Security Engineer II

Pantheon Systems, Inc

• $94K — $118K *
US-AnywhereRemote in Canada
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years of overall experience in security engineering or application security.
  • 2+ years dedicated experience in application security or security engineering.
  • Hands-on experience with Secure by Design development practices.
  • Experience securing production systems in cloud environments, preferably GCP.
  • Proficiency in coding, specifically in Python or Go for building automation tooling.
  • Familiarity with CI/CD tools such as Jenkins or similar platforms.
  • Experience with containerization, Terraform, and Kubernetes.

Responsibilities

  • Author SIEM detection rules and response playbooks to enhance security monitoring.
  • Build and maintain security automation pipelines using Python/Go.
  • Own vulnerability identification and coordinate remediation efforts across engineering.
  • Implement supply chain security controls and integrate them into workflows.
  • Execute cleanup and management of access and identity architecture.
  • Conduct cloud security baselines triage and implement security measures in data warehouses.
  • Define DLP policies and manage credential hygiene programs.

Benefits

  • Flexible time off, sick days, and 13 paid holidays.
  • Comprehensive medical insurance including Health, Dental, and Vision.
  • Paid parental leave along with family planning benefits.
  • Monthly wellness allowance and access to development resources.
  • Team events and activities aimed at education and inspiration.
Full Job Description
The Role

Pantheon's Security Engineering team is responsible for safeguarding, auditing, and testing the security of Pantheon's entire platform. Our Security Engineering team aims to create a comprehensive and multi-dimensional approach to application security, with a focus on Security by Design in agile software development and cloud native environments.

We are seeking a Security Engineer II to join our growing team. This role bridges execution and tooling - you'll own security domains end-to-end while building the automation and processes that multiply the team's impact across engineering. This is a hands-on engineering role: you'll write detection rules, build vulnerability management tooling, implement supply chain security controls, and develop the automation pipelines that make security scale.

Our mission is to safeguard, audit, and test the security of the entire cloud hosting platform in these core areas:
  • Security by Design: Implement "Security by Design" within agile software development and cloud-native environments.
  • Security Tooling & Automation: Build and maintain security tooling and automation that scales the team's impact beyond what manual processes can achieve.
  • Support and Mentorship: Act as a Subject Matter Expert (SME), mentoring and supporting security engineering efforts across the organization.
  • Standard Setting: Contribute to application security policy, process, standards, and guidelines - and build the tooling that enforces them.
  • Application Security Performance: Help engineering teams design and build high-performing, secure applications by mitigating security issues in a risk-based manner.
What You Will Do
  • Detection Engineering: Author SIEM detection rules and response playbooks in Chronicle / Google SecOps (YARA-L), expanding coverage across Pantheon's security monitoring surface.
  • Security Tooling Development: Build and maintain security automation pipelines (Python/Go) - vulnerability management tooling (vulntools, Wiz scripts), GHAS automation, and CI/CD security integrations.
  • Vulnerability Management: Own vulnerability identification, triage, and remediation coordination with engineering squads across application (SAST/DAST/SCA) and infrastructure layers.
  • Supply Chain Security: Implement supply chain security controls (Aikido, SLSA, dependency pinning) and integrate them into engineering workflows.
  • Access & Identity: Execute RBAC cleanup, access architecture implementation, and periodic user access reviews. Manage GitHub org-level security policies and access controls.
  • Cloud Security: Execute CSPM baseline findings triage, cloud security baseline validation, and data warehouse security implementation (Snowflake).
  • DLP & Secrets: Define DLP policies and evaluate tooling; execute credential and secrets hygiene programs (plaintext credential remediation in repositories).
What You Need to Succeed
  • Builder Orientation: You measure impact by what you ship - tooling that engineering teams adopt, automation that replaces manual work, detection rules that catch real threats. Not by tickets closed or alerts triaged.
  • Communication: Strong communication skills essential for partnering with engineering teams across the organization. You advocate for security priorities and tradeoffs across functions without being prompted.
  • Commitment: Demonstrated commitment to teamwork, professionalism, and authenticity, fostering trust and accountability.
  • Grit: Understanding that establishing security best practices is a marathon requiring persistence across many stakeholders.
What You Bring to the Table
  • Overall Experience: Minimum of 4+ years of overall experience, with at least 2+ years dedicated to Application Security or Security Engineering.
  • Security Tooling: Demonstrated experience building security automation - vulnerability management scripts, CI/CD pipeline integrations, detection rules, or similar tooling that engineering teams use in production.
  • Development Practices: Hands-on experience with Secure by Design development practices, including participating in security architecture and design reviews.
  • Cloud Proficiency: Experience securing production systems in cloud environments (GCP preferred; AWS or Azure also valuable).
  • Coding Proficiency: Ability to build maintainable components in Python or Go. You write tools, not just policies.
  • CI/CD Fundamentals: Hands-on experience with Jenkins, Cloud Build, CircleCI, or similar (bonus points for experience with reusable workflows).
  • Cloud & Infrastructure: Experience working with containerization (e.g., Docker, OCI), Terraform, and Kubernetes (K8s).
  • Security Tooling Platforms: Experience with SAST/DAST/SCA/CSPM tools. Familiarity with CodeQL, Wiz, or similar platforms is a plus.
  • Education: Bachelor's degree (preferred) in Computer Science or equivalent practical experience.
What We Offer

We have all the usual perks and benefits but what we can really offer you is a fantastic work environment powered by an amazing team.
  • Industry competitive compensation and equity plan
  • Flexible time off, sick days, and 13 paid holidays
  • Comprehensive medical insurance including Health, Dental and Vision
  • Paid parental leave (plus fertility, adoption and other family planning benefits)
  • In-office workspace (San Francisco & Chicago)
  • Monthly allowance for wellness, reading and access to LinkedIn Learning for continued development
  • Events and activities both team-based and company wide that inspire, educate and cultivate

Compensation: CAD $94,000 - 118,0000 annual salary plus bonus and equity

Similar Jobs

More Jobs at Pantheon Systems, Inc

More Information Technology Jobs

Find similar Security Engineer II jobs: