Security Engineer II (Cloud Security)
Remote
Full Time
#Information Security
#Cloud Security
#Azure Active Directory
#Python
#PowerShell
#SIEM
#IAM
#RBAC
#OAuth
#SAML
#MITRE
#Trust
At ShipBob, we are building the world’s leading full-stack fulfillment platform to empower ecommerce merchants with best-in-class supply chain capabilities. Our mission is to help businesses of all sizes deliver a delightful experience to their shoppers through our global network of fulfillment centers and proprietary technology. We are a high-performance team backed by top-tier investors, and we believe that innovation happens when we foster an ownership mindset, maintain transparency, and support one another in solving complex, real-world problems.
The role
We are looking for a Senior Security Engineer II to join our team on a full-time basis. This is a remote position based in India, requiring availability during US hours from 7 pm to 4 am IST. In this role, you will be a key contributor to our Information Security, Governance, Risk, and Compliance programs, reporting directly to the Vice President of Information Tech and Security. We are seeking someone who is ready to take ownership, push technical boundaries, and grow alongside a team that values high standards and mutual respect.
Core responsibilities
- Monitor and investigate security alerts, tune detection systems like Sentinel and Defender XDR, and proactively execute threat hunting campaigns to identify anomalies.
- Manage identity security initiatives, including conditional access, multi-factor authentication, and role-based access control, while ensuring compliance with frameworks like SOC 2, ISO 27001, and NIST.
- Develop and automate security workflows, playbooks, and tools to improve the efficiency of our security operations and provide expert guidance to engineering teams during vulnerability remediation.
Skills and experience
To be successful in this role, you should possess the following qualifications:
- At least 4 years of hands-on experience in security architecture and engineering within a cybersecurity operations environment.
- At least 2 years of specific experience in incident response, threat intelligence, or access control engineering.
- Deep technical knowledge of Azure services, including Azure Active Directory, Identity Protection, and RBAC.
- Proficiency in scripting languages such as Python or PowerShell.
- Strong familiarity with industry frameworks like MITRE ATT&CK, OAuth, and SAML.
- Excellent analytical skills and the ability to communicate complex risks to diverse stakeholders.
- Relevant certifications such as CISSP, Security+, or GCIH are preferred but not required if you have equivalent professional experience.
Compensation and benefits
We provide a comprehensive benefits package designed to support your well-being and professional life, including:
- Medical, term, and accidental insurance coverage.
- Generous maternity and paternity leave policies.
- Paid time off, including 12 days of all-purpose leave, 15 days of earned leave, and 12 public holidays.
- A dedicated quarterly wellness day.
- A remote work allowance to support your home office setup.
How to apply
We recognize that talent comes from many backgrounds, and we encourage you to apply even if your experience does not perfectly align with every listed requirement. If you are passionate about building secure, scalable systems and want to be part of a fast-growing, mission-driven team, we would love to hear from you. Please submit your application to be considered for this role, as we review candidates on an ongoing basis.





