Sr Security Engineer
Job Summary
Coupa is seeking a Senior Security Engineer to protect enterprise, product, platform, and customer data by building cloud security controls and automated tooling. You will partner with Engineering, IT, and Compliance to design multi-cloud security, harden containerized workloads, and handle vulnerability remediation. The role requires practical cloud experience, strong automation skills, and a dedication to maintaining robust security standards.
Responsibilities
- Design and implement multi-cloud security controls
- Build policy as code and IaC security guardrails in CI/CD
- Harden containerized workloads and Kubernetes clusters
- Perform vulnerability analysis and implement secure remediations
- Support incident response and partner on compliance frameworks
Required Skills
- 5+ years in security engineering or cloud operations
- Practical cloud security experience (AWS, GCP, or Azure)
- Scripting skills in Python, Bash, or JavaScript
- Experience with vulnerability scanning and CI/CD integration
- Familiarity with compliance frameworks like SOC 2 and ISO 27001
Job Details
The Impact of a Sr Security Manager at Coupa:
Coupa's Security Engineers keep our enterprise, product, platform, and customer data safe. As a Senior Security Engineer, you'll take ownership of complex, ambiguous security problems end to end - building cloud security controls, setting engineering standards, and partnering closely with Engineering, IT, and Compliance to ship durable, automated security tooling rather than one-off fixes. You'll set the technical standard for how the team remediates and automates, and you'll be a go-to resource other engineers turn to when a finding needs real root-cause analysis instead of a quick workaround.
What You'll Do:
- Design and implement multi-cloud security controls across Coupa's cloud environment, including VPC segmentation, security groups/NACLs, IAM policy design using least-privilege and permission boundaries, and Organizations/SCPs for guardrails at scale.
- Build policy as code and IaC security guardrails and wire them into CI/CD as pre-merge and pre-deploy gates rather than after-the-fact reviews.
- Harden containerized workloads and Kubernetes clusters - image scanning, admission control, pod security standards, network policies, and container/workload runtime detection.
- Own vulnerability analysis of application packages, container images, and third-party dependencies; triage findings by exploitability and business impact rather than CVSS score alone.
- Design and implement remediations (not just report findings) including secure code fixes, cloud configuration changes, and IAM policy adjustments using least-privilege principles.
- Support incident response and forensics as a technical contributor - log analysis, root-cause investigation, and remediation validation using cloud-native and EDR tooling.
- Partner with the Risk & Compliance team to provide technical evidence and control validation for audit frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP).
- Support and mentor other security engineers - reviewing designs and remediation plans, sharing root-cause analysis techniques, and helping less experienced teammates work through complex or ambiguous findings.
- Participate in the on-call/incident rotation and help continuously improve remediation and response runbooks.
What You Will Bring to Coupa:
- 5+ years of experience in security engineering or cloud operations, with a track record of independently owning complex assessments from scoping through remediation.
- Practical experience with cloud security fundamentals (AWS, GCP, or Azure) - IAM, networking, and common misconfiguration classes - sufficient to both find and fix cloud findings.
- Strong scripting/automation skills in Python, Bash, or JavaScript, with experience building or extending internal security tooling.
- Experience with dependency/container vulnerability scanning tools and integrating them into CI/CD pipelines.
- Working knowledge of common compliance frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP) and what auditable evidence looks like.
- Critical thinking and root-cause analysis skills - comfortable digging past a scanner's output to understand and explain why a vulnerability exists.
- Clear written and verbal communication skills for translating technical findings into remediation guidance for engineers and risk context for stakeholders.
- Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
- Relevant certifications a plus: CISSP, CCSP, CISA, or AWS/GCP security certifications.