Loading jobs…
Loading jobs…
Spire
Endeavour has an exciting opportunity for someone passionate about sustainability and eager to be part of an innovative company that’s on a journey to transform the world’s infrastructure. We are seeking a Senior Security Engineer working directly with Endeavour’s IT team and focusing on troubleshooting technical issues, providing solutions, enhancing existing technology stack and implementing new infrastructure into our ecosystem. This role is part of the support team that services the entire our Endeavour ecosystem and contributes to the overall health and success of the organization.
The Senior Security Engineer needs to be agile, professional, and comfortable in a rapidly changing environment. The right person is trustworthy with confidential information, highly organized, self-motivated, has excellent communication skills, can think strategically, and works equally as well independently as with a team. Endeavour is highly selective about the people we bring on board because our ecosystem depends on it.
Change happens quickly here, and we must maintain a strong team of honest, communicative, collaborative, open-minded, strategic, reliable, and driven team members. We seek ultra-creatives and superstar performers with self-awareness, a sense of humility, and a hunger to make a positive impact in the world. Endeavour offers flexibility and endless growth opportunities to those who can harness their skills and talents and identify how and where to use them to add value.
Our support team is the heart of the ecosystem. We’re a diverse group of bright, passionate, dedicated people, working together to make a real difference. Are you ready to join the journey?
Key Responsibilities
Include but are not limited to: Lead security operations initiatives focused on securing modern software development pipelines, CI/CD platforms, and cloud-native DevOps environments. Partner with engineering and DevOps teams to embed security controls into the Software Development Life Cycle (SDLC) using Dev/SecOps best practices. Design, implement, and monitor security controls for source code repositories, build systems, artifact management platforms, and deployment pipelines.
Conduct threat modeling, risk assessments, application pen testing, and security reviews for internally developed applications, APIs, and automation platforms. Develop and maintain detection and response capabilities for software supply chain threats, credential misuse, pipeline compromise, and cloud workload attacks. Manage vulnerability management processes for applications, containers, infrastructure-as-code, open-source dependencies, and CI/CD tooling.
Implement automated security scanning tools including SAST, DAST, SCA, IaC scanning, and container security solutions. Monitor security events across cloud platforms, developer tooling, SaaS environments, and production systems using SIEM/XDR technologies. Investigate and respond to security incidents involving applications, DevOps tooling, cloud environments, and identity platforms.
Establish security standards for AI/ML systems including model governance, secure API usage, data protection, and responsible AI controls. Assess and mitigate emerging AI-related risks such as prompt injection, model abuse, data leakage, shadow AI usage, and unauthorized automation. Evaluate, implement, and secure enterprise AI tools to improve SecOps efficiency, threat detection, alert triage, and incident response workflows.
Build automation scripts and workflows to streamline repetitive security operations tasks and improve response times. Collaborate with developers to remediate security findings quickly while balancing operational efficiency and release velocity. Create dashboards, metrics, and reporting for security posture across DevOps pipelines, application environments, and AI platforms.