Job Summary
DreamHost is hiring a Security Engineer II to protect its infrastructure, customers, and large multi-tenant Linux hosting environment. This is a hands-on security engineering role focused on incident response, threat detection, application security, vulnerability management, automation, and reducing security risks across shared hosting, VPS, managed WordPress, dedicated servers, cloud, and email platforms.
The engineer will investigate complex security incidents, determine affected systems, contain threats, preserve evidence, and document findings. Responsibilities also include developing malware and webshell detections, log-based alerts, vulnerability assessments, security reviews, and application security controls for DreamHost’s internal and customer-facing systems.
A major part of the role involves modernizing security operations through automation and improved infrastructure controls. The engineer will work on secrets management, identity and access lifecycle, CI/CD security, vulnerability remediation, cloud security, infrastructure as code, and security governance for AI and agent-based tools.
Experience with Python, Go, Bash, Perl, log analysis, intrusion detection, web application firewalls, AWS/GCP/Azure/OpenStack security, Vault, Git, and Ansible is valuable. Experience with multi-tenant environments and production systems that require in-place maintenance is particularly relevant.
DreamHost offers benefits including family health, vision, and dental coverage at no employee cost, 401(k) contributions and matching, profit-sharing opportunities, paid time off, paid holidays, tuition reimbursement, pet insurance, wellness benefits, disability insurance, parental leave, and professional learning opportunities.
The listed compensation for the position is $125,000–$145,000 per year.
Note: This is a short summary of the job for the ease of users. Please click the Apply Now button to view the complete job description and all official details.
Disclaimer: We are human and may occasionally make mistakes. If you notice any harmful, sensitive, inaccurate, or inappropriate information, please contact us so we can review and address it.















