1. What is a Security Engineer?
At Lyft, the Security Engineer role is fundamentally different from traditional security analyst or compliance roles found at other enterprises. Here, you are first and foremost an engineer. You are expected to build the "paved road" that makes it easy for thousands of developers to ship secure code by default.
This position sits at the intersection of infrastructure, software engineering, and security operations. You aren't just running scans or acting as a gatekeeper; you are designing and building the security architecture that protects Lyft’s massive, real-time transportation network. This includes working on critical components like Internet edge proxies (Envoy), Web Application Firewalls (WAF), and service-to-service authentication.
Your impact is high-leverage. A single tool or service you build—such as a centralized credential management service—will be used by every engineering team at Lyft. You will ensure that as Lyft scales its distributed systems across AWS and Kubernetes, security scales with it through automation rather than friction.