ground up, partnering closely with Platform and Product Engineering, and embedding security into every stage of software delivery.
As our first dedicated security engineer, you will establish the technical direction for security while remaining deeply hands-on. You will develop cloud security standards, implement security tooling, strengthen our software development lifecycle, and help lead LearningSpring through SOC 2 and future PCI compliance. You will work across AWS infrastructure, CI/CD pipelines, application architecture, and engineering workflows to ensure security enables—not slows—our ability to deliver for customers. You will be responsible for assisting LearningSpring as we establish DevSecOps practices.
This is not a compliance-only role, nor is it an operations-heavy security position. We are looking for a pragmatic engineer who understands modern cloud platforms, automates wherever possible, makes thoughtful risk-based decisions, and collaborates effectively with engineering teams to build secure, scalable systems.
Key Responsibilities
- Define and implement LearningSpring's cloud security strategy across AWS infrastructure, in vendor integrations, and as a security subject matter expert for application development efforts.
- Partner with Platform Engineering to build secure-by-default infrastructure using Terraform and Infrastructure as Code best practices.
- Design and implement security controls across cloud infrastructure, networking, identity, secrets management, and application environments.
- Integrate security throughout the software development lifecycle, including CI/CD pipelines, automated testing, dependency management, and release processes.
- Lead technical efforts supporting SOC 2 certification and contribute to PCI compliance initiatives.
- Conduct threat modeling and architecture reviews for new systems and major product initiatives.
- Establish vulnerability management processes, including automated scanning, prioritization, remediation, and verification.
- Evaluate, recommend, and implement security tools that align with the company's technology stack and risk profile.
- Develop security standards, engineering guidelines, and reference architectures that enable teams to build securely.
- Improve security observability through logging, monitoring, alerting, and incident response capabilities.
- Partner closely with engineering teams to identify risks early and develop practical solutions that balance security with delivery velocity.
- Stay informed on emerging threats and continuously improve LearningSpring's security posture through automation and engineering best practices.
Key Deliverables
- Successfully lead the technical implementation supporting SOC 2 certification.
- Establish foundational security standards across AWS infrastructure and engineering practices.
- Implement a secure software development lifecycle integrated into CI/CD pipelines.
- Introduce threat modeling as a standard part of engineering design reviews.
- Implement automated vulnerability scanning and remediation workflows.
- Define infrastructure security baselines using Terraform and policy-as-code where appropriate.
- Build a security tooling strategy and implement foundational security platforms.
- Improve cloud monitoring, logging, and incident response capabilities.
- Develop a multi-year technical security roadmap aligned with LearningSpring's business objectives.
Required Qualifications
- 5+ years of experience in Security Engineering, Platform Engineering, DevSecOps, Cloud Engineering, or a closely related field.
- Experience securing production workloads in AWS.
- Strong understanding of cloud networking, IAM, encryption, secrets management, and infrastructure security.
- Experience building Infrastructure as Code using Terraform.
- Experience securing CI/CD pipelines and modern software delivery workflows.
- Experience implementing Secure SDLC practices.
- Hands-on experience with vulnerability management and security automation.
- Experience with scripting and automation using Python or similar languages.
- Experience partnering with engineering teams to perform architecture reviews and threat modeling.
- Working knowledge of SOC 2 controls and experience supporting compliance initiatives.
- Excellent written and verbal communication skills.
- Ability to work independently while collaborating effectively across engineering teams.
Preferred Qualifications
- Experience working within FinTech, financial services, or other highly regulated industries.
- Experience supporting PCI DSS compliance.
- Experience with container and Kubernetes security.
- Experience implementing SAST, DAST, software composition analysis, and secrets scanning.
- Experience with AWS security services such as Security Hub, GuardDuty, Inspector, CloudTrail, and IAM Identity Center.
- Experience evaluating and implementing modern security platforms such as Wiz, Snyk, GitHub Advanced Security, CrowdStrike, or similar technologies.
- Familiarity with policy-as-code and cloud governance frameworks.
- Security certifications such as AWS Security Specialty, Security+, CISSP, or equivalent practical experience.
- Working knowledge of the Drata trust management platform.
Physical Requirements
- Sitting or standing: The ability to remain in a stationary position for extended periods.
- Using hands and fingers: The ability to operate standard office equipment and keyboards.
- Close visual acuity: The ability to see clearly at close distances, which is crucial for computer work.
Your Education
Where you went to school matters less than what you’ve learned since. We value curiosity, resilience, and self-awareness over pedigree. If you’re someone who pushes limits, seeks out complex problems, and knows when to ask for help, you’ll fit right in.
Please send your resume to [email protected] with the title of the role you are applying for in the subject line.
- Successfully support LearningSpring's SOC 2 certification efforts.
- Improve the organization's overall security posture through measurable risk reduction.
- Reduce vulnerability remediation timelines through automation and engineering improvements.
- Embed security into engineering workflows without creating unnecessary friction.
- Establish security standards that are adopted across Platform and Product Engineering.
- Build strong partnerships with engineering teams by providing practical, solution-oriented guidance.
- Develop a clear, actionable security roadmap that balances business objectives with long-term risk management.
- Continuously improve the security maturity of the organization through thoughtful technical leadership.
- We value integrity: We lead with honesty, fairness, and transparency in every action and interaction. By treating each person with dignity, empathy, and respect, we strengthen the trust that underpins our relationships with families, educators, and community partners. Integrity guides both our decisions and how we serve our mission to support every learner’s growth.
- We have a growth mindset: We approach every challenge as an opportunity to innovate. Instead of asking why something can’t be done, we figure out how to make it happen: testing, learning, and iterating along the way.
- We are mission-driven: Everything we do helps more children access the right educational environment. Our work is essential, timely, and directly tied to helping students reach their potential.
- We act on evidence: We use data and measurable outcomes to guide our decisions and improve continuously. Every strategy and product we design reflects evidence-based practice and the ongoing pursuit of real-world impact.
- We are active problem solvers and innovators: We champion creative thinking and challenge convention to find new, effective solutions. Guided by curiosity and purpose, we use emerging tools, including AI and data analytics, to tailor experiences for parents and improve outcomes for students, adapting quickly to meet the evolving needs of families, schools, and states.
For individuals hired to work in Colorado, LearningSpring is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to the State of Colorado and includes the range of factors considered in making compensation decisions, including but not limited to skill sets, experience and training, certifications, etc.
Colorado Pay Range: The anticipated salary range for this role is $150,000 - $175,000 annually.
Final compensation will be determined based on a variety of factors, including relevant experience, skills, education, and past performance. In addition to base salary, this position may also be eligible for a variable bonus and equity.
Our benefits include
- Competitive Medical, Dental, and Vision coverage
- A generous PTO policy
- A robust list of paid holidays
No visa sponsorship is available for this position.
Employment with LearningSpring is contingent upon the satisfactory completion of several pre-employment requirements, including a background check and a professional reference check.
LearningSpring, Inc. does not discriminate in employment opportunities or practices based on race, color, creed, sex, gender, gender identity or expression, pregnancy, childbirth or related medical conditions, religion, veteran and military status, marital status, registered domestic partner status, age, national origin or ancestry, physical or mental disability, medical condition (including genetic information or characteristics), sexual orientation, or any other characteristic protected by applicable federal, state, or local laws.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search