The Role
Hands-on Staff Security Engineer to build and operate DevSecOps capabilities: automate security controls, harden AWS/cloud and CI/CD, improve supply-chain security, build detection/response tooling, partner with engineering for secure design, and lead incident response and compliance automation.
Summary Generated by Built In
About Nue.io
Responsibilities:
What You’ll Bring:
What We Offer:
Nue is the AI-powered revenue architecture platform that unifies CPQ, billing, and revenue lifecycle management into a single system. It enables companies to simplify complex pricing, automate monetization, and gain full control over how they generate and scale revenue. Working with customers such as OpenAI, Chilipiper, Glean, HootSuite, and Mews. Nue helps sales, operations, and finance teams gain revenue acceleration, operational efficiency and revenue controls at speed and scale.
What You’ll Do:We're looking for a highly motivated Staff Security Engineer to join our DevSecOps team and help build and operate the security foundation of Nue's platform and engineering systems.
This is not a policy or analyst role. We want someone who is hands-on, writes code, automates security controls, improves infrastructure, hardens systems, and helps engineers ship safely at speed.
You'll work at the intersection of software engineering, cloud infrastructure, security operations, and developer enablement. You'll partner closely with Product Engineering, Platform, and DevSecOps teams to reduce real risk through practical engineering.
If you're passionate about securing cloud-native systems, building internal tooling, improving detection and response, and making security a force multiplier for engineering, this is the role for you.
- Drive secure-by-default patterns across the organization through reusable libraries, templates, guardrails, and paved-road workflows, improving security posture across cloud infrastructure, the application stack, and developer workflows.
- Lead practical threat modeling for new product capabilities, platform changes, and high-risk workflows, translating findings into clear engineering actions.
- Help define the security tooling strategy across application security, cloud security, detection, and developer workflows, evaluating and integrating tools that meaningfully reduce risk without slowing delivery.
- Improve software supply chain security across build systems, dependencies, container images, secrets, and deployment processes.
- Design, build, and operate security automation and production-quality tooling for identity and access management, secrets management, vulnerability management, and policy enforcement.
- Harden AWS environments, containerized workloads, and CI/CD pipelines, using AI-assisted tooling to accelerate work where it genuinely helps.
- Build and maintain detection and alerting for meaningful security events across endpoints, cloud infrastructure, application logs, audit trails, and identity systems.
- Partner with engineering teams to review architecture, application design, infrastructure changes, and operational patterns with a focus on reducing exploitable risk.
- Support compliance and audit needs through engineering-driven controls, evidence automation, logging, and repeatable operational practices.
- Own hands-on incident response, including triage, containment, root cause analysis, remediation, and post-incident follow-through.
- Participate in on-call rotations for high-severity security and platform incidents and build and test response procedures for scenarios such as credential compromise, privilege escalation, and exposed secrets.
- Bachelor's degree in Computer Science, Engineering, or equivalent practical experience.
- 8+ years of experience across software engineering, infrastructure engineering, platform engineering, SRE, DevOps, security engineering, or related roles in production SaaS environments.
- 3+ years of hands-on experience in security engineering, platform security, cloud security, or related security-focused roles.
- Strong hands-on experience securing cloud-native environments on AWS.
- Proven ability to write code for automation, integrations, internal tooling, and operational workflows using languages such as Python, Go, JavaScript, or Bash.
- Experience operating in a DevSecOps or platform-adjacent model where security is embedded into delivery pipelines and engineering workflows.
- Strong experience with identity and access management, secrets handling, key management, logging, auditability, and least-privilege design.
- Experience building or operating security controls for CI/CD, infrastructure as code, containerized systems, and developer platforms.
- Practical experience with security monitoring, detection engineering, alert tuning, and incident response.
- Ability to assess real-world risk and prioritize pragmatic fixes over theoretical perfection.
- Experience partnering with engineering teams to improve security architecture, code patterns, infrastructure posture, and operational readiness.
- Demonstrated ability to use AI-assisted development tools to accelerate investigations, automate repetitive work, and improve engineering effectiveness while maintaining strong judgment.
- Comfortable working in a fast-paced startup environment with a small, high-impact team.
- Excellent communication and collaboration skills, able to explain trade-offs clearly and drive consensus without becoming a bottleneck.
- Competitive compensation and benefits that reward your talent and impact.
- Comprehensive health, vision, dental, and life insurance
- A front-row seat in the Silicon Valley tech ecosystem, where you’ll work on cutting-edge challenges shaping the future of SaaS, finance, and payments.
- The opportunity to build truly groundbreaking products — your work won’t just support the business; it will influence how companies around the world monetize and grow.
- A high-energy, collaborative culture where smart, supportive teammates push each other to learn fast, think boldly, and do the best work of their careers.
- Room to grow, lead, and make your mark in a fast-scaling company that values creativity, ownership, and ambition.
Nue.IO is an equal opportunity employer and welcome people of diverse backgrounds, perspectives, and skills.
We will work with applicants to provide accommodations at any stage of the hiring process.
If you require accommodations during the interview process, please email your Talent Partner, and we will work with you to meet your needs.
Skills Required
- Bachelor's degree in Computer Science, Engineering, or equivalent practical experience
- 8+ years experience across software, infrastructure, platform, SRE, DevOps, security engineering, or related production SaaS roles
- 3+ years hands-on security engineering, platform security, or cloud security experience
- Strong hands-on experience securing cloud-native environments on AWS
- Proven ability to write automation and tooling code using Python, Go, JavaScript, or Bash
- Experience operating in a DevSecOps or platform-adjacent model, embedding security into delivery pipelines
- Experience with identity and access management, secrets handling, key management, and least-privilege design
- Experience building or operating security controls for CI/CD, infrastructure as code, and containerized systems
- Practical experience with security monitoring, detection engineering, alert tuning, and incident response
- Experience improving software supply chain security across build systems, dependencies, and container images
- Ability to assess real-world risk and prioritize pragmatic fixes over theoretical perfection
- Experience partnering with engineering teams to review architecture, design, and operational patterns for security
- Willingness to participate in on-call rotations for high-severity security and platform incidents
- Strong communication and collaboration skills to explain trade-offs and drive consensus
- Demonstrated ability to use AI-assisted development tools to accelerate investigations and automation
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Nue is an easy-to-manage, omni-channel Quote-to-Revenue Platform that meets the needs of companies looking to innovate and manage their revenue lifecycles end-to-end. With Nue, all go-to-market teams accelerate sales with innovative and flexible pricing models, out-of-the-box customer lifecycle management, and seamless billing – all while delivering complete revenue visibility and accurate analytics to finance.







