Security Engineer
Summary
Senior hands-on security engineer defining and executing software security strategy at Elo, a touchscreen maker: hardening Android devices, AWS cloud, payment products, and the software supply chain. Day-to-day spans CI/CD security tooling (SAST/SCA), container and cloud security, AOSP platform hardening, and driving vulnerability remediation.
We know touch - it's our only business. In fact, we invented the touchscreen over 50 years ago and haven't stopped since. Every 21 seconds, a new Elo touch screen is installed somewhere in the world. We obsess over details to exceed the highest quality standards. We don’t just sell things. We offer solutions to tomorrow’s challenges.
Job Purpose & Responsibilities:
Elo is seeking an experienced Security Engineer to serve as a senior technical security leader within Software Engineering. This is a hands-on individual contributor role responsible for strengthening the security posture of Elo's Android devices, AWS cloud services, payment products, software development environments, and software supply chain.
You will define and execute security engineering strategy, establish technical controls and standards, drive vulnerability remediation, and partner closely with Software Engineering, Product Security, Enterprise Security, IT, Product Management, Quality, Compliance, and external partners.
The ideal candidate combines strong hands-on security engineering expertise with the ability to influence across teams and drive measurable security outcomes.
Key Responsibilities
- Define and execute the Software Engineering security strategy, roadmap, standards, and measurable objectives.
- Integrate and operate SAST, SCA, secrets detection, IaC scanning, and security gates within CI/CD pipelines.
- Drive software supply chain security, including dependency risk management, SBOMs, package governance, and AI-assisted development risks.
- Establish code signing and artifact integrity across Android applications, firmware, BSP images, containers, payment applications, and release artifacts.
- Strengthen AWS cloud security, including IAM, least privilege, MFA, encryption, network controls, logging, WAF, and security guardrails.
- Improve container security, including hardened base images, vulnerability management, registry controls, and lifecycle management.
- Lead Android/AOSP security activities, including CVE remediation, SELinux, Verified Boot, keystore/key attestation, and platform hardening.
- Own vulnerability management across device, cloud, and payment environments, including prioritization, remediation SLAs, and validation.
- Lead threat modeling, secure design reviews, penetration-test remediation, and security assessments.
- Support security requirements related to PCI, EU RED/EN 18031, EU CRA, ETSI EN 303 645, NIST, and OWASP.
- Develop security metrics and provide technical reporting on vulnerabilities, remediation, control coverage, exceptions, and security risk.
- Serve as a technical escalation point for release-blocking security findings and certification concerns.
- Represent Software Engineering in security governance, audits, customer security discussions, and third-party assessments.
- Provide security guidance, secure coding support, and technical coaching to engineering teams.
Minimum Qualifications
- Bachelor’s degree in computer science, Computer Engineering, Information Security, or a related technical field.
- 8+ years of experience in security engineering, software engineering, platform engineering, product security, or a related field.
- Hands-on experience integrating SAST/SCA and security tooling into CI/CD pipelines and driving remediation with development teams.
- Strong working knowledge of AWS security, including IAM, networking, encryption, logging, and cloud security posture management.
- Practical experience with Docker, Kubernetes, and container security.
- Ability to read and review code in at least two languages such as Java, Kotlin, C/C++, Python, Go, or Shell.
- Working knowledge of CVE/CVSS, vulnerability management, threat modeling, and secure software development.
- Understanding of cryptography, PKI, TLS, certificates, and key management.
- Demonstrated ability to influence and drive security outcomes across teams without direct authority.
Preferred Qualifications
- Experience implementing code signing across firmware, mobile, and container artifacts.
- Android/AOSP security experience, including SELinux, Verified Boot, keystore, BSP, or platform security.
- Experience with SBOM and software supply chain security, including SPDX/CycloneDX and tools such as JFrog Curation or Dependency-Track.
- Experience with security platforms such as Cycode, SonarQube, Fortify, Checkmarx, GitHub Advanced Security, Black Duck, Snyk, or Mend.
- Experience with hardened container images such as Chainguard.
- Knowledge of PCI-SSF, PCI-PTS, EU CRA, EU RED/EN 18031, ETSI EN 303 645, or IEC 62443.
- Familiarity with OWASP Top 10, OWASP Mobile Top 10, OWASP SAMM, and NIST secure development practices.
- Security certifications such as CISSP, CSSLP, OSCP, GIAC, or AWS Security Specialty.
- Experience working within an enterprise security governance model where enterprise teams establish security guardrails and business units drive implementation.
What Success Looks Like
In this role, you will help Elo move from reactive security remediation toward measurable, repeatable, engineering-driven security practices. Success includes stronger security controls, reduced vulnerability exposure, secure development pipelines, improved cloud and device security, reliable software supply chain controls, and demonstrable compliance with customer and regulatory requirements.
Physical Demands
- Ability to lift up to OSHA single person lift requirements
- Ability to sit, stand, bend, or walk for prolonged periods of time
- Ability to travel domestically and internationally
- Must be able to work a standard full-time schedule
- Must be able to work a hybrid schedule, in the Milpitas office on Tuesdays and Wednesdays
Elo Touch Solutions provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, Elo Touch Solutions complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Elo Touch Solutions expressly prohibits any form of workplace harassment based on race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. Improper interference with the ability of Elo Touch Solutions employees to perform their job duties may result in discipline up to and including discharge.
Elo Touch Solutions offers a competitive total compensation package. Benefits include Health, Dental, Vision, Life Insurance, Paid Vacation, 401K, Long and Short-Term Disability, and Tuition Reimbursement. Starting compensation for this role typically ranges between $130,400.00 and $179,000.00 annually is commensurate with experience relative to the position and may vary based on candidate geographical location.