Senior Security Engineer
Rate is one of the nation’s top retail mortgage lenders, delivering a seamless, tech-driven experience that helps customers reach their homeownership and financial goals. Founded in 2000 and based in Chicago, Rate is licensed in all 50 states and D.C. and has helped over 2 million homeowners with a wide range of loan products, competitive rates and personalized service. With 5,000+ employees across 300+ offices and 12+ subsidiaries, Rate’s Loan Officers rank among the best in the country. From purchases and refinances to tapping into equity, Rate makes financing faster, simpler and less stressful. Our technology — including Same Day Mortgage, the Rate App, FlashClose℠, MyAccount and the Language Access Program — has earned recognition from HousingWire, Scotsman Guide, NerdWallet, the Chicago Tribune and Crain’s Chicago Business. Learn more at rate.com.
Job Profile:
Security EngineerJob Description Summary:
We are committed to providing a competitive and equitable total rewards package. The compensation for this role is designed to attract, retain, and motivate top talent.The expected base salary range for this position is $160,000 to $180,000 annually
Job Description:
Why Rate is the BEST Place to Work
Rate is one of the nation’s top retail mortgage lenders, delivering a seamless, tech-driven experience that helps customers reach their homeownership and financial goals. Founded in 2000 and based in Chicago, Rate is licensed in all 50 states and D.C. and has helped over 2 million homeowners with a wide range of loan products, competitive rates and personalized service. With 5,000+ employees across 300+ offices and 12+ subsidiaries, Rate’s Loan Officers rank among the best in the country. From purchases and refinances to tapping into equity, Rate makes financing faster, simpler and less stressful. Our technology — including Same Day Mortgage, the Rate App, FlashClose℠, MyAccount and the Language Access Program — has earned recognition from HousingWire, Scotsman Guide, NerdWallet, the Chicago Tribune and Crain’s Chicago Business. Learn more at rate.com.
What Makes Our Team Awesome
We are a gritty group of passionate technologists on a mission to dominate the mortgage world!
The Information Technology Team within Rate passionately and consistently puts our customers first. We are building the latest technology to help create the best mortgage experience on the planet and get your mortgage, your way, anytime, anywhere. Whether that is improving our digital mortgage platform, automating loan coordination and underwriting processes, or building out the latest marketing and customer engagement platform, we’re doing it all. We build high-performing, self-organized, cross-functional agile teams that operate with minimal hierarchy. Information Technology team members hold themselves and others accountable and live and breathe the tenets of autonomy, mastery, and purpose.
What’s the Role?
We are seeking a Security Engineer with a primary focus on cloud security and infrastructure. This generalist security role will be responsible for developing, architecting, and deploying security solutions across multiple technology domains including cloud infrastructure, network security, endpoint detection and response (EDR), data loss protection (DLP), and container environments. The Security Engineer will report to the Security Director and be a key member of the larger security engineering team, collaborating with other security engineers and application security engineers to solve objectives both independently and together. The role requires subject matter expertise in cloud security while maintaining a broad understanding of enterprise security technologies and the ability to work autonomously as well as within a team environment.
Responsibilities:
- Take ownership of security projects and initiatives from objective to completion; work independently and with minimal oversight to identify problems, evaluate solutions, and implement fixes.
- Self-manage workload and priorities; track work in sprints, articulate progress and blockers, and provide clear written and oral communication of detailed steps needed to accomplish security objectives.
- Collaborate with other security engineers and application security engineers to solve complex security challenges; contribute to team initiatives while maintaining autonomous responsibility for assigned projects.
- Design, architect, and implement secure infrastructure and security controls across multiple technology domains with emphasis on cloud deployments.
- Develop and deploy Infrastructure as Code using Terraform to provision and manage secure cloud environments while maintaining security posture.
- Proactively identify security gaps and deficiencies in existing security designs, propose plans for improvement and implementation across all security domains.
- Lead vendor evaluation, selection, and engagement for security tools and platforms; manage vendor relationships and coordinate implementations.
