Staff Site Reliability Engineer, Security
Hackajob
United States$140k–$180kPosted Aug 8, 2026
Staff Site Reliability Engineer, Security
hackajob United StatesStaff Site Reliability Engineer, Security
hackajob
United States
1 week ago
37 applicants
See who hackajob has hired for this role
Use AI to assess how you fit
Get AI-powered advice on this job and more exclusive features.
hackajob provided pay range
This range is provided by hackajob. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.
Base pay range
$140,000.00/yr - $180,000.00/yr hackajob is collaborating with Stord to connect them with exceptional professionals for this role.Stord is The Consumer Experience Company, powering seamless checkout through delivery for today's leading brands. Stord is rapidly growing and is on track to double our revenue in the next 18 months. To meet and exceed this target, Stord is strategically scaling teams across the entire company, and seeking energetic experts to help us achieve our mission.
By combining comprehensive commerce-enablement technology with high-volume fulfillment services, Stord provides brands a platform to compete with retail giants. Stord manages over $10 billion of commerce annually through its fulfillment, warehousing, transportation, and operator-built software suite including OMS, Pre- and Post-Purchase, and WMS platforms. Stord is leveling the playing field for all brands to deliver the best consumer experience at scale.
With Stord, brands can increase cart conversion, improve unit economics, and drive sustained customer loyalty. Stord’s end-to-end commerce solutions combine best-in-class omnichannel fulfillment and shipping with leading technology to ensure fast shipping, reliable delivery promises, easy access to more channels, and improved margins on every order.
Hundreds of leading DTC and B2B companies like AG1, True Classic, Native, Seed Health, quip, goodr, Sundays for Dogs, and more trust Stord to deliver industry-leading consumer experiences on every order. Stord is headquartered in Atlanta with facilities across the United States, Canada, and Europe. Stord is backed by top-tier investors including Kleiner Perkins, Franklin Templeton, Founders Fund, Strike Capital, Baillie Gifford, and Salesforce Ventures.
We are seeking a scrappy, high-ownership Staff Site Reliability Engineer (SRE) to join our lean, fast-moving SRE team. This is a security-focused engineering role rather than a policy or audit one. You'll write code, build automation, integrate scanners into CI/CD, ship Terraform modules the rest of the team can adopt, and drive Dependabot triage with engineering teams. Together, you'll define what "secure by default" actually looks like in our GCP environment and GitHub organization, then make it operational.
Why This Role
- A clear charter with a foundation to build on. Cloud security posture, vulnerability/dependency management, and security solution engineering are yours. The pieces exist (scanners, IAM controls, edge protections, GitHub baselines), but no one has stitched them into a coherent program. You will.
- Build the program, then scale it through the team. You're shipping security tooling, automation, and IaC modules the rest of SRE can run. The work scales through the team rather than centralizing on one person.
- Real platform surface area. You're working across GKE workloads, Istio mesh, Cloud Armor, Cloudflare edge, GitHub Actions supply chain, and GCP IAM. The kind of stack with enough surface area that you can make a measurable impact in your first quarter.
- High-signal moment in the industry. Post-Shai-Hulud, post-XZ, post-everything: CI/CD supply chain hardening, secret management, and short-lived credentials are no longer aspirational. You'll be implementing security best practices, not just documenting them.
Cloud Security Posture Management
- Assess and harden Stord's GCP footprint (GKE, IAM, Cloud Armor), and codify the baseline in Terraform and policy-as-code where it makes sense.
- Build continuous posture monitoring against that baseline, with a published gap list and remediation schedule.
- Drive the evaluation, integration, and rollout of new security tooling as the program matures. You'll lead the conversations and recommendations on what we adopt, what we build in-house, and what we sunset.
- Establish and automate the vulnerability and dependency remediation workflow across engineering teams: triage cadence, ownership model, severity-based SLAs, and the tracking infrastructure that drives closure.
- Own Dependabot configuration and triage workflows across our GitHub organization, plus secret scanning, push protection, and response workflows for any secrets that surface.
- Build supply-chain controls into CI/CD: provenance, dependency review, lockfile policies, build attestation where it pays off.
- Wire container image scanning and DAST/network scanning programs into the same workflow so vulnerabilities don't slip through the cracks between layers.
- Build security capabilities that the broader SRE team can run as part of their normal operating model: Terraform modules, Cloud Armor rules, Istio authorization policies, Cloudflare configuration, scanner pipelines, and custom automation that fills gaps in off-the-shelf tooling.
- Ship documentation, runbooks, and self-service tooling that make your designs portable to the rest of the team, so the program continues to function smoothly through handoffs and rotations.
- Set the engineering bar for security work inside SRE: code review standards, IaC patterns, "secure by default" templates for new services.
- Partner cross-functionally with engineering teams on app security questions, IT on identity and endpoint boundaries, and IT/compliance on occasional SOC 2 evidence pulls, without owning those domains.
