Location: San Ramon, CA | Reno, NV
Ridgeline is on the hunt for an experienced Infrastructure Security Engineer. As an Infrastructure Security Engineer at Ridgeline, you will play a key role in securing Ridgeline’s cloud environments, with ownership over security for specific platforms and services. You will help define and implement cloud security best practices for your teams and share those practices with peers through reviews, documentation, and pairing. You will ensure that our cloud development, deployment, and methodologies comply with industry standards and regulations.
This position requires close collaboration and partnership with our Engineering/DevOps, Product Management, and Technology organizations. Your role is just as much teaching and bringing those around you on the cloud security journey as it is doing the work. We believe in a culture where security is everyone's responsibility and an integral part of our engineering philosophy.
What You’ll Do- Independently perform cloud architecture and network security reviews for your product areas in AWS and select third‑party cloud services, and help embed security‑by‑design practices within your team and adjacent teams.
- Develop and maintain scalable security tooling, with a heavy emphasis on effectively leveraging AI augmented tooling where appropriate.
- Contribute to the design and implementation of guardrails and controls in our AWS environment (e.g., SCPs, IAM boundaries, AWS managed security services, custom-built solutions, and policy‑as‑code), and own guardrails for specific domains or services.
- Monitor and enhance workload security, integrating detection and alerting into observability systems to safeguard services at runtime.
- Build and champion frameworks for secure platform integrations with third-party cloud services and internal tools.
- Embed security into CI/CD and infrastructure automation, ensuring reproducible, testable, and auditable deployments.
- Implement and improve access management, least‑privilege enforcement, encryption/key management, and runtime protections within your services.
- Utilize AI tools and platforms to improve security operations and development workflows; actively contribute to AI-integrated processes and team efficiencies.
- Think creatively, own problems, seek solutions, and communicate clearly along the way.
- Partner with other engineers through code reviews, pairing, and design consultation.
- Collaborate with engineering, product, and compliance partners to define and deliver security requirements for the services you support, and provide clear technical guidance during design and implementation.
- Bachelor’s degree in Computer Science or equivalent practical experience.
- 5+ years of relevant experience in cloud security or platform engineering, including experience independently leading complex initiatives within your team and collaborating effectively with adjacent teams.
- Advanced proficiency in at least one high-level language (Python strongly preferred; Kotlin or TypeScript a plus).
- Experience with AWS, especially in the following areas:
- Identity and Access Management (IAM, Orgs & SCPs, Identity Center)
- Networking (VPC, Security Groups, Transit Gateway, Load Balancers)
- Compute (Lambda, ECS or EKS, Fargate)
- Data Persistence (S3, Aurora, DynamoDB)
- Logging & Monitoring (GuardDuty, CloudTrail, CloudWatch)
- Demonstrated success in designing and implementing access management strategies and policy frameworks (IAM/SCPs).
- Strong understanding of cloud workload protection, infrastructure monitoring, and threat detection in AWS-native environments.
- Fluency with infrastructure-as-code (e.g., Terraform) and CI/CD practices.
- Strong written and verbal communication skills, with the ability to explain security tradeoffs clearly to engineers, product partners, and stakeholders.
- Demonstrated ability to make sound architectural tradeoffs within your services, improve long‑term code and system health, and collaborate with adjacent teams when changes have cross‑team impact.
- Familiarity with key concepts in network security: firewalls, IDS/IPS, and traffic segmentation.
- Contributions to security tooling, open source projects, or published security research.
- Experience with AI or LLM tools in a development or security context.
Compensation and Benefits
The typical starting salary range for this role is: $149,000 - $250,000. Final compensation amounts are determined by multiple factors, including candidate experience and expertise, and may vary from the amount listed above.
As an employee at Ridgeline, you’ll have many opportunities for advancement in your career and can make a true impact on the product.
In addition to the base salary, Ridgeline employees can participate in our Company Stock Plan subject to the applicable Stock Option Agreement. We also offer rich benefits that reflect the kind of organization we want to be: one in which our employees feel valued and are inspired to bring their best selves to work. These include unlimited vacation, educational and wellness reimbursements, and $0 cost employee insurance plafis. Please check out our Careers page for a more comprehensive overview of our perks and benefits.
Ridgeline is proud to be a community-minded, discrimination-free equal opportunity workplace.
Ridgeline processes the information you submit in connection with your application in accordance with the Ridgeline Candidate Privacy Policy. Please review the Ridgeline Candidate Privacy Policy in full to understand our privacy practices and contact us with any questions.
Skills Required
- Bachelor's degree in Computer Science or equivalent practical experience
- 5+ years of relevant experience in cloud security or platform engineering
- Experience independently leading complex initiatives and collaborating with adjacent teams
- Advanced proficiency in at least one high-level programming language
- Advanced proficiency in Python
- Experience with AWS IAM, Organizations, SCPs, and Identity Center
- Experience with AWS networking, including VPC, Security Groups, Transit Gateway, and Load Balancers
- Experience with AWS compute services, including Lambda, ECS or EKS, and Fargate
- Experience with AWS data persistence services, including S3, Aurora, and DynamoDB
- Experience with AWS logging and monitoring services, including GuardDuty, CloudTrail, and CloudWatch
- Success designing and implementing access management strategies and IAM/SCP policy frameworks
- Strong understanding of cloud workload protection, infrastructure monitoring, and AWS-native threat detection
- Fluency with infrastructure as code, such as Terraform
- Experience with CI/CD practices
- Strong written and verbal communication skills
- Ability to make architectural tradeoffs, improve code and system health, and manage cross-team impacts
- Familiarity with firewalls, IDS/IPS, and traffic segmentation
- Contributions to security tooling, open-source projects, or published security research
- Experience with AI or LLM tools in development or security contexts
- Experience with Kotlin or TypeScript
Ridgeline Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Ridgeline and has not been reviewed or approved by Ridgeline.
-
Affordable Benefits — Employee-only medical, dental, and vision coverage is offered at no cost, lowering out-of-pocket expenses. Wellness and education stipends further enhance the overall value of the package.
-
Equity Value & Accessibility — Stock options are provided to all employees, creating broad-based ownership. This makes equity a meaningful pillar of total compensation.
-
Parental & Family Support — Paid parental leave for all caregivers alongside fertility coverage indicates strong support for family-building. These benefits reduce logistical and financial strain during major life events.
Ridgeline Insights
What We Do
Ridgeline has a simple mission: partner with investment management firms to modernize their software. Founded by software industry entrepreneur Dave Duffield, Ridgeline is headquartered in Incline Village, Nevada.







