Job DescriptionAt LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. The work location of this role is hybrid, meaning it will be performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team.
This role will be hybrid in LinkedIn's Mountain View office location.
About the teamLinkedIn's members entrust us with their information every day and we take their security seriously. Our core value of putting our members first powers all the decisions we make, including how we manage and protect the data of our members and customers. Information Security at LinkedIn is dedicated to protecting and securing business-critical member data and company assets. Our core mission is to empower LinkedIn to create a secure and thriving platform for every member of the global workforce.
LinkedIn's Enterprise and Third Party Risk Management Security team is dedicated to protecting our data, systems, and global members by managing security and privacy risks throughout our internal and external ecosystem. We collaborate across the organization to evaluate the security maturity of our partners and suppliers, identifying systemic threats and providing the technical guidance necessary for the secure integration of external services. Our mission is to leverage security engineering, advanced risk analytics, and automation to provide continuous assurance and visibility throughout the third-party lifecycle and services within our corporate enterprise. We are committed to building scalable, high-impact solutions that mitigate vulnerabilities and ensure all external engagements align with LinkedIn's rigorous security, privacy, and regulatory standards.
About the role:As a Senior Security Engineer focused on the Enterprise & Third Party Risk Management team, you will strengthen LinkedIn's security posture by identifying and mitigating security risks introduced by third-party technologies, services, and integrations.
You will independently lead technical security assessments of complex and high-risk technologies, perform architecture and design reviews, threat model integrations, and partner with engineering/non engineering teams and technology providers to mitigate identified risks. You will also help evolve the methodologies, tooling, and security patterns used to assess third-party technologies at scale.
The ideal candidate balances technical proficiency with strong cross-functional communication and leadership skills. From a technical standpoint, this individual will possess deep subject-matter expertise in application, cloud infra, and enterprise security, along with the ability to convey complex risks to both engineering partners and non-technical stakeholders. Successful candidates will drive alignment across diverse perspectives, prioritize critical vulnerabilities, and guide teams toward resilient security solutions.
Responsibilities:- Lead technical security assessments of complex third-party technologies, including SaaS, cloud services, APIs, AI/ML services, developer platforms, and infrastructure providers.
- Provide architectural guidance and security consultation to engineering and non engineering teams throughout the development lifecycle.
- Lead technical security assessments of complex and critical platforms, performing end-to-end evaluations that encompass architecture reviews, threat modeling, and penetration testing.
- Perform architecture reviews and threat modeling to identify trust boundaries, attack paths, data exposure, identity and privilege risks, and other security weaknesses.
- Evaluate security architecture and controls across application and cloud security, IAM, data protection, vulnerability management, secure development, incident response, and software supply chain.
- Analyze technical security evidence, identify material security gaps, and define appropriate remediation or compensating controls with internal teams and technology providers.
- Develop and deploy security tooling, automated workflows, and standardized processes to enhance operational efficacy and expand the organizational influence of the team.
- Provide clear technical risk assessments and recommendations that enable engineering and business stakeholders to make informed decisions about third-party technologies.
- Improve assessment methodologies, technical security requirements, automation, and reusable security patterns to increase the effectiveness and scalability of third-party security reviews.
- Architect and implement automated security tooling utilizing machine learning and GenAI technologies to optimize review processes, elevate vulnerability identification capabilities, and minimize operational overhead, including hands-on software development for security automation.
- Collaborate with engineering, business, and product teams to proactively enhance security posture through scalable self-service resources, documentation, and readiness frameworks.
- Evaluate, deploy and maintain enterprise security tools like DLP, DSPM, SSPM, EDR, etc
QualificationsBasic Qualifications:- BA/BS degree in Computer Science, Cybersecurity, Information Security, or related technical field, or equivalent technical experience.
- 2+ years of experience in security engineering or a related technical security discipline.
- 2+ years of experience with security assessment methodologies such as threat modeling, architecture/design reviews, penetration testing, or vulnerability assessment.
- 2+ years of experience evaluating security architecture for modern applications, SaaS services, cloud infrastructure, APIs, or other complex technology environments.
- 2+ years of experience in one or more areas including application security, cloud security, IAM, infrastructure security, data protection, or software supply-chain security.
- Experience with programming or scripting languages such as Java, Go, or Python.
Preferred Qualifications:- BS and 5+ years of relevant work experience, MS and 4+ years of relevant work experience, or PhD and 2+ years of relevant work experience.
- 5+ years of experience building or scaling a Third-Party Security, Vendor Security, or Supply Chain Security programs within a large scale technology company
- 5+ years of experience independently leading complex security assessments from architecture review through risk identification and remediation.
- Strong knowledge of modern SaaS and cloud architectures, APIs, identity federation, OAuth/OIDC, privileged access, and data security.
- 5+ years of experience analyzing penetration-test results, vulnerability assessments, architecture documentation, and other technical security evidence.
- 5+ years of experience building automation or security tooling that improves assessment coverage, control validation, attack-surface identification, or continuous security monitoring.
- Ability to communicate complex technical security risks clearly and influence engineering and business stakeholders.
Suggested Skills:- Third-Party Technology Security
- Security Assessment Methodologies
- Threat Modeling
- Security Architecture
- Application Security
You will Benefit from our Culture
We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels.
LinkedIn is committed to fair and equitable compensation practices. The pay range for this role is $129,000 to $212,000. Actual compensation packages are based on a wide array of factors unique to each candidate, including but not limited to skill set, years & depth of experience, certifications and specific office location. This may differ in other locations due to cost of labor considerations.
The total compensation package for this position may also include annual performance bonus, stock, benefits and/or other applicable incentive compensation plans. For additional information, visit: https://careers.linkedin.com/benefits.
Additional Information