xelys jobs xelys jobs

Senior Security Engineer (Infrastructure)

Instacart

full-remoteseniorpermanentsecuritybackend Full remote - New-York, US 29 days ago via WTTJ

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Cloud SecurityAWSGCPIdentity and Access Management (IAM)Infrastructure as CodeTerraformPolicy-as-CodeOPA RegoCSPMPython

About the role

Role Overview

Join Instacart’s CAPS team as a Senior Security Engineer (Infrastructure). You will secure cloud infrastructure, AI systems, and product surfaces by identifying critical risks, defining scalable remediation, and building secure-by-default primitives and internal security platforms.

Key Missions & Responsibilities

  • Identify and assess risks across Instacart’s:
    • Cloud accounts
    • Identity stack
    • AI/agent platforms
    • Product services
  • Define scalable remediation strategies and drive programs end-to-end: discovery → routing/ownership → fix → measurement → prevention.
  • Build secure-by-default primitives, such as:
    • Policy-as-code
    • Paved-road infrastructure modules
    • Identity & access frameworks
  • Lead investigations and incident work:
    • Root-cause analysis
    • Variant analysis to ensure bug classes are eliminated, not just individual instances
  • Operate security tooling/platforms (SaaS and internal), and run scan infrastructure across CI fleets.
  • Coach and mentor engineers across security and other functions.

Requirements

  • 5+ years in security engineering with depth in at least two areas:
    • Cloud security (AWS/GCP)
    • Identity & access engineering
    • Vulnerability management at scale
    • Secure infrastructure platform engineering
  • Threat model and SaaS architecture understanding
  • Proficiency in Python or TypeScript to build/maintain internal services (APIs, scanners, dashboards), not just scripts
  • 3+ years performing code reviews and design reviews
  • Hands-on Infrastructure-as-Code experience (e.g., Terraform or CloudFormation)
  • Experience with Variant Analysis, Root Cause Analysis, or secure frameworks
  • Working knowledge of cloud IAM (roles, trust policies, federation, SCPs/org policies)
  • Track record building security research, competitive hacking, or OSS contributions
  • Track record building internal security platforms engineers actually adopt (e.g., IAM attack-path analysis, vulnerability management, supply-chain/AMI pipelines, secrets management, GRC automation)
  • CSPM at scale (e.g., Wiz/Prisma or equivalent) including remediation programs across IaC findings and live threat findings (e.g., C2, credential abuse)

Nice-to-Haves / Additional Signals

  • Policy-as-code at org scope with OPA/Rego and/or Terraform Sentinel, including disciplined test coverage and rollout/grandfathering strategies
  • Experience securing AI/LLM platforms (model gateways, agent frameworks, MCP servers, prompt injection mitigations)
  • Identity governance experience with modern IGA stacks (e.g., ConductorOne, Sailpoint, Veza), including JIT access, auto-approval policies, and SoD constraints

About Instacart

Instacart is a technology company focused on helping people shop for groceries and other essentials. It operates large-scale platforms and services, and builds security capabilities to protect cloud infrastructure, identity systems, and emerging AI product surfaces.

Scraped 6/28/2026