Unknown Company

Senior Security Engineer (FedRAMP)

san jose, ca • Posted 6 days ago
Onsite Full Time IT & Technology

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.

About the Role

We’relooking for a Senior Security Engineer tosupportthedevelopment and growthof Veeam Data Cloud (VDC) , our cloud-native SaaS platform. This role owns hands‑on security engineering for VDC’s regulated environments,starting with our FedRAMP boundarybut extending tothe broader set of regulated customer needswe will take on as our platform grows. VDC delivers high‑trust, secure data protection services on Microsoft Azure and AWS for customers in regulated industries.

You’llpartner closely with product, platform engineering, and SRE to embed compliant, secure‑by‑design patterns into everything we ship — designing controls that satisfyNIST 800‑53todaybutwill adapttootherframeworksas we expand.

This is a role with room to shape how securityengineering scales acrossVDC’sregulated footprint: youwillown the domain end to end, work independently on complex, ambiguous problems, and set baselines, review practices, and remediation standardstokeep VDC compliant and secure at scale.

Due to the fact that this position will deal with highly sensitive data and will support federal customers, we are only considering US citizens at this time. Security clearance is not required, but there is a slight chance it maybe requested in the future

What You’ll Do

  • Champion secure design patterns that enable compliance‑driven engineering across VDC’s Cloud environments, including VDC‑wide standards such as supply chain security
  • Support the design and onboarding of new workloads into regulated environments from a security compliance perspective
  • Partner with VDC Engineering to harden shared infrastructure (e.g. VMs, containers, and operating systems) against secure baselines such as STIGs and CIS benchmarks
  • Oversee and support vulnerability scanning alongside the Platform team, providing remediation guidance and tracking fixes against SLAs
  • Support configuration management change control and configuration baseline compliance with Platform Engineering and SRE
  • Review significant architecture changes across our regulated environments and provide security input on approvals
  • Build reusable, framework‑agnostic guardrails and evidence so security controls scale across FedRAMP, sovereign cloud, and emerging regulatory requirements
  • Review application and platform code and identify security deficiencies
  • Align commercial, government, and other product roadmaps so controls and standards carry cleanly across environments and frameworks
  • Participate inanon‑call rotation shared across the Security Engineering team to respond, triage, and resolve alerts to closing

What You’ll Bring

  • 8+ years in security engineering, with hands‑on experience securing cloud environments (strong preference for experience inAzure and/or AWS)
  • Experiencedeliveringcloudproducts tomeet regulated compliance requirementssuch asgovernment (FedRAMP, CMMC, IL2/IL4/IL5, sovereign cloud),financialservices(PCI‑DSS),and/or healthcare(HIPAA, HITRUST)
  • Ability to translate specific compliance controls into concrete architecture and operational decisions (e.g., how an audit logging requirement drives log retention design, or how boundary protection requirements shape network segmentation)
  • Working knowledge ofNIST 800‑53, including continuous monitoring, vulnerability management,and configuration managementstandards
  • Experience hardening infrastructure to secure baselines such as STIGs or CIS benchmarks
  • Strongunderstanding ofcloud security fundamentalsinidentity, network boundaries, encryption, andvulnerability remediationdomains
  • Ability to learn large, complex platforms quickly with limited guidance: Being comfortable building understanding from code, docs, and architecture artifacts
  • A collaborative, hands‑on approach to partnering across engineering, product, security, compliance,and SRE
  • Deep partner mindset:Ability to takea hands‑on approach to enable engineering teams rather than serving as gatekeepers
  • AI as a force multiplier:AI tools are woven into how wework,and we build security at AI‑speed using these tools. We want engineers who treat AI as a force multiplier, not an afterthought

Bonus Skills

  • Experience designingand working withcontrolsto satisfyrequirementsacrossmultiple compliance frameworks
  • Hands‑on experience with vulnerability scanning tools (e.g.Wiz,Nessus)
  • Experience withIaCtools (e.g.Terraform)
  • ExperienceusingGitHubfor configuration managementand change control
  • Exposure to supply chain security standards and secure‑by‑design practices
  • Relevant certifications (e.g., CISSP, CCSP, or cloud provider security certs)

What You’ll Get

  • Unlimited paid time off, plus 3 global VeeaMe Days for self‑care
  • Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
  • Medical, dental, and vision coverage from day one
  • Mental health support, therapy sessions, and digital wellness tools via SupportLinc EAP
  • 401(k) retirement plan with matching contributions up to annual limits
  • Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
  • AirVet: 24/7 virtual veterinary care at no cost
  • Legal services, identity protection, and supplemental health insurance options
  • Tax-advantaged spending accounts for healthcare, dependent care, and commuting
  • Professional training and education, including courses and workshops, internal meetups, and unlimited access to our online learning platforms (LinkedIn Learning, Athena, O’Reilly) and mentoring through our MentorLab program

#LI-SO2

#J-18808-Ljbffr
Back to Job Search