Engineering

Security Engineer Job Description Template (Free, 2026)

Security engineers protect products, infrastructure, and data by thinking like attackers and building defensive systems at scale — attracting them requires a JD that demonstrates genuine security culture, not compliance checkbox thinking. Includes 2026 US salary benchmarks and ATS-optimized formatting.

Post in Treegarden

Copy-ready template

Job Title: Security Engineer [Mid-Level / Senior / Staff] Department: Engineering / Security Location: [City, State] / Remote / Hybrid Reports To: CISO / Head of Security / VP Engineering Employment Type: Full-Time About [Company Name] [Company Name] is a [stage/sector] company handling [describe sensitive data/scale, e.g., PII for X users, financial transactions, healthcare records]. Security is a core engineering discipline here, not an afterthought — we have active SOC 2 [Type I / Type II] certification, a [bug bounty / VDP program], and dedicated security engineering headcount. We are looking for a security engineer who thinks offensively to build better defenses. About the Role As a Security Engineer, you will own and improve the security posture of our product and infrastructure — spanning application security, cloud configuration, identity and access management, and incident detection. You will partner directly with product engineering teams to shift security left, conduct threat modeling and security reviews, and build tooling that scales security practices without becoming a bottleneck. Your work protects [X] customers and their data. Key Responsibilities • Conduct application security reviews, threat modeling, and penetration testing across web, API, and mobile surfaces • Build and maintain security tooling: SAST/DAST pipelines (Semgrep, Snyk, Burp Suite), secrets scanning, dependency auditing • Define and enforce cloud security standards across [AWS / GCP / Azure] using CSPM tools and policy-as-code (OPA, Checkov) • Manage identity and access: RBAC, IAM policies, SSO integration, privileged access management (PAM) • Operate and tune the SIEM/SOAR platform; develop detection rules and automated response playbooks • Lead incident response for security events: triage, containment, eradication, post-mortem • Collaborate with engineering and DevOps to integrate security gates into CI/CD pipelines (shift-left security) • Drive compliance deliverables for SOC 2, ISO 27001, or other applicable frameworks • Conduct security awareness training and support phishing simulation programs • Track and prioritize the vulnerability management backlog with engineering teams Required Qualifications • [3]+ years in security engineering, application security, or cloud security roles • Strong understanding of OWASP Top 10, common vulnerability classes, and secure coding principles • Hands-on experience with cloud security architecture and IAM (AWS IAM, GCP IAM, or Azure AD) • Experience with SAST, DAST, SCA, and secrets scanning tooling in CI/CD pipelines • Proficiency in at least one scripting language: Python, Go, or Bash for security automation • Familiarity with network security fundamentals, TLS/mTLS, zero-trust architecture • Experience supporting SOC 2, ISO 27001, PCI DSS, or HIPAA audit processes Nice to Have • Offensive security experience (OSCP, bug bounty, CTF participation) • Cloud security certifications (AWS Security Specialty, GCP Professional Security Engineer) • Experience with eBPF-based runtime security tools (Falco, Tetragon) • Knowledge of supply chain security (SBOM, SLSA, Sigstore) What We Offer • Competitive salary: $[low]–$[high]/year (see benchmarks below) • Equity: [X]% stock options / RSUs • Health, dental, and vision insurance (100% employer-paid for employee) • Flexible PTO + [X] company-wide holidays • Remote-friendly / home office stipend of $[X] • Conference attendance (DEF CON, Black Hat, BSides) budget • Learning & development budget: $[X]/year including certifications • [Additional perk — wellness stipend, etc.] Salary Range: $110,000–$190,000/year (US, 2026 benchmark; exact offer commensurate with experience) [Company Name] is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

How to customize this security engineer job description

1. Specify the security domain clearly

AppSec, CloudSec, DetEng, and GRC are distinct specializations. A JD that tries to cover all of them attracts no one well. Pick the primary domain, list secondary skills as nice-to-have, and be honest about the role's actual day-to-day focus.

2. Describe your compliance landscape honestly

State which frameworks you're actively maintaining and at what maturity. Top security engineers want to know whether they'll be building a program or operating an existing one. Overstating maturity leads to disappointment and early attrition.

3. Signal security culture at the leadership level

Experienced security engineers evaluate executive buy-in before accepting offers. Mentioning that the CISO reports to the CEO, that security has veto power on feature launches, or that the bug bounty is active signals that security is a first-class concern.

4. List certifications as nice-to-have, not required

Requiring CISSP or CISM as hard prerequisites filters out many excellent practitioners with deep hands-on skills but fewer certifications. Move certifications to "nice to have" and assess skills practically during the interview process instead.

Security Engineer salary benchmarks (US, 2026)

Level Experience Salary Range
Mid-Level 2–4 years $110,000 – $140,000
Senior 5–8 years $140,000 – $175,000
Staff / Lead 8–12 years $175,000 – $190,000
Principal / CISO 12+ years $190,000 – $280,000+

Source: Bureau of Labor Statistics, LinkedIn Salary, Glassdoor 2026 data. Ranges reflect US national median; adjust +20–30% for San Francisco/NYC markets.

Frequently asked questions

What should a security engineer job description include? +

A strong security engineer JD describes the security domain (AppSec, CloudSec, Detection & Response), compliance requirements, tooling (SAST/DAST, SIEM, CSPM), team structure, and a salary range. Mentioning your threat model, incident history, and bug bounty program signals security maturity.

What is the average security engineer salary in the US in 2026? +

Security engineer salaries range from $110,000 to $190,000+ depending on seniority and specialization. Mid-level engineers earn $110,000–$140,000, senior engineers $140,000–$175,000, and staff-level security engineers $175,000–$190,000. Specialized offensive security skills command 15–25% premiums above these ranges.

How do I write a security engineer job description that attracts top candidates? +

Be specific about your security maturity, compliance landscape, and tooling. Top security engineers evaluate whether leadership treats security as a first-class concern. Show that security has a budget, executive backing, and influence over product decisions. Avoid generic JDs that could apply to any company.

Can I use this template in my ATS? +

Yes. This template works in any ATS including Treegarden, Greenhouse, Lever, and Workable. In Treegarden, paste it into the job wizard to auto-format for your career page and publish to connected job boards with a single click.

Ready to post your first Security Engineer job?

Paste this template into Treegarden, set your pipeline, and publish to 10+ job boards in under 30 seconds.

Request a demo