Guidewire Software

Senior Security Engineer

Guidewire Software$133K — $199K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in security engineering, cloud security, or DevSecOps.
  • Hands-on experience with AWS environments; GCP experience preferred.
  • Knowledge of cloud governance, network security, and account lifecycle controls.
  • Proficiency in infrastructure-as-code with Terraform or CloudFormation.
  • Experience securing and testing CI/CD pipelines with GitHub Actions.
  • Scripting experience in Python, Go, or similar languages.
  • Familiarity with AI security concepts and willingness to leverage AI in security.

Responsibilities

  • Lead infrastructure security initiatives focusing on AWS and CI/CD pipelines.
  • Design and implement security controls for cloud platforms.
  • Develop secure-by-default infrastructure solutions with automation tools.
  • Enhance cloud governance and security posture across various dimensions.
  • Maintain security baselines for cloud accounts and supporting infrastructure.
  • Secure CI/CD workflows, addressing dependencies and artifacts.
  • Involve in AI security initiatives and threat modeling for advanced AI systems.

Benefits

  • Health, dental, and vision insurance.
  • Paid time off for work-life balance.
  • Company-sponsored retirement plan.
  • Eligibility for annual bonus plans and long-term incentives.
Full Job Description

Summary

Guidewire is seeking a Senior Security Engineer to design, build, operate, and improve secure infrastructure and cloud security capabilities across an AWS-first, multi-cloud environment.

The core focus of this role is AWS cloud infrastructure and CI/CD supply chain security, while also partnering across teams to address emerging security frontiers—including securing AI systems (LLMs, AI agents, and Model Context Protocol integrations) and leveraging modern AI models and technologies to enhance and automate our security capabilities.

This role partners with functions across infrastructure and platform engineering, site reliability engineering and operations, product and application engineering, data and analytics, security, and other technology and business functions. The engineer translates security risks into scalable controls, automation, secure-by-default patterns, standards, and operating processes.

The role is expected to independently own complex work, solve ambiguous security problems, influence stakeholders, and mentor other engineers.

Job Description

Responsibilities:
  • Lead complex infrastructure security initiatives involving multiple teams, systems, and dependencies, with a primary focus on AWS cloud environments and CI/CD pipelines.

  • Design, implement, and operate security controls across AWS and applicable cloud platforms.

  • Build secure-by-default solutions using infrastructure as code, policy as code, CI/CD, and automation.

  • Improve cloud governance, security posture, and operational resilience through controls for cloud organization and account structure, access management integration, policy enforcement, logging and monitoring, data protection, configuration management, network security, and account lifecycle management.

  • Define and maintain security baselines for cloud accounts, operating systems, containers, AMIs, Kubernetes, networks, and supporting infrastructure.

  • Support cloud account onboarding, offboarding, inventory, configuration drift management, exception handling, and control validation.

  • Design and improve cloud and infrastructure network security, including network segmentation, traffic visibility, ingress and egress control, DNS, firewalls, routing, private connectivity, and related monitoring and enforcement mechanisms.

  • Secure CI/CD and software supply chains, including build and deployment workflows, dependencies, artifacts, containers, registries, third-party actions, secrets, and runner environments.

  • Support asset and identity governance for applications, infrastructure, containers, service accounts, workload identities, API keys, AI agents, and MCP tools.

  • Participate in AI security initiatives involving next-generation AI models, agents, and tool integrations (including Model Context Protocol / MCP), driving threat modeling, prompt injection defenses, data egress protection, guardrails, human-in-the-loop controls, monitoring, and leveraging AI models to automate and enhance security operations.

  • Apply risk-based security analysis using reachability, attack paths, asset criticality, exploitability, and business impact—not severity alone.

  • Validate scanning-tool and AI-generated findings, establish ownership and remediation expectations, and improve finding quality feedback loops.

  • Represent Security in architecture, change management, design review, and operational forums.

  • Communicate risks, trade-offs, assumptions, dependencies, and business impact to technical and non-technical audiences.

  • Create standards, runbooks, architecture decision records, dashboards, documentation, and enablement materials.

  • Mentor engineers and help partner teams adopt secure patterns without requiring direct management responsibility.

  • Participate in on-call rotations and incident response support for cloud and infrastructure security incidents.

  • Monitor emerging threats and translate relevant developments into practical improvements to Guidewire’s security controls.



Required Qualifications:
  • Typically 5+ years of experience in security engineering, cloud security, infrastructure security, DevSecOps, or equivalent practical experience.

  • Hands-on experience designing and operating secure AWS environments is required. Experience with Google Cloud Platform (GCP) is strongly preferred; experience with other cloud platforms is a plus.

  • Experience designing or operating cloud security capabilities, including cloud governance, access management integration, policy enforcement, logging and monitoring, data protection, network security, configuration management, and cloud account lifecycle controls.

