Base Career helps you apply smarter for this job.
Key skills for this role
Own design and hardening of security infrastructure across cloud environments — network segmentation, firewalls, IDS/IPS, VPNs, WAF, and endpoint detection and response (EDR)
Lead vulnerability management end to end: run assessments and authenticated scans, triage and prioritize by exploitability and blast radius, and drive remediation SLAs with engineering
Build and tune detection content (SIEM/SOAR rules, alerting logic) against real attack techniques — not just default vendor signatures
Act as incident commander for security incidents: contain, eradicate, run forensics, and write the post-incident review
Threat-model new features and infrastructure changes before they ship — catch design-level risk, not just implementation bugs
Own IAM hygiene and cloud security posture (least privilege, key/secret management, network boundaries) across production AWS accounts
Write, enforce, and maintain security policies and standards — own them as living controls, not documents that sit in a drive
Own Roofr's compliance program end to end: map controls to NIST CSF 2.0, SOC 2, and CCPA/CPRA, run the audits, close the gaps, and keep evidence current between them
Run tabletop exercises and incident playbook drills
Push secure-by-design practices into engineering workflows — threat modeling in design review, security requirements in the SDLC, not a gate bolted on at the end
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, CAN
Roofr is hiring a Senior People Operations Specialist for a 12-month contract to support employee lifecycle programs across onboarding, engagement, performance, benefits, HR systems, and international employment. Candida
North Salt Lake, USA
, CAN
, CAN
Brazil, USA
, CAN
, CAN
Deep network security fundamentals — firewalls, VPNs, routing/segmentation, network boundaries, TLS, DNS, and how attackers actually abuse them
Hands-on cloud security in AWS — IAM policy design, VPC architecture, KMS/secrets management, CloudTrail/GuardDuty or equivalent
Real incident response experience — triage, containment, forensics, root cause, not just theory from a course
Working knowledge of SIEM/SOAR tooling, writing detection logic (Python/Bash), and building your own tooling when nothing off-the-shelf fits
Fluent in compliance frameworks — NIST CSF 2.0, SOC 2, and CCPA/CPRA — and translating controls into policy people actually follow
Strong software engineer at heart — comfortable reading and writing real application code, not just scripts, so you can dig into the codebase directly instead of filing a ticket and waiting
Confident being the only security voice in the room — makes the call and owns it
Translates technical risk into business terms leadership can actually act on
Calm and decisive under incident pressure; documents as they go, not after
Ownership-oriented; builds the process that doesn't exist yet instead of waiting for one
Strong individual contributor who wants to stay hands-on — this role builds the foundation directly, it doesn't lead from the side
Experience using AI/LLM tooling for threat intelligence — alert triage, detection summarization, or hunting workflows — not required, but a plus for a team building modern security practice from scratch
Familiarity with GDPR — a plus as Roofr's customer base grows internationally
Experience with PHP/Laravel — a plus for digging into Roofr's own codebase directly, not required
Comfortable around Postgres — helpful, not required
Our compensation ranges are built using multiple market benchmarks and reflect both the scope of the role and current market data. While many hires fall within the beginning to midpoint of the band to allow for growth over time, we tailor offers based on each candidate’s experience, seniority, and demonstrated impact.
🏠 What we offer (US + Canada)
When you join our team, you’re not just accepting a job. You’re making a career move. Here’s how we’ll support you in doing some of the most impactful work of your career:
🏝️ Vacation/Paid Time Off:
1st week of employment is mandatory PTO! Start your journey with Roofr by decompressing and recharging - we will see you in week 2!
1 Friday off per month (we call those our laundry days!)
Company wide paid shutdown for the week between Christmas and New Years
Flexible time off
80% employer-paid benefits in the U.S. and 100% employer-paid premiums for Extended Healthcare and Dental in Canada
RRSP/401k match
Generous Parental Leave policy
All-in-one roofing software platform with CRM, instant estimates, proposals, measurements, payments, and material ordering designed specifically for roofing contractors.
Visit company websiteJobs and hiring trendsSenior · 8+ years experience
Remote
Apply faster on company sites with our extension.