Coupa Software

Coupa Software

Coupa Software is the premier cloud-based finance platform, empowering companies worldwide to optimize spend, boost profits, and reduce costs with a comprehensive suite of modules.

Internet Software & Services
1K-5K
Founded 2006

Description

  • Design and implement multi-cloud security controls across Coupa's cloud environment.
  • Build policy-as-code and infrastructure-as-code security guardrails into CI/CD pipelines.
  • Harden containerized workloads and Kubernetes clusters through scanning, admission control, pod security, network policies, and runtime detection.
  • Own vulnerability analysis for application packages, container images, and third-party dependencies.
  • Design and implement remediations, including secure code fixes, cloud configuration changes, and IAM policy adjustments.
  • Support incident response and forensics through log analysis, root-cause investigation, and remediation validation.
  • Partner with Risk & Compliance to provide technical evidence and control validation for audits.
  • Mentor other security engineers by reviewing designs, remediation plans, and root-cause analyses.
  • Participate in the on-call and incident rotation and improve runbooks and response processes.

Requirements

  • 7+ years of experience in security engineering or penetration testing.
  • Experience independently owning complex assessments from scoping through remediation.
  • Practical experience with cloud security fundamentals in AWS, GCP, or Azure.
  • Experience with IAM, networking, and common cloud misconfiguration classes.
  • Strong scripting and automation skills in Python, Bash, or JavaScript.
  • Experience building or extending internal security tooling.
  • Experience with dependency and container vulnerability scanning tools integrated into CI/CD pipelines.
  • Working knowledge of compliance frameworks such as SOC 2, ISO 27001, PCI-DSS, and FedRAMP.
  • Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • Relevant certifications such as CISSP, CCSP, CISA, or AWS/GCP security certifications are a plus.

Benefits

  • Two company-wide paid Global Wellness Days each year.
  • Paid birthday time off.
  • 40 hours of paid Volunteer Time Off annually.
  • 24/7 Employee Assistance Program with counseling and support resources.
  • Business travel protection through Zurich Travel Assist.
  • Generous employee referral bonus program.
  • Competitive location-specific benefits, including comprehensive medical/dental insurance, retirement/pension plans, and life or accident protection.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec

Elastic 1K-5K Internet Software & Services

Elastic is hiring a Senior Information Security Infrastructure Engineer for its InfoSec Security Architecture team to ingest security telemetry into Elasticsearch and maintain the clusters and pipelines that support detection, incident response, and security consulting.

Elasticsearch GitHub GitHub Actions Helm Kubernetes Python REST API Terraform
8 hours, 47 minutes ago

Cybersecurity Specialist (DISA)

Horizon Industries Limited is seeking a Cybersecurity Specialist to support DISA enterprise software systems remotely in the USA, providing security engineering and information assurance support in an agile environment.

Agile Bash Cybersecurity Linux Perl SIEM SQL Windows Server
8 hours, 47 minutes ago

Director, Security Research

Sysdig 251-1K IT Services

Sysdig is hiring a senior leader to direct its Threat Research Team, focusing on AI security threats, AI-assisted research methods, and production detection capabilities for Sysdig customers and the Falco community.

Kubernetes Linux
9 hours, 17 minutes ago

Security Engineer - SOAR

Centorrino Technologies 51-250 Internet Software & Services

Centorrino Technologies is seeking a Security Engineer specializing in SOAR to develop and implement secure, automated incident-response capabilities for cloud and hybrid environments in Australia.

Network Security
10 hours, 2 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers