What You'll Do:
Architect and implement validated security strategies for our AWS-based serverless infrastructure and authentication surfaces, including SAML single sign-on with online-banking identity providers.
Collaborate actively within the MeridianLink Security team to drive automation and detection initiatives, building resilient and self-healing security solutions.
Design, develop, and enhance security tooling, automated checks, and robust CI/CD pipeline controls for our internal tools and services.
Analyze and optimize internal metrics and alerting workflows, meticulously reducing false positives and precision-focusing engineering efforts for maximum impact.
Develop comprehensive, repeatable processes and author detailed playbooks to efficiently and effectively resolve security incidents.
Serve as a primary incident responder and incident manager, participating in a weekly on-call rotation to address critical security events.
What You'll Bring:
Bachelor's degree in Computer Science or a related field, coupled with 2-4 years of direct security experience, or equivalent practical work experience.
Minimum of 3 years of dedicated experience as a Security Engineer or in a closely related position.
At least 2 years of hands-on experience in core cybersecurity technologies, with a strong focus on vulnerability management, security monitoring, data logging, and IAM.
Demonstrated proficiency with AWS security services for a minimum of 1 year, including WAF, GuardDuty, IAM, KMS, and CloudWatch.
2+ years of experience with tool integrations and REST APIs, alongside practical coding experience in TypeScript or Python.
Proven experience in Security Operations, security monitoring, Incident Response, and Threat Intelligence.
Deep proficiency in networking technologies, network security principles, and network monitoring solutions.
Comprehensive knowledge of modern security systems, including authentication and single sign-on (SAML, OIDC/OAuth), web application firewalls, and intrusion detection and notification systems.
Familiarity with Infrastructure as Code methodologies (e.g., Pulumi, SST, Terraform) and public cloud platforms, specifically AWS.