Required
- Deep GCP and GKE security experience. You've hardened production Kubernetes on GCP: workload identity, RBAC, network policies, Pod Security Standards, image provenance. You know where the sharp edges are and which knobs actually matter.
- Dependabot and secret scanning at scale. Hands-on with Dependabot configuration, triage workflows, and remediation tracking. Comfortable rolling out GitHub secret scanning organization-wide, including push protection and response workflows for found secrets.
- CI/CD supply chain hardening. You've designed or operated controls against the threat model that produced Shai-Hulud, XZ, and SolarWinds. Familiar with SLSA, provenance, sigstore, and the trade-offs between rigor and developer friction.
- Cloud security posture management in practice. You've stood up CSPM (built-in, commercial, or open source), defined a baseline, and driven remediation, with an eye for separating real signal from dashboard noise.
- Infrastructure-as-code and automation fluency. Comfortable with Terraform for cloud resources and writing code (Python, Go, shell, or similar) to automate security workflows, integrate tools, and build in-house capabilities when off-the-shelf options fall short.
- Systems-level technical fluency. You can reason about how the platform pieces fit together (GKE workloads, networking, edge, CI/CD) and debug security-relevant infrastructure problems alongside the broader SRE team.
- Track record of designing for operability. You've shipped tools and workflows that other engineers actually adopt and rely on day-to-day.
- Ownership & Accountability. You own features end-to-end and take pride in what you ship. You follow through from design to production and don't drop things.
- Strong Communication. You can explain technical decisions and trade-offs to engineers, PMs, and stakeholders. You ask good questions and listen well.
- Collaborative Approach. You work well with others, give constructive code review feedback, and actively seek input from teammates.
- Production Mindset. You prioritize reliability and user impact. You think about failure modes, monitoring, and operational concerns as part of your design process.
- Learning Agility. You're comfortable with rapidly evolving AI/ML technologies and tools. You stay current without chasing hype.
- Directed AI-Assisted Development. You know how to use AI coding tools as a productivity multiplier while maintaining quality and your own technical judgment.
- Container and image scanning. Production experience integrating image scanners into CI/CD and registry workflows, with thoughtful handling of vulnerability data freshness and triage.
- DAST and network scanning programs. OWASP ZAP, nmap, or commercial equivalents, built into a repeatable internal audit cadence rather than one-off exercises.
- Cloudflare edge security. WAF rules, rate limiting, bot management, and how that fits with origin-side Cloud Armor.
- Detection engineering on GCP. Log Explorer, BigQuery-backed security analytics, and alert tuning that keeps the on-call experience humane.
- Prior experience standing up a security program inside an SRE or platform team, taking partial foundations and making them coherent.
- Familiarity with the current supply-chain threat landscape and recent CISA guidance (post-Shai-Hulud token guidance, M-22-18 / SSDF, etc.).
- Contributions to open-source security tooling or published security research.
- 30 days: You've ramped on Stord's GCP footprint, GitHub configuration, and existing security tooling. You've identified the top three posture gaps and the top three CI/CD supply chain risks, and you've socialized them with SRE leadership.
- 90 days: The vulnerability and dependency remediation workflow is live with at least one engineering team as a pilot, including triage cadence, ownership model, and remediation tracking against documented SLAs.
- 6–12 months: The remediation workflow is rolled out across engineering. A documented cloud security posture baseline exists, with a prioritized gap list under active remediation on a published schedule. The broader SRE team is operating security tooling you designed without you being in the loop on every alert.
-
Seniority level
Mid-Senior level -
Employment type
Full-time -
Job function
Engineering and Information Technology -
Industries
IT Services and IT Consulting
Referrals increase your chances of interviewing at hackajob by 2x
See who you knowGet notified about new Site Reliability Engineer jobs in United States.
Sign in to create job alertSimilar jobs
-
Staff Site Reliability Engineer, Security
Staff Site Reliability Engineer, Security
Stord
United States 1 month ago -
Senior / Staff Site Reliability Engineer
Senior / Staff Site Reliability Engineer
Radar
United States 2 days ago -
Staff Site Reliability Engineer- Remote
Staff Site Reliability Engineer- Remote
BeyondTrust
United States 3 days ago -
Staff Site Reliability Engineer
Staff Site Reliability Engineer
Babylist
United States 13 hours ago -
Staff Site Reliability Engineer - Volcano
Staff Site Reliability Engineer - Volcano
Kong
United States $150,000.00 - $210,000.00 4 days ago -
Staff Site Reliability Engineer
Staff Site Reliability Engineer
FloSports
United States 1 week ago -
Staff Platform Engineer
Staff Platform Engineer
Postscript
United States $190,000.00 - $230,000.00 2 weeks ago -
Staff Site Reliability Engineer
Staff Site Reliability Engineer
BlinkRx
United States 17 hours ago -
Staff Site Reliability Engineer
Staff Site Reliability Engineer
bolt.new
United States 2 weeks ago -
Staff DevSecOps Engineer
Staff DevSecOps Engineer
Redox
United States 2 days ago -
Staff Site Reliability Engineer
Staff Site Reliability Engineer
Coalition, Inc.
