Security Engineer II (Remote)
Sign up free to see how well your resume matches this role.
What you'll do
- Lead investigation and resolution of complex security incidents, coordinating across teams and communicating status clearly while facts are still incomplete.
- Design and implement safeguards protecting customer sites, accounts, and infrastructure from active and evolving threats.
- Conduct vulnerability assessments, security reviews, and risk analysis, with remediation guidance engineers can act on.
- Build automation and tooling that improves detection, monitoring, response, and operational safety.
- Partner with Systems, Development, Abuse, and Support to get security controls implemented rather than merely recommended.
- Mentor less experienced team members and contribute to the team's shared knowledge and runbooks.
- Contribute to security policy, standards, and process, and support compliance efforts without mistaking compliance for security.
What they're looking for
- 3–6 years in security engineering, incident response, application security, offensive security, or systems administration, with demonstrated ability to resolve complex security problems independently.
- Depth in at least one of: application security, incident response and detection engineering, or offensive security and penetration testing plus working competence in the other two.
- Strong hands-on Linux (Debian/Ubuntu preferred), including low-level concepts: processes, namespaces, capabilities, filesystems, kernels, and how things actually break.
- Experience operating long-lived production systems that can't simply be rebuilt including repairing hosts in place, under load, with real users on them.
- Experience in multi-tenant or customer-facing environments where users are untrusted.
- Scripting and automation you've shipped and operated in production. Python, Go, Bash, Perl, or similar. We care that you've built and maintained real tooling, not which language.
- Log analysis and investigation at scale, and comfort with intrusion detection and web application firewalls (mod_security or similar).
- Working knowledge of cloud platform security (AWS, GCP, Azure, or OpenStack) including IAM, network controls, and workload isolation.
- Familiarity with secrets management and CI/CD security (Vault or equivalent, pipeline hardening, dependency and supply-chain risk).
- Version control and infrastructure-as-code fluency (Git, Ansible or similar).
- Practical, current fluency with AI tooling in your own work. You use it daily, you know where it fails, and you can say what you don't let it do.
- Clear written and verbal communication, including translating technical risk for non-technical stakeholders.
Nice to have
- Web hosting or WordPress-at-scale experience, as a provider or a customer.
- Container and orchestration security (Podman, Docker, Kubernetes) including escape and isolation failure modes.
- Malware analysis, YARA rule authorship, or reverse engineering.
- Detection-as-code or SIEM engineering experience.
- Hands-on experience securing AI/LLM systems, agent frameworks, or MCP tooling. Prompt injection, tool-permission scoping, or data-boundary work.
- Familiarity with PCI DSS, SOC 2, or ISO 27001 — as context, not as a career.
- Open source contributions.
Summarised by NextRaise from the employer’s description, which follows in full below.
Full description from employer
Why work for DreamHost?
We help people own their digital presence. It's not just wishful thinking. It's our noble cause — an idea that drives everything we do.
When you put your dreams online—your words, your photos, your creations—you shouldn't have to worry about your service provider mining that data for marketing purposes. Those are your dreams — not ours! DreamHost's open platform gives you the power to share your data and the freedom to control how it's used.
Working for DreamHost you can be a steward of your own career. We invest in our people, we promote from within the organization when possible and we offer extensive training to aid in your success. In this role, we offer competitive salary, health, vision, and dental insurance, as well as a company-issued laptop, 401k, opportunities for growth, and much much more! We are proud to be a US employer with a fantastic culture and the ability to offer so much to our employees.
Benefits Offered
Full health/vision/dental for the entire family at zero cost to team member
3% Safe Harbor contributed to 401(k) plus up to 1% employer match
Opportunities for profit sharing and bonuses
Generous time-off (starting at 15 vacation days)
11 Paid holidays (Technical Support and Technical Operations use a floating holiday policy)
Paid sick leave (80 hours accrued)
Tuition reimbursement (50/50 up to a specific amount)
Pet Insurance
Thrive Pass wellness allowance of $30 per month
Udemy online learning courses
Disability Insurance
Generous maternity/paternity leave
Discounted personal travel through corporate booking program Egencia
Laid-back atmosphere
Fun monthly company events
Free web hosting
Overview
The Security Engineer II is responsible for protecting DreamHost, our infrastructure, and our customers in a large, multi-tenant Linux hosting environment where untrusted code runs on our machines by design. This is a hands-on engineering role. You will investigate live compromises, build the tooling and detections that find the next one, review the security of our own applications and infrastructure, and drive down long-standing risk across a fleet spanning shared hosting, VPS, managed WordPress, dedicated servers, cloud, and email.
