---
title: "Security Engineer"
company: "Censys"
company_url: "https://www.remjobs.works/companies/censys"
url: "https://www.remjobs.works/job/censys-security-engineer-0959aee7-934d-491d-aa5a-efb1ffc978d1"
apply_url: "https://job-boards.greenhouse.io/censys/jobs/8541287002"
workplace: remote
location: "Remote"
employment_type: unspecified
seniority: mid
role: devops-infrastructure
region: other
date_posted: 2026-09-22T20:15:10.000Z
first_seen_by_remjobs: 2026-09-22T20:36:52.814Z
---

# Security Engineer

**Censys** · Remote

Apply: https://job-boards.greenhouse.io/censys/jobs/8541287002

## About Censys

Censys empowers security teams with the most comprehensive, accurate, and up-to-date map of the internet to defend attack surfaces and hunt for threats.

## About the role

##### Company Background

Censys’ mission is to be the one place to understand everything on the internet. Frustrated by the lack of trustworthy Internet intelligence, we set out to create the industry’s most comprehensive, accurate, and up-to-date map of the Internet. Today, Censys delivers real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide.

Censys maps the internet. Our customers rely on us for the exposure and threat intelligence that shapes their security programs — which means the bar for our own security is not theoretical. You'll help set it.

This is a senior, high-ownership role on a small team. You will own the identity program, cloud security posture, and vulnerability management end to end, serve as a core incident responder, and build the automation — increasingly agentic — that enables our team to operate at the scale of a much larger one. You'll also be one of our most direct users of our own product: monitoring Censys's external attack surface with Censys is part of the job.

We're looking for someone well-rounded rather than narrowly specialized, who is energized by AI and wants to build with it, and who is comfortable deciding what matters most when everything looks urgent.

**What You’ll Do:**

- Identity & Access Management Own identity as a program, not a ticket queue. Drive down standing access and manual provisioning over time for joiner-mover-leaver changes and non-human identity management.

- Cloud Security (GCP-first) Harden and continuously improve our cloud-native environment: organization policy, IAM least privilege, service account and workload identity hygiene, network segmentation, secrets management, and posture monitoring. Partner with SRE on infrastructure-as-code guardrails so security is enforced at build time, not discovered later.

- Vulnerability Management Own the program: asset coverage, risk-based prioritization that weighs real exploitability and exposure rather than raw CVSS, defensible SLAs, hands-on partnership with engineering on remediation, and reporting leadership can act on. Use Censys to keep an outside-in view of our own attack surface.

- Detection & Incident Response Build detection coverage for identity, cloud, and SaaS. Share in the security escalation rotation, lead or co-lead high-severity incidents, run blameless post-incident reviews, and turn findings into durable fixes. Maintain runbooks and run tabletops that are actually exercised.

- AI and Agentic Security Two halves, both yours:

- Securing our AI footprint. Non-human and agent identity, MCP server and tool-permission scoping, secrets handling for autonomous workflows, data-flow review for AI-enabled features, untrusted-input and prompt-injection boundaries, and security review of AI tooling adopted across the company.

- Building with agents. Design and ship agentic security workflows — alert triage and enrichment, evidence collection, access review orchestration, phishing response, posture drift detection — that measurably reduce manual toil.

- Security Automation and Slack-Native Operations Censys runs on Slack. Security should meet people where they already work: ChatOps-driven requests and approvals, self-service paths that are easier than the insecure alternative, and automation over documentation wherever possible.

*Scope note: Application and product security are owned by our SRE team. You'll partner closely with them on cloud and infrastructure guardrails and contribute security expertise to their work — but you are not expected to own the SDLC or product security roadmap.*

**What You’ll Bring:**

- 5+ years in security engineering, with real depth in at least two of: identity and access management, cloud security, vulnerability management, detection and response.

- Hands-on identity operations experience — SSO/SAML/OIDC, MFA and conditional access, device trust, lifecycle automation. Direct Duo and Google Workspace experience is a significant advantage.

- Experience securing cloud-first or cloud-native environments. GCP preferred; strong AWS or Azure background with genuine interest in going deep on GCP works.

- Scripting and automation ability — Python, Go, or similar — sufficient to build tooling and API integrations, not only to configure vendor products.

- Incident response experience as a primary responder or lead on high-severity incidents, including post-incident analysis.

- Genuine enthusiasm for AI, and hands-on experience building with LLMs or agent frameworks (professional, open source, or personal projects all count).