United States 3 weeks ago -
Staff Infrastructure Engineer — Observability
Staff Infrastructure Engineer — Observability
SentinelOne
United States 2 weeks ago -
Staff Site Reliability Engineer
Staff Site Reliability Engineer
Filevine
United States $240,000.00 - $275,000.00 1 week ago -
Staff Site Reliability Engineer, Core AI Infrastructure
Staff Site Reliability Engineer, Core AI Infrastructure
Coinbase
United States 2 weeks ago -
Staff Platform Engineer
Staff Platform Engineer
Wurl
United States 1 week ago -
Senior Staff Operations Engineer, AIOps
Senior Staff Operations Engineer, AIOps
Airbnb
United States 2 weeks ago -
Lead Site Reliability Engineer
Lead Site Reliability Engineer
Movable Ink
United States 4 days ago -
Staff Site Reliability Engineer
Staff Site Reliability Engineer
Wand AI
Palo Alto, CA 2 months ago -
Principal DevSecOps Engineer - AI Infrastructure
Principal DevSecOps Engineer - AI Infrastructure
IR
United States $230,000.00 - $260,000.00 3 weeks ago -
Sr. Site Reliability Engineer
Sr. Site Reliability Engineer
Backblaze
United States 4 months ago -
Site Reliability Engineer
Site Reliability Engineer
MyFitnessPal
United States 1 week ago -
Principal DevOps Engineer
Principal DevOps Engineer
Malwarebytes
United States 1 month ago -
Staff Site Reliability Engineer
Staff Site Reliability Engineer
Finalsite
United States $180,000.00 - $250,000.00 2 months ago -
Site Reliability Engineer (Senior or Staff), Infrastructure Security
Site Reliability Engineer (Senior or Staff), Infrastructure Security
MongoDB
San Francisco, CA 5 days ago -
Staff Site Reliability Engineer
Staff Site Reliability Engineer
Domino Data Lab
United States 3 days ago -
Staff Platform Engineer
Staff Platform Engineer
Cortex
New York, NY 1 day ago -
Senior Staff DevOps Engineer
Senior Staff DevOps Engineer
SailPoint
United States 4 days ago
People also viewed
-
Staff Site Reliability Engineer
Staff Site Reliability Engineer
Palo Alto, CA $180,000.00 - $210,000.00 1 week ago -
Staff Site Reliability Engineer
Staff Site Reliability Engineer
San Francisco, CA 2 weeks ago -
Senior Infrastructure Engineer
Senior Infrastructure Engineer
United States 5 months ago -
Lead Site Reliability Engineer
Lead Site Reliability Engineer
United States 2 months ago -
Member of Technical Staff, Infrastructure
Member of Technical Staff, Infrastructure
United States $220,000.00 - $280,000.00 2 weeks ago -
Staff Platform Engineer - Americas
Staff Platform Engineer - Americas
United States $232,000.00 - $323,000.00 5 days ago -
Senior Site Reliability Engineer
Senior Site Reliability Engineer
United States $150,000.00 - $200,000.00 3 weeks ago -
Staff DevSecOps Engineer
Staff DevSecOps Engineer
United States 5 days ago -
Senior / Staff Engineer - Platform
Senior / Staff Engineer - Platform
San Francisco, CA 3 months ago -
Staff Infrastructure Security Engineer
Staff Infrastructure Security Engineer
United States 2 weeks ago
Similar Searches
-
Site Reliability Engineer jobs
169,128 open jobs -
Flash Developer jobs
57 open jobs -
Geek Squad jobs
910 open jobs -
Platform Engineer jobs
56,237 open jobs -
Site Engineering Manager jobs
12,353 open jobs -
Senior Unix Engineer jobs
9,970 open jobs -
Linux System Engineer jobs
18,569 open jobs -
Senior Infrastructure Engineer jobs
33,051 open jobs -
Build And Release Engineer jobs
14,154 open jobs -
Linux Engineer jobs
23,514 open jobs -
Production Support Engineer jobs
224,323 open jobs -
System Development Engineer jobs
237,756 open jobs -
Senior Infrastructure Analyst jobs
1,977 open jobs -
Principal Infrastructure Engineer jobs
7,502 open jobs -
Network Project Engineer jobs
10,282 open jobs -
Senior Escalation Engineer jobs
14,746 open jobs -
Linux System Administrator jobs
9,806 open jobs -
Infrastructure Engineer jobs
64,841 open jobs -
Reliability Manager jobs
10,044 open jobs -
Senior Professional Services Engineer jobs
14,745 open jobs
Only part of this posting is shown here. Read the full description