You will work on a small security team where everyone owns real workstreams end to end, partners directly with Systems, Development, Abuse, and Support, and is expected to exercise judgment without waiting for permission.
What you'll work on
Incident response across shared, virtualized, and dedicated Linux hosts — compromise investigation, blast-radius scoping, containment, evidence preservation, and write-ups.
Detection engineering: malware and webshell signatures, log-based detections, and reducing the false positives that create alert fatigue at fleet scale.
Application security review of our in-house control plane, customer panel, and internal tooling, plus the third-party and open-source code we depend on.
Secrets management modernization such as moving static credentials into Vault, adopting dynamic credentials, and eliminating plaintext secrets from code, logs, and CI.
Identity and access lifecycle: directory and SSO migration, privileged access review, and durable offboarding.
Vulnerability management and patch velocity across a large, heterogeneous fleet, including end-of-life OS and runtime remediation.
Automation. Anything done manually more than twice is a candidate for tooling, and you'll build it.
Security review and governance of AI and agent tooling as it's adopted internally — data exposure, permission scope, agent identity, and abuse paths. You'll also be using these tools heavily yourself; the team runs on them.
Responsibilities
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the role.
Lead investigation and resolution of complex security incidents, coordinating across teams and communicating status clearly while facts are still incomplete.
Design and implement safeguards protecting customer sites, accounts, and infrastructure from active and evolving threats.
Conduct vulnerability assessments, security reviews, and risk analysis, with remediation guidance engineers can act on.
Build automation and tooling that improves detection, monitoring, response, and operational safety.
Partner with Systems, Development, Abuse, and Support to get security controls implemented rather than merely recommended.
Mentor less experienced team members and contribute to the team's shared knowledge and runbooks.
Contribute to security policy, standards, and process, and support compliance efforts without mistaking compliance for security.
3–6 years in security engineering, incident response, application security, offensive security, or systems administration, with demonstrated ability to resolve complex security problems independently.
Depth in at least one of: application security, incident response and detection engineering, or offensive security and penetration testing plus working competence in the other two.
Strong hands-on Linux (Debian/Ubuntu preferred), including low-level concepts: processes, namespaces, capabilities, filesystems, kernels, and how things actually break.
Experience operating long-lived production systems that can't simply be rebuilt including repairing hosts in place, under load, with real users on them.
Experience in multi-tenant or customer-facing environments where users are untrusted.
Scripting and automation you've shipped and operated in production. Python, Go, Bash, Perl, or similar. We care that you've built and maintained real tooling, not which language.
Log analysis and investigation at scale, and comfort with intrusion detection and web application firewalls (mod_security or similar).
Working knowledge of cloud platform security (AWS, GCP, Azure, or OpenStack) including IAM, network controls, and workload isolation.
Familiarity with secrets management and CI/CD security (Vault or equivalent, pipeline hardening, dependency and supply-chain risk).
Version control and infrastructure-as-code fluency (Git, Ansible or similar).
Practical, current fluency with AI tooling in your own work. You use it daily, you know where it fails, and you can say what you don't let it do. We are not looking for enthusiasm or for resistance, but for someone who has integrated these tools into real engineering work and formed opinions from experience.
Clear written and verbal communication, including translating technical risk for non-technical stakeholders.
A strong sense of ethics, healthy skepticism, and the patience to stay useful under pressure.
Nice to have
Web hosting or WordPress-at-scale experience, as a provider or a customer.
Container and orchestration security (Podman, Docker, Kubernetes) including escape and isolation failure modes.
Malware analysis, YARA rule authorship, or reverse engineering.
Detection-as-code or SIEM engineering experience.
Hands-on experience securing AI/LLM systems, agent frameworks, or MCP tooling. Prompt injection, tool-permission scoping, or data-boundary work.
Familiarity with PCI DSS, SOC 2, or ISO 27001 — as context, not as a career.
Open source contributions.
Compensation
$125,000-$145,000 / yearly
**DreamHost provides equal employment opportunities to all team members and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.**
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.