We are seeking a Security Engineer II to join our growing security team. This role will have a huge impact on maintaining and improving Greenlight’s security posture by developing and implementing automated workflows or AI toolings.
Design, build, and maintain high-scale automation and AI workflows to improve security and business systems operations, internal processes and team efficiency.
Build custom integrations and internal tooling using Python(preferred), Go, or AWS services across SaaS platforms, cloud systems, and internal APIs.
Develop AI-assisted workflows and guardrails that help teams use automation safely and effectively.
Build and configure automated tooling for real-time monitoring of data security, privacy, and vulnerability management.
Enhance and utilize the Security team's primary orchestration platform (i.e. Tines), specifically targeting improvements in alerting mechanisms, investigation procedures, data enrichment, approval processes, and cross-system automation capabilities.
Partner with IT, Engineering, and Business Owners to identify operational bottlenecks and deploy AI-powered solutions that enhance both security and efficiency.
Improve how security controls are embedded into CI/CD pipelines and engineering workflows through automation-first solutions.
Create dashboards, utilities, and self-service tools that reduce operational overhead and improve visibility.
Support security-focused use cases such as vulnerability management, access reviews, alert triage, logging and monitoring workflows, and secure development practices.
Document workflows, playbooks, and system designs so they are maintainable, transparent, and easy to evolve.
4+ years of professional experience in Cybersecurity, DevOps, or Software Engineering with a focus on automation or tooling.
Strong proficiency in Python (preferred) or Go for building custom security tools, internal utilities, and API-heavy integrations across SaaS and cloud platforms.
Hands-on experience with CI/CD platforms (GitHub Actions, GitLab CI) and embedding shift-left security controls into engineering workflows.
Solid understanding of cloud security principles (AWS preferred), containerization (Docker/K8s), and securing distributed systems.
Experience with no-code/low-code security orchestration platforms (e.g., Tines, Torq, or Tray.io) and building automated workflows for alert triage, access reviews, and vulnerability management.
Familiarity with compliance frameworks such as SOC 2 or ISO 27001, including experience automating evidence collection or control testing workflows.
Proven experience using AI-assisted development tools (Copilot, Cursor, etc.) and a practical understanding of deploying AI-driven workflows with appropriate guardrails and human-in-the-loop controls.
Working knowledge of the OWASP Top 10, including LLM-specific risks, and secure development practices.
Experience with Infrastructure-as-code (IaC)
Direct experience implementing security controls within both AWS and GCP.
Security certifications such as CISSP, Security+, or specialized GIAC certifications.
Experience handling data privacy requirements (SOC2, GDPR, or CCPA) within automated workflows.