- Provide subject matter expertise in cloud security while maintaining competency across network security, EDR, DLP, SIEM, and other security technologies depending on organizational needs.
- Manage security logging infrastructure; identify critical log sources, configure SIEM to capture essential security events, troubleshoot logging issues, and provide recommendations for log architecture and retention.
- Develop and maintain security policies, standards, procedures, and documentation to ensure consistency and compliance across the organization.
- Lead the evaluation, deployment, and management of security tools and platforms across cloud and on-premises environments.
- Collaborate with DevOps, infrastructure, development, and business teams to identify security needs, propose solutions, and integrate security controls into Infrastructure as Code, CI/CD pipelines, and deployments.
- Monitor and respond to security incidents and alerts; use SIEM and logging infrastructure to investigate and remediate threats and vulnerabilities across all security domains within defined SLAs.
- Manage identity and access controls across platforms; ensure implementation of least privilege, RBAC principles, and security best practices.
- Maintain knowledge of current security trends, emerging threats, and best practices across multiple technology domains; communicate findings to management and stakeholders.
- Assist other security team members with broader security initiatives, providing cross-training and subject matter expertise.
Qualifications:
- 5+ years' experience in security engineering with emphasis on infrastructure security, cloud security, or equivalent combination of roles solving security problems in large-scale systems.
- Self-Direction, Workload Management & Communication
- Demonstrated ability to self-task and work independently to identify, analyze, and solve complex security problems with minimal oversight; comfort taking ownership of projects from objective to completion.
- Ability to self-manage workload and priorities; comfort tracking work in sprint-based environments and providing regular updates on progress, blockers, and completion status.
- Strong written and oral communication skills with ability to document and clearly articulate detailed steps, plans, and requirements needed to accomplish security objectives.
- Experience working with vendors; ability to evaluate, select, and manage vendor solutions for security tools and platforms.
Cloud Security & Infrastructure
- Proficiency with Infrastructure as Code, specifically Terraform, for deploying and managing infrastructure with security considerations.
- Proficiency with at least one major cloud platform (AWS, Azure, or GCP) and understanding of multi-cloud security considerations.
- Experience designing and securing containerized environments and Kubernetes clusters in production.
- Demonstrated experience with cloud network architecture, VPCs, security groups, firewalls, and network segmentation.
- Cloud security posture management and experience implementing security controls and compliance frameworks (SOC 2, PCI-DSS, NIST, or CIS).
Logging & Security Monitoring
- Hands-on experience with Security Information and Event Management (SIEM) and next-generation SIEM technologies; comfort with log searching, filtering, and analysis.
- Demonstrated ability to troubleshoot logging infrastructure, identify critical log sources for security investigations, and provide recommendations for log retention and architecture.
Network & Endpoint Security
- Strong understanding of network protocols, routing, firewalls, VLANs, and VPN technologies.
- Hands-on experience with Endpoint Detection and Response (EDR) tools and strategies, including threat detection and incident response.
- Hands-on experience implementing and managing Data Loss Prevention (DLP) solutions and policies.
Application Security & Development Support
- Experience supporting application security initiatives and collaborating with development and AppSec teams.
- Familiarity with agile development processes and experience integrating security practices and guardrails into DevOps and CI/CD workflows.
General Security & Professional Skills
- Experience with identity and access management (IAM), directory services, and role-based access control.
- Proficiency in at least one scripting language (Python, Bash, PowerShell, or equivalent) for automation and tooling.
- Strong interpersonal and communication skills with ability to effectively influence stakeholders and work across technical and non-technical teams.
- Excellent ability to communicate complex technical information to diverse audiences in clear, authoritative, and actionable terms.
Preferred Experience:
Cloud Security & Infrastructure
- Designing, implementing, and maintaining cloud infrastructure security in large-scale, multi-cloud environments (AWS, Azure, GCP, or equivalent).
- Proficiency with Infrastructure as Code (IaC), specifically Terraform, for deploying and managing secure cloud infrastructure.
