
Security Engineer
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in Germany, +3 more countries.
• Take charge of hands-on engineering and operational responsibilities within the security program.
• Manage the public bug bounty initiative, encompassing triage, validation, communication with researchers, and follow-up on remediation.
• Examine reported vulnerabilities at the code level in Rust, Go, and Python.
• Supply security tools, standardized defaults, documentation, and practical advice to engineering teams.
• Collaborate with engineering teams to design, review, and validate security enhancements.
• Strengthen and oversee the security of the GitHub organization, including secret scanning, push protection, branch protection, dependency alerts, and code scanning.
• Monitor, investigate, and respond to security alerts within AWS, Kubernetes, CI/CD, and associated infrastructures.
• Track and report on vulnerability remediation SLAs, MTTR, patch latency, and critical findings to the Security Officer.
• Implement, configure, and sustain security tools across development and cloud environments.
• Assist in security incident response, including investigation, containment, remediation, and follow-up actions.
• Maintain comprehensive and auditable records of vulnerabilities and incidents.
• Develop scalable security automation and guardrails, including CI/CD checks, policy-as-code, GitHub automation, and automated cloud security measures.
• Engage in threat modeling and architecture evaluations.
• Contribute to ISMS security tool assessments, technical vendor evaluations, and proof-of-concept initiatives.
• Proficient in reading and navigating unfamiliar Rust, Go, and Python codebases to validate vulnerability reports, trace impact, and evaluate fixes.
• Skilled in writing and maintaining automation and security tools.
• Experience in triaging vulnerability reports or engaging in bug bounty, vulnerability disclosure, product security, or related roles.
• Practical understanding of cloud and container security, especially AWS and Kubernetes.
• Familiar with GitHub security features and securing CI/CD processes.
• Capable of methodically investigating alerts and vulnerabilities, distinguishing real risks from noise, and suggesting appropriate remediation.
• Strong written communication skills to collaborate effectively with external researchers and internal engineering teams.
• Self-motivated and comfortable managing a security queue independently.
• Over 3 years of hands-on experience in security engineering, product security, or vulnerability management.
• Background in offensive security, such as penetration testing, CTF participation, vulnerability research, or exploit analysis (preferred).
• Experience in an open-source company or contributing security enhancements to open-source projects (preferred).
• Familiarity with cloud-native incident response (preferred).
• A competitive salary complemented by additional perks.
• Flexible working hours and an asynchronous-friendly culture.
• High levels of ownership and tangible impact.
• An open-source, engineering-driven environment.
• Freedom to select your own laptop equipment.
• For candidates in the US: 401k matching.
• For candidates in the US: health, dental, and vision insurance.
• For candidates in the US: a flexible PTO policy.
Cloudiax
Cisco
Cisco
Skylight
Get handpicked remote jobs straight to your inbox weekly.