Senior Security Engineer
TLDR
Strengthen security across cloud-native apps and Kubernetes, embedding security into the development lifecycle and influencing architecture to protect data and trust.
- Lead and continuously improve application security practices across the software development lifecycle, including secure design reviews, threat modeling, code reviews, and integration of automated security testing tools.
- Strengthen cloud and containerized environments by implementing and maintaining security controls across AWS, Kubernetes/EKS, identity and access management, network segmentation, workload security, and secrets management.
- Design, implement, and enhance service mesh security controls, including authentication, authorization, encryption, and secure service-to-service communication.
- Develop security guardrails and automation through policy-as-code frameworks, reusable templates, and developer-friendly self-service security tooling.
- Improve software supply chain security by establishing secure build and release processes, artifact validation, dependency visibility, image signing, and provenance controls.
- Drive vulnerability management initiatives, including risk assessment, prioritization, remediation coordination, and validation of security improvements.
- Implement and maintain technical security controls supporting compliance frameworks and data protection requirements, including access control, encryption, logging, monitoring, and audit readiness.
- Partner with engineering, platform, and operations teams to design, deploy, operate, and continuously improve security services and processes.
- Minimum 5 years of experience in security engineering, application security, cloud security, or software engineering with a strong focus on security.
- Strong expertise in application security, including threat modeling, secure code review, API security, and mitigation of common application and API vulnerabilities.
- Hands-on experience securing production environments running on AWS and Kubernetes/EKS.
- Practical experience implementing and managing security controls within service mesh environments such as Istio.
- Strong programming skills in Go or Python, with the ability to develop automation, tooling, and integrations.
- Experience securing CI/CD pipelines and working with Infrastructure as Code technologies, including Terraform, GitOps workflows, or similar platforms.
- Knowledge of Kubernetes security, networking, and policy enforcement tools such as Kyverno, OPA, or Cilium.
- Ability to translate security, privacy, and compliance requirements into effective technical solutions.
- Experience working within regulated environments governed by frameworks such as HIPAA, SOC 2, ISO 27001, or similar standards.
- Strong ownership mindset with the ability to independently drive projects from concept through operational maturity.
- Excellent written and verbal communication skills in English.
- Additional experience with supply chain security tools, penetration testing, offensive security practices, or bug bounty programs is considered an advantage.
- Competitive compensation package aligned with experience and expertise.
- Equity or stock option opportunities.
- Full equipment and technology setup provided.
- 21 days of annual leave in addition to public holidays.
- Fully remote work option for eligible candidates.
- Flexible and collaborative international work environment.
- Opportunity to work with modern cloud-native technologies and security tooling.
- Exposure to large-scale products used by millions of users worldwide.
- Career growth opportunities within a high-performing engineering organization.
Requirements
Benefits
Benefits
Equity Compensation
Equity or stock option opportunities.
Flexible Work Hours
Flexible and collaborative international work environment.
Home Office Stipend
Full equipment and technology setup provided.
Learning Budget
Career growth opportunities within a high-performing engineering organization.
Paid Time Off
21 days of annual leave in addition to public holidays.
Remote-Friendly
Fully remote work option for eligible candidates.
Stock Options
Equity or stock option opportunities.
Jobgether runs the largest remote job platform, effectively linking job seekers with over 200,000 flexible and remote opportunities that match their unique skills and preferences. Our focus is on enhancing the hiring process, ensuring efficiency while prioritizing the candidate experience, particularly in the growing health and wellness sector.
- Founded
- Founded 2020
- Employees
- 11-50 employees
- Industry
- Professional Services