- Cloud security fundamentals including identity and access management (IAM), network segmentation, encryption, and data protection across cloud platforms.
- Building and securing containerized environments including Kubernetes, Docker, container registries, and orchestration platforms.
- Cloud security posture management and compliance frameworks including industry standards such as NIST and CIS benchmarks.
- Implementing and managing cloud security tools and services such as cloud access security brokers (CASB) and cloud workload protection platforms (CWPP).
- BONUS: Experience with third-party Cloud Security Posture Management (CSPM) tools such as Wiz, Lacework, or equivalent.
Logging & Security Monitoring
- Experience with Security Information and Event Management (SIEM) and next-generation SIEM (SIEM+) technologies; comfort with log searching, filtering, and analysis.
- Ability to troubleshoot logging infrastructure issues, identify critical log sources for security investigations, and provide recommendations for log retention and architecture.
- System monitoring and security alerting; ability to correlate logs and events across multiple platforms to identify and remediate threats.
Network & Endpoint Security
- Network security architecture and implementation including VLANs, VPNs, firewalls, network segmentation, and routing protocols.
- Endpoint Detection and Response (EDR) tools and strategies, including threat detection, incident response, and endpoint hardening.
- Data Loss Prevention (DLP) solutions and strategies, including implementation of DLP policies, monitoring, and compliance controls.
Application Security & Development Support
- Supporting application security initiatives; experience collaborating with application security teams on CI/CD pipeline security and secure development practices.
- Implementing security guardrails and policies within cloud environments to support development and deployment workflows.
- Integrating security controls into Infrastructure as Code and deployment automation to enforce security posture.
General Security & Professional Skills
- Identity and access management fundamentals including SSO, MFA, RBAC (Role Based Access Control), and principle of least privilege.
- Understanding of industry standards and compliance frameworks such as NIST, CIS, and PCI-DSS.
- Intermediate scripting and automation skills using Python, Bash, PowerShell, or equivalent for security automation and infrastructure deployment.
- Self-directed work style with ability to take ownership of projects and initiatives from objective to completion with minimal oversight.
- Experience working independently to identify, evaluate, and implement solutions to complex security problems; comfort with vendor evaluation and selection.
Other Useful Details
Employee Type: Full-Time
Pay Range: annual pay + bonus and/or commissions
Location: Remote
Rate Companies is an Equal Opportunity Employer that welcomes and encourages all applicants to apply regardless of age, race, sex, religion, color, national origin, disability, veteran status, sexual orientation, gender identity and/or expression, marital or parental status, ancestry, citizenship status, pregnancy or other any other protected characteristic. #LI-Remote
The company offers a comprehensive benefits program to eligible employees, including eligibility to participate in a company-sponsored 401(k); vacation benefits; eligibility for medical, dental, vision, and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; critical care insurance; personal accidental insurance; commuter benefits; pet insurance; certain time off and leave of absence benefits; well-being benefits (e.g., employee assistance program); and other supplemental benefits (e.g. legal planning assistance; identity theft protection; pet insurance; wellness resources).
Please click this link to learn more about our benefit offerings for Washington State:
Additional Job Description Summary:
Rate is an Equal Opportunity Employer that welcomes and encourages all applicants to apply regardless of age, race, sex, religion, color, national origin, disability, veteran status, sexual orientation, gender identity and/or expression, marital or parental status, ancestry, citizenship status, pregnancy or other reason protected by law.
The company offers a comprehensive benefits program to eligible employees, including eligibility to participate in a company-sponsored 401(k); vacation benefits; eligibility for medical, dental, vision, and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; critical care insurance; personal accidental insurance; commuter benefits; pet insurance; certain time off and leave of absence benefits; well-being benefits (e.g., employee assistance program); and other supplemental benefits (e.g. legal planning assistance; identity theft protection; pet insurance; wellness resources).
Please click this link to learn more about our benefit offerings for Washington State: Benefit Offerings for Washington State
Required Skills
Required Languages
🇬🇧 English