Security Engineer II (Remote)

DreamHost, LLC

• $125K — $145K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-6 years in security engineering, incident response, application security, or systems administration
  • Depth in application security, incident response detection engineering, or offensive security with competence in the other two
  • Strong hands-on experience with Linux (Debian/Ubuntu preferred)
  • Scripting and automation experience in languages like Python, Go, or Bash
  • Log analysis and investigation at scale, with familiarity in intrusion detection and web application firewalls
  • Working knowledge of cloud platform security (AWS, GCP, Azure, or OpenStack)
  • Experience with AI tooling integrated into engineering work.

Responsibilities

  • Lead complex security incident investigations and coordinate across teams
  • Design and implement safeguards against active threats
  • Conduct vulnerability assessments and provide remediation guidance
  • Build automation and tooling for detection and monitoring
  • Collaborate with cross-functional teams on security implementation
  • Mentor junior team members and contribute to knowledge sharing
  • Support compliance efforts while defining security policies and standards.

Benefits

  • Full family health, vision, and dental insurance at no cost
  • 3% Safe Harbor 401(k) contributions plus up to 1% match
  • Opportunities for profit sharing and bonuses
  • Starting with 15 vacation days and 11 paid holidays
  • 80 hours paid sick leave
  • Tuition reimbursement program
  • Monthly Thrive Pass wellness allowance of $30
  • Generous maternity and paternity leave
  • Discounted travel through a corporate booking program
  • Casual work atmosphere and fun company events
  • Free web hosting services.
Full Job Description
Benefits Offered
  • Full health/vision/dental for the entire family at zero cost to team member
  • 3% Safe Harbor contributed to 401(k) plus up to 1% employer match
  • Opportunities for profit sharing and bonuses
  • Generous time-off (starting at 15 vacation days)
  • 11 Paid holidays (Technical Support and Technical Operations use a floating holiday policy)
  • Paid sick leave (80 hours accrued)
  • Tuition reimbursement (50/50 up to a specific amount)
  • Pet Insurance
  • Thrive Pass wellness allowance of $30 per month
  • Udemy online learning courses
  • Disability Insurance
  • Generous maternity/paternity leave
  • Discounted personal travel through corporate booking program Egencia
  • Laid-back atmosphere
  • Fun monthly company events
  • Free web hosting


Overview

The Security Engineer II is responsible for protecting DreamHost, our infrastructure, and our customers in a large, multi-tenant Linux hosting environment where untrusted code runs on our machines by design. This is a hands-on engineering role. You will investigate live compromises, build the tooling and detections that find the next one, review the security of our own applications and infrastructure, and drive down long-standing risk across a fleet spanning shared hosting, VPS, managed WordPress, dedicated servers, cloud, and email.

You will work on a small security team where everyone owns real workstreams end to end, partners directly with Systems, Development, Abuse, and Support, and is expected to exercise judgment without waiting for permission.

What you'll work on
  • Incident response across shared, virtualized, and dedicated Linux hosts - compromise investigation, blast-radius scoping, containment, evidence preservation, and write-ups.
  • Detection engineering: malware and webshell signatures, log-based detections, and reducing the false positives that create alert fatigue at fleet scale.
  • Application security review of our in-house control plane, customer panel, and internal tooling, plus the third-party and open-source code we depend on.
  • Secrets management modernization such as moving static credentials into Vault, adopting dynamic credentials, and eliminating plaintext secrets from code, logs, and CI.
  • Identity and access lifecycle: directory and SSO migration, privileged access review, and durable offboarding.
  • Vulnerability management and patch velocity across a large, heterogeneous fleet, including end-of-life OS and runtime remediation.
  • Automation. Anything done manually more than twice is a candidate for tooling, and you'll build it.
  • Security review and governance of AI and agent tooling as it's adopted internally - data exposure, permission scope, agent identity, and abuse paths. You'll also be using these tools heavily yourself; the team runs on them.


Responsibilities

Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the role.
  • Lead investigation and resolution of complex security incidents, coordinating across teams and communicating status clearly while facts are still incomplete.
  • Design and implement safeguards protecting customer sites, accounts, and infrastructure from active and evolving threats.
  • Conduct vulnerability assessments, security reviews, and risk analysis, with remediation guidance engineers can act on.
  • Build automation and tooling that improves detection, monitoring, response, and operational safety.
  • Partner with Systems, Development, Abuse, and Support to get security controls implemented rather than merely recommended.
  • Mentor less experienced team members and contribute to the team's shared knowledge and runbooks.
  • Contribute to security policy, standards, and process, and support compliance efforts without mistaking compliance for security.


  • 3-6 years in security engineering, incident response, application security, offensive security, or systems administration, with demonstrated ability to resolve complex security problems independently.
  • Depth in at least one of: application security, incident response and detection engineering, or offensive security and penetration testing plus working competence in the other two.
  • Strong hands-on Linux (Debian/Ubuntu preferred), including low-level concepts: processes, namespaces, capabilities, filesystems, kernels, and how things actually break.
  • Experience operating long-lived production systems that can't simply be rebuilt including repairing hosts in place, under load, with real users on them.
  • Experience in multi-tenant or customer-facing environments where users are untrusted.
  • Scripting and automation you've shipped and operated in production. Python, Go, Bash, Perl, or similar. We care that you've built and maintained real tooling, not which language.
  • Log analysis and investigation at scale, and comfort with intrusion detection and web application firewalls (mod_security or similar).
  • Working knowledge of cloud platform security (AWS, GCP, Azure, or OpenStack) including IAM, network controls, and workload isolation.
  • Familiarity with secrets management and CI/CD security (Vault or equivalent, pipeline hardening, dependency and supply-chain risk).
  • Version control and infrastructure-as-code fluency (Git, Ansible or similar).
  • Practical, current fluency with AI tooling in your own work. You use it daily, you know where it fails, and you can say what you don't let it do. We are not looking for enthusiasm or for resistance, but for someone who has integrated these tools into real engineering work and formed opinions from experience.
  • Clear written and verbal communication, including translating technical risk for non-technical stakeholders.
  • A strong sense of ethics, healthy skepticism, and the patience to stay useful under pressure.


Nice to have
  • Web hosting or WordPress-at-scale experience, as a provider or a customer.
  • Container and orchestration security (Podman, Docker, Kubernetes) including escape and isolation failure modes.
  • Malware analysis, YARA rule authorship, or reverse engineering.
  • Detection-as-code or SIEM engineering experience.
  • Hands-on experience securing AI/LLM systems, agent frameworks, or MCP tooling. Prompt injection, tool-permission scoping, or data-boundary work.
  • Familiarity with PCI DSS, SOC 2, or ISO 27001 - as context, not as a career.
  • Open source contributions.


Compensation
  • $125,000-$145,000 / yearly

Similar Jobs

More Jobs at DreamHost, LLC

More Information Technology Jobs

Find similar Security Engineer II (Remote) jobs: