The Impact of a Lead Security Engineer at Coupa
Coupa's Security Engineering team protects our enterprise, product, platform, and customer data at scale. As Lead Security Engineer, you will be a hands-on technical leader on the Security Engineering team — architecting and building cloud security controls, setting engineering standards, and partnering closely with Engineering, IT, and Compliance to ship durable, automated security tooling rather than one-off fixes. You thrive on ambiguity, sweat the implementation details, and take pride in solutions that scale across hundreds of accounts and services.
What You'll Do:
Architect and build multi cloud security controls across Coupa's cloud environment. VPC segmentation, security groups/NACLs, IAM policy design using least-privilege and permission boundaries, and Organizations/SCPs for guardrails at scale.
Build policy-as-code and IaC security guardrails and wire them into CI/CD as pre-merge and pre-deploy gates rather than after the fact reviews.
Harden containerized workloads - image scanning, admission control, pod security standards, and runtime detection.
Write auto-remediation for cloud misconfiguration and drift so common findings close without manual ticket routing.
Own Vulnerability management program, act as the technical escalation point for security incidents and vulnerability findings - leading forensics, containment, and root-cause analysis using cloud-native and EDR tooling, and driving remediation to closure.
Partner with Risk & Compliance to translate audit framework requirements (SOC 2, ISO 27001, PCI-DSS, FedRAMP) into concrete technical controls, and automate evidence collection by integrating cloud telemetry with GRC tooling.
Mentor other security engineers through design review, threat modeling, and code/architecture review; raise the technical bar for the whole team.
Own reference architectures, threat models, and runbooks for the security tooling you build; participate in and help improve the on-call rotation.
What You'll Bring to Coupa:
10+ years of security engineering experience, including significant hands-on work securing production cloud environments at scale, plus experience leading projects or mentoring other engineers.
Deep, hands-on AWS security expertise - IAM, VPC/networking, KMS, GuardDuty, Security Hub, Config, and Organizations/SCPs; working knowledge of GCP or Azure security is a plus.
Production experience with Terraform (or equivalent IaC) and policy-as-code frameworks, plus container/Kubernetes security tooling.
Strong software engineering fundamentals - Python and/or Go, Git-based workflows, and building/maintaining CI/CD security integrations (SAST, DAST, SCA).
Experience with SIEM/SOAR platforms and vulnerability management tooling (e.g., Wiz, Qualys, Tenable) - building detections and workflows, not just consuming dashboards.
Working knowledge of compliance frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP, NIST 800-53) sufficient to translate control requirements into engineering work.
Excellent written and verbal communication skills - able to write clear technical design docs and explain risk trade-offs to auditors and engineering leadership alike.
Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
Relevant certifications a plus: CISSP, CCSP, CISA, or AWS/GCP security certifications.
Some international travel may be required.