Remote job
Senior Security Engineer
Job details
About this role
Role overview A remote-first opportunity for an experienced security professional to own the full security posture of an open-source orchestration platform and its cloud SaaS counterpart. The position blends offensive and defensive work: actively probing systems for weaknesses, hardening infrastructure, and patching issues directly through code contributions. It suits someone who enjoys moving between threat modeling, hands-on exploitation, and remediation in a fast-moving open-source environment.
Responsibilities - Conduct penetration testing and structured threat modeling across the web application, APIs, control plane, and cloud environments. - Track and remediate vulnerabilities spanning source code, third-party dependencies, container images, and cloud configuration. - Write and submit patches or pull requests, or collaborate closely with product engineers to drive fixes to completion. - Audit and harden cloud infrastructure, including Kubernetes clusters, networking, and identity configurations. - Embed security tooling (SAST, DAST, dependency scanners) into CI/CD pipelines so vulnerabilities surface before production. - Review code, evaluate third-party libraries, and assess open-source supply-chain risks. - Lead incident response and shape continuous monitoring, detection, and mitigation practices.
Requirements - 5+ years in security engineering, product security, DevSecOps, or a combined offensive/defensive role. - Demonstrated hands-on penetration testing background across applications, APIs, and network layers. - Builder mentality: ability to read code, understand exploits, write fixes, or produce actionable remediation guidance. - Deep familiarity with cloud security on GCP or AWS and with containerized environments such as Kubernetes and Docker. - Experience managing CVEs, open-source licensing concerns, and software composition analysis tools. - Fluent written and spoken English, with the discipline to operate autonomously in a fully remote setup.
Nice to have - Comfort working in a fast-paced open-source startup where pragmatism and execution speed are valued. - Familiarity with infrastructure-as-code, GitHub Actions, ArgoCD, or similar deployment tooling.
Benefits and work setup - Fully remote-first with access to coworking spaces worldwide. - Health coverage including medical, dental, and vision. - Home office equipment provided. - Hiring process typically completes in 2-3 weeks, starting with an asynchronous practical assessment followed by intro, team, and leadership conversations.