
Security Engineer
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in United States.
• Drive a secure Software Development Life Cycle (SDLC) and conduct security-focused code reviews throughout the engineering organization.
• Take ownership of application security aspects including authorization, tenant isolation, prevention of Server-Side Request Forgery (SSRF) and injection attacks, and secrets management.
• Enhance the security posture of cloud environments (GCP IAM, egress controls) and implement supply-chain security measures.
• Coordinate activities such as penetration testing, threat modeling, and vulnerability management.
• Lead incident response efforts and promote compliance readiness (e.g., SOC 2).
• A minimum of 4 years of experience in security engineering, with a strong emphasis on application security.
• Practical experience in securing cloud-native, multi-tenant architectures.
• Familiarity with OWASP-class vulnerabilities and strategies for preventing them in actual code.
• Capability to collaborate effectively with engineers to ensure security is practical and not obstructive.
• A high-impact position with ownership from the very beginning.
• Competitive salary along with significant equity opportunities.
• Direct collaboration with founders and real users.
• Flexibility to work remotely.
• An opportunity to contribute to the development of an AI-native product from its inception.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.