Senior Security Engineer
Vanta's Security team is responsible for safeguarding sensitive data, establishing enterprise-wide security standards, contributing expertise to product and engineering initiatives, and enabling the business to manage risk effectively. As a Senior Security Engineer, you'll own high-impact projects across the organization, working to strengthen our security posture while supporting developers in shipping products securely.
About the Role
You'll be part of Vanta's Security organization, which combines operational security services with embedded involvement in the software development lifecycle. The team builds tools and programs that make secure development frictionless, sets policies across the enterprise, and provides advisory services. In this role, you'll have ownership of security initiatives with visibility across the business, collaborating with engineering, product, sales, and support teams.
Responsibilities
- Lead threat modeling, tabletop exercises, and risk identification activities to uncover potential security vulnerabilities
- Participate in prioritization discussions to determine which security risks require immediate attention
- Plan and execute projects to address prioritized risks, coordinating with cross-functional stakeholders
- Build and maintain operational programs for ongoing security work—such as vulnerability management—to achieve sustained security maturity
- Partner with engineering teams to design secure software architecture, resolve security concerns, and foster a strong security culture
- Implement, customize, and operate security tools to mature the security program while minimizing operational friction
- Manage bug bounty and penetration testing programs
- Develop and support a network of security champions across the organization
- Identify security knowledge gaps in the development organization and deliver training to close them
- Contribute architectural input to enable teams to innovate securely and repeatably
Requirements
- Demonstrated track record of independent ownership and accountability for areas of responsibility
- Hands-on experience with threat modeling, red teaming, penetration testing, or similar methods of identifying security issues
- Software development experience with the ability to read and analyze code for security vulnerabilities
- Strong collaboration and communication skills, with genuine empathy for developer workflows and constraints
- Excellent project management and organizational capabilities
- Openness to using AI tools responsibly to amplify skills, improve efficiency, and enhance impact
Benefits
- Industry-competitive salary and equity
- Comprehensive medical, dental, and vision coverage with 100% of employee-only premiums covered for most medical plans
- 16 weeks paid parental leave for all new parents
- Health and wellness stipend
- Remote workspace, internet, and cellphone stipend
- Commuter benefits for SF and NYC office employees
- Family planning benefits
- 401(k) matching with immediate vesting
- Flexible PTO policy plus 80 hours of annual sick time
- 11 company-paid holidays
- Virtual team building, lunch and learns, and company-wide events
Location: Remote, U.S.
Note on Compensation: Vanta sets standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by candidate location, skills, depth of work experience, and relevant licenses or credentials.