Senior Security Engineer (Infrastructure)
Instacart
full-remoteseniorpermanentsecuritybackend Full remote - New-York, US 29 days ago via WTTJ
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
Cloud SecurityAWSGCPIdentity and Access Management (IAM)Infrastructure as CodeTerraformPolicy-as-CodeOPA RegoCSPMPython
About the role
Role Overview
Join Instacart’s CAPS team as a Senior Security Engineer (Infrastructure). You will secure cloud infrastructure, AI systems, and product surfaces by identifying critical risks, defining scalable remediation, and building secure-by-default primitives and internal security platforms.
Key Missions & Responsibilities
- Identify and assess risks across Instacart’s:
- Cloud accounts
- Identity stack
- AI/agent platforms
- Product services
- Define scalable remediation strategies and drive programs end-to-end: discovery → routing/ownership → fix → measurement → prevention.
- Build secure-by-default primitives, such as:
- Policy-as-code
- Paved-road infrastructure modules
- Identity & access frameworks
- Lead investigations and incident work:
- Root-cause analysis
- Variant analysis to ensure bug classes are eliminated, not just individual instances
- Operate security tooling/platforms (SaaS and internal), and run scan infrastructure across CI fleets.
- Coach and mentor engineers across security and other functions.
Requirements
- 5+ years in security engineering with depth in at least two areas:
- Cloud security (AWS/GCP)
- Identity & access engineering
- Vulnerability management at scale
- Secure infrastructure platform engineering
- Threat model and SaaS architecture understanding
- Proficiency in Python or TypeScript to build/maintain internal services (APIs, scanners, dashboards), not just scripts
- 3+ years performing code reviews and design reviews
- Hands-on Infrastructure-as-Code experience (e.g., Terraform or CloudFormation)
- Experience with Variant Analysis, Root Cause Analysis, or secure frameworks
- Working knowledge of cloud IAM (roles, trust policies, federation, SCPs/org policies)
- Track record building security research, competitive hacking, or OSS contributions
- Track record building internal security platforms engineers actually adopt (e.g., IAM attack-path analysis, vulnerability management, supply-chain/AMI pipelines, secrets management, GRC automation)
- CSPM at scale (e.g., Wiz/Prisma or equivalent) including remediation programs across IaC findings and live threat findings (e.g., C2, credential abuse)
Nice-to-Haves / Additional Signals
- Policy-as-code at org scope with OPA/Rego and/or Terraform Sentinel, including disciplined test coverage and rollout/grandfathering strategies
- Experience securing AI/LLM platforms (model gateways, agent frameworks, MCP servers, prompt injection mitigations)
- Identity governance experience with modern IGA stacks (e.g., ConductorOne, Sailpoint, Veza), including JIT access, auto-approval policies, and SoD constraints
About Instacart
Instacart is a technology company focused on helping people shop for groceries and other essentials. It operates large-scale platforms and services, and builds security capabilities to protect cloud infrastructure, identity systems, and emerging AI product surfaces.
Scraped 6/28/2026