Job Description
Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small. Coupa AI is informed by trillions of dollars of direct and indirect spend data across a global network of 10M+ buyers and suppliers. We empower you with the ability to predict, prescribe, and automate smarter, more profitable business decisions to improve operating margins.
Coupas Security Engineering team protects our enterprise, product, platform, and customer data at scale. As Lead Security Engineer, you will be a hands-on technical leader on the Security Engineering team - architecting and building cloud security controls, setting engineering standards, and partnering closely with Engineering, IT, and Compliance to ship durable, automated security tooling rather than one-off fixes. You thrive on ambiguity, sweat the implementation details, and take pride in solutions that scale across hundreds of accounts and services.
- Architect and build multi cloud security controls across Coupas cloud environment. VPC segmentation, security groups/NACLs, IAM policy design using least-privilege and permission boundaries, and Organizations/SCPs for guardrails at scale.
- Build policy-as-code and IaC security guardrails and wire them into CI/CD as pre-merge and pre-deploy gates rather than after the fact reviews.
- Harden containerized workloads - image scanning, admission control, pod security standards, and runtime detection.
- Write auto-remediation for cloud misconfiguration and drift so common findings close without manual ticket routing.
- Own Vulnerability management program, act as the technical escalation point for security incidents and vulnerability findings - leading forensics, containment, and root-cause analysis using cloud-native and EDR tooling, and driving remediation to closure.
- Partner with Risk Compliance to translate audit framework requirements (SOC 2, ISO 27001, PCI-DSS, FedRAMP) into concrete technical controls, and automate evidence collection by integrating cloud telemetry with GRC tooling.
- Mentor other security engineers through design review, threat modeling, and code/architecture review; raise the technical bar for the whole team.
- Own reference architectures, threat models, and runbooks for the security tooling you build; participate in and help improve the on-call rotation.
- 10+ years of security engineering experience, including significant hands-on work securing production cloud environments at scale, plus experience leading projects or mentoring other engineers.
- Deep, hands-on AWS security expertise - IAM, VPC/networking, KMS, GuardDuty, Security Hub, Config, and Organizations/SCPs; working knowledge of GCP or Azure security is a plus.
- Production experience with Terraform (or equivalent IaC) and policy-as-code frameworks, plus container/Kubernetes security tooling.
- Strong software engineering fundamentals - Python and/or Go, Git-based workflows, and building/maintaining CI/CD security integrations (SAST, DAST, SCA).
- Experience with SIEM/SOAR platforms and vulnerability management tooling (e. g. , Wiz, Qualys, Tenable) - building detections and workflows, not just consuming dashboards.
- Working knowledge of compliance frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP, NIST 800-53) sufficient to translate control requirements into engineering work.
- Excellent written and verbal communication skills - able to write clear technical design docs and explain risk trade-offs to auditors and engineering leadership alike.
- Bachelors degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
- Relevant certifications a plus: CISSP, CCSP, CISA, or AWS/GCP security certifications.
- Some international travel may be required.
- Global Wellness Days: Enjoy two designated, company-wide paid wellness days off each year (typically the first Friday in March and the last Friday in September) so the entire global team can unplug, step away, and recharge together .
- Birthday Time-Off: Celebrate your day! Coupa provides a paid day off on your birthday or another day of your choice within your birthday month .
- Volunteer Time Off (VTO): Giving back is in our DNA. We offer 40 hours of paid VTO annually to support the community initiatives and volunteer programs you are passionate about .
- Employee Assistance Program (EAP): Access free, confidential, 24/7/365 counseling and resources for emotional support, work-life solutions, financial advice, legal guidance, and support for new parents .
- Business Travel Protection: Travel with peace of mind. Zurich Travel Assist provides medical, safety, pre-trip planning, and emergency support during any business travel .
- Referral Bonus Program: Share the Coupa experience! Receive generous monetary referral bonuses when you successfully refer talented friends or acquaintances who are hired into open roles .
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