  • Hands-on experience authoring, reviewing, testing, and troubleshooting infrastructure-as-code using Terraform, CloudFormation, or comparable technologies to deploy and manage security controls.

  • Hands-on experience building, securing, testing, and operating CI/CD pipelines, preferably using GitHub Actions or comparable platforms, including pipeline automation, secrets management, artifact handling, and runner security.

  • Hands-on scripting or programming experience, using Python, Go, or another appropriate language, to automate security tasks, integrate controls, and troubleshoot security tooling.

  • Practical knowledge of cloud and infrastructure networking, including segmentation, routing, DNS, firewalls, ingress and egress controls, private connectivity, and network telemetry.

  • Experience securing containers and Kubernetes platforms, preferably EKS or an equivalent platform.

  • Knowledge of threat modeling, secure design, vulnerability management, security testing, risk assessment, monitoring, and incident response.

  • Ability to evaluate security-control effectiveness using evidence, operational feedback, exceptions, findings, and relevant metrics.

  • Demonstrated experience building, operating, or contributing to security measurement and analysis capabilities, such as asset inventories, control-coverage reporting, configuration-drift analysis, attack-path analysis, or security data platforms.

  • Working knowledge of identity and access-control concepts, including authentication, authorization, privileged access management, identity governance, zero-standing privilege, workload and non-human identities, and secrets management, with the ability to apply these concepts when evaluating, designing, implementing, or measuring controls across cloud, infrastructure, CI/CD, and operational workflows.

  • Working knowledge of software supply-chain security concepts, including SBOMs, artifact signing, provenance, dependency management, secure registries, and CI/CD runner hardening, with the ability to evaluate, design, implement, or measure related controls and automation.

  • Working knowledge of foundational AI security concepts (e.g., LLM risks, prompt safety) and an eagerness to apply AI capabilities to security automation.

  • Ability to own complex work, manage ambiguity, make trade-offs, identify risks, and deliver outcomes across multiple teams.

  • Strong written and verbal communication skills, including the ability to explain complex security concepts in business terms.



Preferred Qualifications:
  • Hands-on experience or deep knowledge of AI-security risks and controls, including LLMs, AI agents, MCP, AI gateways, prompt injection defense, sensitive-data leakage, and applying advanced AI models/tools to improve security operations.

  • Familiarity with NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, ISO/IEC 42001, or comparable frameworks.

  • Relevant certifications such as AWS Security Specialty, CISSP, GIAC, or equivalent practical expertise.

The US base salary range for this full-time position is $133,000 - $199,000. Your base pay will depend on your experience, skills, education, training, and location among other factors. All full-time positions or part-time roles working 30 hours or more a week at Guidewire are eligible for benefits that support their health and well-being including health, dental, and vision insurance, paid time off, and a company sponsored retirement plan. In addition, some roles may be eligible for the annual company bonus plan, commissions, and/or long term incentive awards which are contingent on a variety of factors including, but not limited to, company and employee performance.

About Guidewire Software

Guidewire Software, Inc. provides software products for property and casualty insurers worldwide. The company offers Guidewire InsuranceSuite comprising Guidewire PolicyCenter, BillingCenter, and ClaimCenter applications. It also provides Guidewire InsuranceNow, a cloud-based platform, which offers policy, billing, and claims management functionality to insurers that prefer to subscribe to a cloud-based solution. In addition, the company offers Guidewire Underwriting Management, a cloud-based integrated business application; Guidewire Rating Management that enables insurers to address the pricing needs; Guidewire Reinsurance Management, a cloud-based application that helps insurers to manage their reinsurance activities; and Guidewire Client Data Management, a cloud-based application, which provides customer data management capabilities. Further, it provides Guidewire Product Content Management that provides software tools and standards-based line-of-business templates to introduce and modify products; Guidewire AppReader, a natural language processing tool; Guidewire ClaimCanvas, a claim fraud detection and investigation solution; Guidewire ClaimCenter Test Automation, a testing solution for ClaimCenter; Guidewire PolicyCenter Test Automation, a testing solution for PolicyCenter; and Guidewire DevConnect, a developer environment that offers tools to develop and support integration applications. Additionally, the company offers implementation and integration, maintenance support, and professional services, as well as Guidewire Live, a cloud-based analytics platform. It sells its products primarily through its direct sales force. The company was founded in 2001 and is headquartered in Foster City, California.
Learn more about Guidewire Software
Size
2,942 employees
Market Cap
$5 billion
Industry
Net Income
-$21.1 million
Founded
2001
5 Year Trend
+9.8%
Revenue
$761.6 million
NASDAQ

Similar Jobs

More Jobs at Guidewire Software

More Information Technology Jobs

Find similar Senior Security Engineer jobs: