Security Engineer (L5) - Workforce Security

Netflix

Remote Actively hiring Verified listing
Remote, USA Posted 9 days ago $400,000$680,000 / year

At a glance

AI generated

TL;DR

As a Senior Security Engineer specializing in Endpoint Security at Netflix's Workforce Security team, you will play a pivotal role in identifying and managing risks across all software on Netflix endpoints by developing scalable technical security controls that enhance business agility while reducing risk. Your day-to-day responsibilities include designing and implementing protective endpoint security measures such as host hardening, vulnerability identification, and effective patch management for Mac, Windows, and Linux systems. You will also evaluate the build versus buy options for security capabilities, gather requirements, conduct cost-benefit analyses, and estimate development efforts accurately. Additionally, you must possess knowledge of commercially available endpoint MDM solutions like Jamf or Intune, experience with vulnerability scanning tools such as CrowdStrike, and strong scripting skills to validate publicly disclosed exploits. This role demands excellent communication and risk translation abilities to articulate complex technical risks in clear business terms for stakeholders, ensuring informed decision-making.

Skills

Jamf Kandji Intune CrowdStrike Tenable MacOS Windows Linux Vulnerability Management Threat Modeling Scripting Endpoint Security MDM Solutions Patch Management Host Hardening CI/CD

What you'll do

  • Design and implement protective endpoint security controls for Mac, Windows, and Linux systems.
  • Develop and execute a comprehensive Patch and Vulnerability Management Strategy to prioritize remediation efforts.
  • Evaluate build vs. buy decisions for security capabilities through requirement gathering and cost-benefit analysis.
  • Translate complex technical risks into clear business risks for stakeholders to inform decision-making.
  • Provide operational support for Workforce Security, including participation in 24/7 Incident Response as needed.
  • Design and test host hardening configurations to maintain defined security standards across devices.

What we're looking for

  • Experience designing and testing host hardening configurations for Mac, Windows, and Linux systems.
  • Knowledge of endpoint MDM solutions like Jamf, Kandji, or Intune and vulnerability scanning tools such as CrowdStrike, Tenable.
  • Understanding of Vulnerability Management practices and ability to validate publicly disclosed exploits.
  • Scripting skills with the use of GenAI sufficient for production-level work.
  • Strong cross-functional collaboration and communication skills to translate technical risks into business terms.
  • Ability to autonomously drive work delivery and manage open-ended problems from concept to product.

Market check

Salary context

This $400,000–$680,000 range sits above 100% of similar postings on FindRole.

Peer median band

$113,400$206,845

Median floor and ceiling across peers.

Typical midpoint (25–75%)

$142,400$185,000

Middle half of comparable postings.

Based on 240 comparable postings.

* 240 is the maximum number of comparable postings sampled.

Employer

About Netflix

Netflix is the world''s leading streaming entertainment service, offering a vast library of TV series, films, documentaries, and original content to subscribers in over 190 countries. Industry: Streaming Entertainment & Media

Netflix currently has 91 open roles on FindRole.

Listed pay typically runs $388,000–$610,000 across 87 roles with salary data.

Most-posted roles

View all roles at Netflix

More like this

Similar roles

Security Engineer (Compliance)

Berkeley Research Group

Remote (US) 107 days ago $125,000$170,000
SOC 2 ISO 27001 CSA STAR NIST CSF Microsoft Azure Amazon Web Services firewalls intrusion detection systems anti-virus software authentication systems log management Web applications Service Oriented Architectures CI/CD
Remote

Security Systems Engineer

Booz Allen Hamilton

Locations Atlanta, Georgia, US 11 days ago $69,300$158,000
Armis Elastic Stack Bash Perl JavaScript Python CI/CD Kubernetes Docker AWS Azure Google Cloud Platform Terraform Ansible PostgreSQL MongoDB Redis Git Jenkins Prometheus Grafana Splunk SIEM Nmap Wireshark

Security Engineer II

Endeavor Health

Nso 4901 Searle Parkway Corporate Office Skokie, US 49 days ago
HIPAA NIST PCI Kubernetes AWS Terraform Python SQL PostgreSQL Docker CI/CD Git Splunk SIEM CyberArk RSA Archer CISCO ASA Check Point RADAR Qualys Microsoft 365 Cisco Umbrella

Security Engineer

Adobe

Seattle, US 54 days ago $180,600$261,450
Entra ID AD Okta SailPoint Zero Trust RBAC ABAC M365 Slack GitHub Workday Google Python PowerShell Terraform Teleport Vault SPIFFE SPIRE CI/CD

Security Engineer

Leidos

9615 Ashburn Va Non-Specific Customer Site, US 25 days ago $69,550$125,725
AWS Linux Python Ansible Networking VPN DNS DHCP VPCs Firewalls Splunk EC2 S3 Lambda Storage Gateways CentOS RHEL Kali Linux Rocky Linux Windows McAfee CrowdStrike CI/CD

Security Engineer

Booz Allen Hamilton

Locations Annapolis Junction, Maryland, US 16 days ago $112,800$257,000
Elasticsearch Kibana Logstash Beats Fleet ES QL EQL Elastic Security SOAR n8n XSOAR Elastic transforms runtime fields RAG architectures vector search Python scikit-learn PyTorch AI/ML concepts