What You'll Do:
- Design and implement multi-cloud security controls across Coupa's cloud environment, including VPC segmentation, security groups/NACLs, IAM policy design using least-privilege and permission boundaries, and Organizations/SCPs for guardrails at scale.
- Build policy as code and IaC security guardrails and wire them into CI/CD as pre-merge and pre-deploy gates rather than after-the-fact reviews.
- Harden containerized workloads and Kubernetes clusters — image scanning, admission control, pod security standards, network policies, and container/workload runtime detection.
- Own vulnerability analysis of application packages, container images, and third-party dependencies; triage findings by exploitability and business impact rather than CVSS score alone.
- Design and implement remediations — not just report findings — including secure code fixes, cloud configuration changes, and IAM policy adjustments using least-privilege principles.
- Support incident response and forensics as a technical contributor — log analysis, root-cause investigation, and remediation validation using cloud-native and EDR tooling.
- Partner with the Risk & Compliance team to provide technical evidence and control validation for audit frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP).
- Support and mentor other security engineers — reviewing designs and remediation plans, sharing root-cause analysis techniques, and helping less experienced teammates work through complex or ambiguous findings.
- Participate in the on-call/incident rotation and help continuously improve remediation and response runbooks.
What You'll Bring to Coupa:
- 7+ years of experience in security engineering or penetration testing, with a track record of independently owning complex assessments from scoping through remediation.
- Practical experience with cloud security fundamentals (AWS, GCP, or Azure) — IAM, networking, and common misconfiguration classes — sufficient to both find and fix cloud findings.
- Strong scripting/automation skills in Python, Bash, or JavaScript, with experience building or extending internal security tooling.
- Experience with dependency/container vulnerability scanning tools and integrating them into CI/CD pipelines.
- Working knowledge of common compliance frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP) and what auditable evidence looks like.
- Critical thinking and root-cause analysis skills — comfortable digging past a scanner's output to understand and explain why a vulnerability exists.
- Clear written and verbal communication skills for translating technical findings into remediation guidance for engineers and risk context for stakeholders.
- Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
- Relevant certifications a plus: CISSP, CCSP, CISA, or AWS/GCP security certifications
- Global Wellness Days: Enjoy two designated, company-wide paid wellness days off each year (typically the first Friday in March and the last Friday in September) so the entire global team can unplug, step away, and recharge together .
- Birthday Time-Off: Celebrate your day! Coupa provides a paid day off on your birthday or another day of your choice within your birthday month .
- Volunteer Time Off (VTO): Giving back is in our DNA. We offer 40 hours of paid VTO annually to support the community initiatives and volunteer programs you are passionate about .
- Employee Assistance Program (EAP): Access free, confidential, 24/7/365 counseling and resources for emotional support, work-life solutions, financial advice, legal guidance, and support for new parents .
- Business Travel Protection: Travel with peace of mind. Zurich Travel Assist provides medical, safety, pre-trip planning, and emergency support during any business travel .
- Referral Bonus Program: Share the Coupa experience! Receive generous monetary referral bonuses when you successfully refer talented friends or acquaintances who are hired into open roles .
Skills Required
- 7+ years of experience in security engineering or penetration testing
- Practical experience with cloud security fundamentals (AWS, GCP, or Azure) including IAM, networking, and misconfigurations
- Strong scripting/automation skills in Python, Bash, or JavaScript and experience building or extending internal security tooling
- Experience with dependency/container vulnerability scanning tools and integrating them into CI/CD pipelines
- Experience hardening containerized workloads and Kubernetes clusters (image scanning, admission control, pod security, network policies)
- Working knowledge of compliance frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP) and auditable evidence
- Critical thinking and root-cause analysis skills for vulnerability triage
- Clear written and verbal communication skills for technical and stakeholder communication
- Bachelor's degree in Computer Science, Information Systems, or related field, or equivalent practical experience
- Relevant certifications (CISSP, CCSP, CISA, or AWS/GCP security certifications)
Coupa Compensation & Benefits Highlights
-
Healthcare Strength — Healthcare is described as comprehensive from day one for employees and dependents, including medical, dental, vision, mental‑health resources, and a no‑cost EAP. Additional options like FSAs and wellness initiatives are also cited.
-
Leave & Time Off Breadth — Time off is positioned around Flexible Time Off, floating holidays, and 40 hours of paid Volunteer Time Off, supported by a virtual‑first work model. These programs are highlighted as core elements of work‑life balance.
-
Parental & Family Support — Paid parental leave and a digital program for paths to parenthood (including adoption and surrogacy) are explicitly called out. Resources also extend to family medical leave and, in some locations, an onsite Mother’s Room.
Coupa Insights
What We Do
Coupa is a global technology company that helps businesses run smarter by connecting all the ways they spend money — from procurement and expenses to payments and supply chain decisions — in one intelligent platform. In simple terms, Coupa gives organizations the visibility and control they need to make better financial choices, reduce waste, and drive real impact. It’s where technology meets purpose: helping companies manage their resources more responsibly while creating a positive ripple across their people, partners, and the planet.
Why Work With Us
At Coupa, we prioritize an inclusive and empathetic workplace where every voice is valued. Our teams are proactive and accountable, ensuring we collaborate effectively to achieve our goals. The foundation of our culture rests on our people; we believe in fostering an environment that encourages innovation and curiosity.
Gallery
Coupa Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Our virtual-first approach is intentional. It gives you the freedom to do your best work in a space that supports focus, balance, and creativity, while staying connected to a global team of changemakers who are redefining the future of business spend


















