Remote job
Lead Security Engineer / DevSecOps
Job details
About this role
Role overview A senior security leadership role setting the technical direction for cloud and Kubernetes security across multiple client engagements. The lead blends architectural influence with deep hands-on work, covering secure-by-default platforms, pipeline hardening, detection engineering, and emerging threats specific to AI and LLM systems. It is a player-coach position that raises the bar for the wider security practice.
Responsibilities - Define and evolve security architecture standards for cloud and Kubernetes environments across client platforms. - Embed security controls into CI/CD pipelines, including scanning, policy-as-code, and supply-chain protections. - Design and tune detection content for runtime threats, with attention to novel AI and LLM attack patterns. - Lead threat modeling, architecture reviews, and risk assessments for new initiatives. - Mentor other engineers and review their work to lift overall security engineering quality. - Align security investments with business risk through clear stakeholder communication.
Requirements - Extensive experience in security engineering with a clear progression into leadership responsibilities. - Deep expertise in cloud security on AWS, GCP, or Azure, and Kubernetes hardening. - Practical knowledge of DevSecOps tooling such as SAST, DAST, SCA, and secret management. - Experience building or operating a detection engineering program including SIEM, EDR, or custom rules. - Strong communication skills for working with both engineers and executive stakeholders. - Familiarity with AI and LLM threat landscapes such as prompt injection, model exfiltration, or supply-chain risk.
Nice to have - Relevant certifications such as OSCP, GIAC, AWS Security Specialty, or CKS. - Public speaking, blogging, or open-source contributions in security.