- Working familiarity with a prescriptive control framework — ISO 27XXX, CMMC, FedRAMP — and the judgment to implement controls as engineering rather than paperwork.

- Comfort operating with ambiguity on a lean team: you can prioritize independently, say no with a reason, and finish things.

- Strong written communication for an async, Slack-heavy environment.

**Bonus Points:**

- Deep GCP expertise: organization policies, VPC Service Controls, workload identity federation, custom org constraints.

- Experience securing or building agentic systems, MCP servers, or AI-enabled products.

- Detection engineering and SIEM or data-pipeline experience.

- Prior experience on a security team at a security product company.

- Direct experience taking an organization through CMMC assessment or a FedRAMP authorization, including boundary definition and continuous monitoring.

- SOC 2, ISO 27001, ISO 42001, or GDPR experience and how it intersects with engineering practice.

- Defining and reporting security metrics to executive stakeholders.

- Open source contributions, published research, tooling, advisories, or conference talks.

- Relevant certifications such as GCP Professional Cloud Security Engineer, GIAC (GCFA, GCDA, GCSA), or OSCP.

For high cost of living areas in the US (San Francisco / Seattle / NYC), the expected salary range for this position is 139,000 USD - $167,000 USD, plus bonus eligibility and equity.

For all other locations in the US, the expected salary range for this position is $121,000 USD - $155,000 USD, plus bonus eligibility and equity. 121,000 - $155,000

For candidates being considered outside of the US, location specific market data will be evaluated and discussed during the interview process.

Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. The listed range is a guideline, and the range for this role may be modified. For roles that are available to be filled remotely, the pay range is localized according to employee work location by a factor of between 83% and 100% of range. Please discuss your specific work location with your recruiter for more information.

For US Employees: Censys offers a competitive benefits package to employees, including equity, health, dental & vision coverage, retirement with company contribution, parental leave, mental health & wellness benefits, flexible PTO, and a professional development stipend. Censys also offers sales incentive pay for most sales roles and an annual bonus plan for eligible non-sales roles. Please see our [careers page](https://censys.com/careers/) for more details. For employees located outside of the US, location-specific benefits are available and will the information pertaining to those will be provided to you during the interview process.

We will work to ensure individuals with disabilities are provided reasonable accommodation to apply for a role, participate in the interview process, perform essential job functions, and receive other benefits and privileges of employment. If you require accommodation, please reach out to your recruiter. These modifications enable an individual with a disability to have an equal opportunity not only to get a job, but successfully perform their job tasks to the same extent as people without disabilities.

To ensure the integrity of our hiring process and in attempt to facilitate a more personal connection, we require all candidates to keep their cameras on during video interviews. You may also be required to meet a Censys employee at one point during your process. Additionally, if hired, you will be invited to visit Ann Arbor, Michigan for in-person onboarding.

By applying for this job, the candidate acknowledges and agrees that any personal data contained in their application or supporting materials will be processed in accordance with our [Censys Privacy Policy](https://censys.com/privacy-policy/).

We value diversity and are committed to creating an inclusive environment for all employees. Censys is an [equal opportunity employer](https://www.eeoc.gov/sites/default/files/2022-10/EEOC_KnowYourRights_screen_reader_10_20.pdf).

Note to external recruiters/agencies: We are not currently engaging with third-party agencies for this role and will not accept unsolicited outreach. We kindly ask that you do not submit resumes or candidate profiles to our team.

###### Identity Verification

As part of our hiring process, all candidates who receive an offer of employment will be asked to complete an identity verification through CLEAR.

**California Privacy Rights Notice**

Pursuant to the California Consumer Privacy Act (CCPA), we are providing you with notice that we collect personal information from job applicants for business purposes, including evaluating your candidacy for employment, conducting interviews, and, if applicable, completing the hiring process. The categories of information we may collect include identifiers (such as name and contact information), professional or employment-related information (such as work history, education, and references), and other information you provide in your application. We do not sell or share your personal information. For more information on how we use and protect your personal information, and your rights under the CCPA, please refer to our [Privacy Policy](https://censys.com/privacy-policy#:~:text=California%20resident%20rights).

---

Source: Censys's own career page, read by RemJobs. Canonical HTML version: https://www.remjobs.works/job/censys-security-engineer-0959aee7-934d-491d-aa5a-efb1ffc978d1
