Senior Staff Security Engineer
Gusto is a payroll and HR platform that helps small businesses pay domestic and international employees, manage benefits, and automate compliance.
Maintainer signals as of 8/12/2026
Projects
About Gusto
Gusto serves small and mid-sized businesses with payroll processing, employee benefits administration, and HR tools in one platform. Users can run payroll, manage health insurance, hire globally, and pay international contractors in local currency or USDC stablecoins. The platform automates payroll tax filings across multiple states and integrates with tools like QuickBooks and Xero.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will lead edge and network security strategy, operate Cloudflare and AWS perimeter controls, codify security policies, build detections and alerting, respond to incidents, and develop AI-assisted security automations and agents.
Requirements
- 10+ years of hands-on security engineering experience
- Experience owning edge, network, or perimeter security at scale
- Production-grade expertise with Cloudflare WAF, DDoS, Bot Management, WARP, Gateway, and Access
- Network architecture expertise across edge and cloud
- Knowledge of TLS, mTLS, segmentation, egress controls, and DDoS resilience
- AWS networking experience with VPC, Network Firewall, Shield, CloudFront, and NACLs
- Fluency with policy-as-code, Terraform, and CI/CD security delivery
- Crossplane or similar experience is a plus
- Experience with cloud security, IAM, container security, and detection engineering
- Hands-on incident response experience
- Daily use of agentic tooling such as Claude Code
- Experience building MCP servers, agents, and LLM automations
- Excellent written and verbal communication
- Relevant security certifications are a plus
Responsibilities
- Design and operate the Cloudflare edge security stack
- Own the AWS and edge network security perimeter
- Develop policy-as-code patterns for WAF rules, network policies, and edge configuration
- Build detections and alerting on edge and network telemetry
- Lead incident response for perimeter and network events
- Contribute to cloud posture, container security, IAM, vulnerability management, and on-call activities
- Use AI-native tools for investigation, automation, and detection engineering
- Prototype and ship agents, MCP servers, and LLM-assisted automations
Benefits
- Equity in the form of stock
- Hybrid work option
