Salt Security is the original API Security vendor pioneering the market as the first vendor in 2018. Since then we have exhibited hyper-growth in a number of customers, threats stopped, and revenue. We saw API security as the security battleground of the future years ago as APIs started to form the foundation of the application innovation needed to drive business success today. Across banks, retail and transportation, IoT, autonomous vehicles, and smart cities, every modern app depends on APIs. Attackers realize APIs are the conduits to all sorts of valuable data and services – within the year, APIs are predicted to be the number one application threat vector. Without secure APIs, businesses cannot rapidly innovate. Salt Security has delivered the only patented solution to discover all APIs and their exposed data, stop API attackers, and provide remediation details for dev teams to write more secure APIs.
At Salt, we’re passionate about what we do. We work as a team and embrace new ideas, wherever they come from. We also enjoy all the benefits of a startup environment, including quickly seeing the results of your work, making an outsized impact on our company, and solving diverse challenges.
Want to make a big difference? We encourage you to apply!
We are looking for a Security Engineer with 1-2 years of experience to join our Internal Security team.
This role combines hands-on cloud and security operations with support for GRC and compliance activities.
You will be involved in securing our cloud, SaaS, and AI-driven systems, monitoring security events, and helping maintain our overall security posture. In parallel, you will support customer security questionnaires and compliance processes.
What you'll do
Monitor, triage, and investigate security alerts and incidents across cloud and security tools (EDR, CASB, ZTNA, SaaS security platforms, and identity providers), and support response and remediation activities
Assist in securing cloud environments (AWS/GCP/Azure), including IAM, access controls, network security, and CI/CD pipeline security
Work closely with DevOps and IT teams to implement and enforce security best practices across infrastructure, endpoints, and SaaS systems
Support vulnerability management processes, including scanning, prioritization, and remediation tracking
Support risk management processes by identifying, assessing, and tracking risks, including vulnerability management, remediation efforts, and control gaps
Support customer security questionnaires (RFPs/RFIs) with accurate technical responses
Assist in maintaining compliance with frameworks such as SOC 2 and ISO 27001, including preparing audit evidence and documentation
Who You Are?
1-2 years of experience in cybersecurity, cloud security, and security operations
Basic hands-on experience with cloud platforms (AWS, GCP, or Azure)
Understanding of core security concepts: IAM, networking, least privilege, and secure configurations
Experience or strong interest in collaborating with DevOps and IT teams, alongside a focus on AI security, data protection, and emerging technologies
Familiarity with security tools such as EDR, vulnerability scanners, or SaaS security solutions
Strong analytical and troubleshooting skills, with high attention to detail and the ability to manage multiple tasks
Good communication skills and ability to work cross-functionally
Willingness to learn and grow in both technical security and GRC domains
Nice to have
Experience with cloud security best practices and securing CI/CD pipelines and infrastructure-as-code (Terraform, etc.)
Familiarity with identity systems (Okta, Azure AD, etc.)
Familiarity with compliance frameworks such as SOC 2, ISO 27001, or NIST