Censys
Security Engineer
Remote. The employer does not say where candidates may be based.
Location not stated
Employer listed it yesterday · Added today
First listed yesterday.
Salary
Not stated
Location
Location not stated
Work style
Async
Contract
Full-time
Experience
Mid
Category
Software
This employer didn't state pay. Jobs like this usually pay around $160k–$255k a year, a typical range taken from 596 mid-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Undisclosed
The listing is advertised as remote but does not state which countries or regions candidates may work from.
Why this role is Undisclosed
We only label a role Work from anywhere, Region restricted or Work from home when the employer's own wording says so. We checked this advert under our current rules and found no country or region eligibility requirement in it. We don't guess, so it stays Undisclosed until the employer publishes enough location information. Here is exactly what the advert left out.
- Countries you can work from: Not stated. The advert only gives "Remote", which names no country you must live in.
- Whether the work is remote: Never mentioned. The role reached us through a remote job board, but the advert itself doesn't say the work is remote.
- Working hours: Stated: Async.
Worth a look all the same. Missing wording is usually a rushed job posting rather than a closed door, so ask where you can be based in your first message, before you write a tailored application.
What the employer says
- Source listing states candidate location: "Remote"
What Nomaders makes of it
- No residency or region requirement found in the job description
- Check with the employer before assuming you can work from abroad
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Company Background
Censys’ mission is to be the one place to understand everything on the internet. Frustrated by the lack of trustworthy Internet intelligence, we set out to create the industry’s most comprehensive, accurate, and up-to-date map of the Internet. Today, Censys delivers real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide.
Censys maps the internet. Our customers rely on us for the exposure and threat intelligence that shapes their security programs — which means the bar for our own security is not theoretical. You'll help set it.
This is a senior, high-ownership role on a small team. You will own the identity program, cloud security posture, and vulnerability management end to end, serve as a core incident responder, and build the automation — increasingly agentic — that enables our team to operate at the scale of a much larger one. You'll also be one of our most direct users of our own product: monitoring Censys's external attack surface with Censys is part of the job.
We're looking for someone well-rounded rather than narrowly specialized, who is energized by AI and wants to build with it, and who is comfortable deciding what matters most when everything looks urgent.
What You’ll Do:
Identity & Access Management Own identity as a program, not a ticket queue. Drive down standing access and manual provisioning over time for joiner-mover-leaver changes and non-human identity management.
Cloud Security (GCP-first) Harden and continuously improve our cloud-native environment: organization policy, IAM least privilege, service account and workload identity hygiene, network segmentation, secrets management, and posture monitoring. Partner with SRE on infrastructure-as-code guardrails so security is enforced at build time, not discovered later.
Vulnerability Management Own the program: asset coverage, risk-based prioritization that weighs real exploitability and exposure rather than raw CVSS, defensible SLAs, hands-on partnership with engineering on remediation, and reporting leadership can act on. Use Censys to keep an outside-in view of our own attack surface.
Detection & Incident Response Build detection coverage for identity, cloud, and SaaS. Share in the security escalation rotation, lead or co-lead high-severity incidents, run blameless post-incident reviews, and turn findings into durable fixes. Maintain runbooks and run tabletops that are actually exercised.
AI and Agentic Security Two halves, both yours:
Securing our AI footprint. Non-human and agent identity, MCP server and tool-permission scoping, secrets handling for autonomous workflows, data-flow review for AI-enabled features, untrusted-input and prompt-injection boundaries, and security review of AI tooling adopted across the company.
Building with agents. Design and ship agentic security workflows — alert triage and enrichment, evidence collection, access review orchestration, phishing response, posture drift detection — that measurably reduce manual toil.
Security Automation and Slack-Native Operations Censys runs on Slack. Security should meet people where they already work: ChatOps-driven requests and approvals, self-service paths that are easier than the insecure alternative, and automation over documentation wherever possible.
Scope note: Application and product security are owned by our SRE team. You'll partner closely with them on cloud and infrastructure guardrails and contribute security expertise to their work — but you are not expected to own the SDLC or product security roadmap.
What You’ll Bring:
5+ years in security engineering, with real depth in at least two of: identity and access management, cloud security, vulnerability management, detection and response.
Hands-on identity operations experience — SSO/SAML/OIDC, MFA and conditional access, device trust, lifecycle automation. Direct Duo and Google Workspace experience is a significant advantage.
Experience securing cloud-first or cloud-native environments. GCP preferred; strong AWS or Azure background with genuine interest in going deep on GCP works.
Scripting and automation ability — Python, Go, or similar — sufficient to build tooling and API integrations, not only to configure vendor products.
Incident response experience as a primary responder or lead on high-severity incidents, including post-incident analysis.
Genuine enthusiasm for AI, and hands-on experience building with LLMs or agent frameworks (professional, open source, or personal projects all count).
Working familiarity with a prescriptive control framework — ISO 27XXX, CMMC, FedRAMP — and the judgment to implement controls as engineering rather than paperwork.
Comfort operating with ambiguity on a lean team: you can prioritize independently, say no with a reason, and finish things.
Requirements
- ·5+ years in security engineering, with real depth in at least two of: identity and access management, cloud security, vulnerability management, detection and response.
- ·Hands-on identity operations experience — SSO/SAML/OIDC, MFA and conditional access, device trust, lifecycle automation. Direct Duo and Google Workspace experience is a significant advantage.
- ·Experience securing cloud-first or cloud-native environments. GCP preferred; strong AWS or Azure background with genuine interest in going deep on GCP works.
- ·Scripting and automation ability — Python, Go, or similar — sufficient to build tooling and API integrations, not only to configure vendor products.
- ·Incident response experience as a primary responder or lead on high-severity incidents, including post-incident analysis.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, undisclosed, matches where you plan to live and work.
- 2Tailor your CV to the role at Censys, mentioning your remote working experience and working hours (Async).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 13h ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $160k to $255k per year · You'll be taken to the employer's careers page.