
Security Engineer
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants anywhere in the world.
• Lead security assessments for web applications, APIs, microservices, AWS workloads, internal platforms, and AI-driven products.
• Execute advanced application security evaluations utilizing SAST, DAST, SCA, manual code review, API testing, and business logic testing.
• Identify vulnerabilities related to authentication, authorization, session management, access control, injection flaws, SSRF, deserialization issues, insecure file handling, data exposure, and insecure API design.
• Conduct threat modeling for new products, essential features, AWS architectures, AI workflows, identity systems, and high-risk data flows.
• Develop and enhance secure SDLC procedures, which include security requirements, code scanning, dependency reviews, CI/CD security gates, and release risk assessments.
• Evaluate infrastructure-as-code templates such as Terraform, CloudFormation, AWS CDK, Helm charts, and Kubernetes manifests for security misconfigurations.
• Assess AWS environments for IAM vulnerabilities, exposed services, insecure networking, public S3 buckets, secrets exposure, logging deficiencies, encryption issues, workload risks, and privilege escalation pathways.
• Review AWS IAM policies, roles, trust relationships, permission boundaries, service control policies, identity federation, and cross-account access patterns.
• Evaluate AWS services including EC2, S3, Lambda, ECS, EKS, RDS, API Gateway, CloudFront, WAF, KMS, Secrets Manager, Systems Manager, ECR, VPC, Route 53, and IAM Identity Center.
• Conduct red team operations, adversary simulations, attack path analyses, and controlled exploitation to verify real-world risks.
• Create proof-of-concept exploits, custom scripts, and automation to replicate vulnerabilities and demonstrate their business impact.
• Evaluate containerized and Kubernetes environments, including EKS, for workload isolation, RBAC issues, exposed services, image vulnerabilities, secrets management, and runtime security gaps.
• Review CI/CD pipelines for insecure workflows, overprivileged tokens, secrets exposure, supply chain vulnerabilities, artifact integrity, and deployment abuse routes.
• Perform software composition analysis to identify vulnerable dependencies, licensing risks, malicious packages, transitive dependency exposures, and supply chain weaknesses.
• Utilize SIEM and security telemetry to support investigations, validate attack paths, enhance detections, and measure control effectiveness.
• Develop detection logic, threat-hunting queries, dashboards, and alerting workflows using SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, Chronicle, or AWS-native telemetry.
• Employ AWS security services such as GuardDuty, Security Hub, CloudTrail, AWS Config, Inspector, Detective, Macie, IAM Access Analyzer, Security Lake, and CloudWatch to enhance visibility and detection capabilities.
• Automate security workflows using Python, Bash, PowerShell, Go, or similar scripting languages.
• Develop threat automation for vulnerability enrichment, alert triage, AWS posture checks, attack simulations, evidence collection, and remediation tracking.
• Collaborate with DevOps and platform teams to enhance secrets management, identity controls, network segmentation, logging, monitoring, and secure deployment practices.
• Evaluate AI and LLM-based systems for risks such as prompt injection, indirect prompt injection, data leakage, insecure tool usage, excessive agency, jailbreaks, model misuse, retrieval poisoning, and unsafe agent behavior.
• Review AI workloads utilizing AWS services such as Amazon Bedrock, SageMaker, Lambda, API Gateway, S3, KMS, and IAM to ensure secure design, data protection, and access control.
• Generate clear technical reports that include evidence, exploitability, impact, likelihood, risk ratings, and actionable remediation recommendations.
• Mentor engineers and security team members on secure coding practices, AWS security, offensive testing, threat modeling, and AI security risks.
• Extensive hands-on experience in application security, product security, AWS cloud security, offensive security, or security engineering.
• In-depth understanding of secure SDLC methodologies and experience integrating security into engineering workflows.
• Practical experience with SAST, DAST, SCA, manual penetration testing, code reviews, and vulnerability validation.
• Strong knowledge of OWASP Top 10, OWASP API Security Top 10, OWASP ASVS, common CWE classes, and real-world application attack methodologies.
• Experience in testing web applications, APIs, microservices, cloud services, containers, and distributed systems.
• Solid understanding of authentication, authorization, identity federation, OAuth, OIDC, SAML, JWT, session security, and access control design.
• Proven experience in securing AWS environments in production settings.
• Comprehensive knowledge of AWS IAM, VPC networking, encryption, KMS, Secrets Manager, S3 security, CloudTrail, GuardDuty, Security Hub, AWS Config, and workload hardening.
• Experience in reviewing infrastructure-as-code and identifying security vulnerabilities in Terraform, CloudFormation, AWS CDK, Kubernetes YAML, Helm, Dockerfiles, or similar technologies.
• Familiarity with CI/CD security across tools such as Bitbucket Pipelines, Jenkins, AWS CodePipeline, or similar platforms.
• Experience in red teaming, adversary emulation, penetration testing, exploit development, attack path mapping, or offensive security assessments.
• Familiarity with SIEM platforms and proficiency in writing detection or hunting queries using SPL, KQL, SQL, Lucene, YARA, Sigma, or similar languages.
• Strong scripting capabilities in Python, Bash, PowerShell, JavaScript, or similar languages.
• Ability to automate repetitive security tasks and create internal tools that enhance security testing, visibility, and response.
• Familiarity with container and Kubernetes security, including ECS, EKS, RBAC, admission controls, image scanning, runtime controls, network policies, and secrets management.
• Proficiency in reviewing code in languages such as Python, JavaScript, TypeScript, Java, Go, Kotlin, C#, or similar.
• Excellent written and verbal communication skills, with the ability to articulate complex technical risks to engineering and leadership teams.
• Flexible work arrangements
• Opportunities for professional development
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.