
Senior Security Engineer
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in Malta.
• Design and lead the architecture and execution of security measures within cloud infrastructure, applications, and CI/CD pipelines.
• Develop security controls as part of a compact three-member security team.
• Provide coaching and mentorship to developers, engineers, and architects on secure design, threat modeling, and cloud security protocols.
• Manage vulnerability and attack surface oversight, focusing on exploitability and ensuring resolution of identified issues.
• Integrate and optimize SAST, DAST, and SCA throughout the software development lifecycle (SDLC).
• Engineer and uphold cloud security posture, primarily within AWS and Cloudflare environments.
• Strengthen configurations, automate compliance assessments, and proactively address security vulnerabilities.
• Oversee end-to-end detection and response processes, including logging, alerting, investigation, remediation, and conducting post-incident reviews.
• Architect and direct Identity and Access Management (IAM) strategies for least-privilege access for both human and machine identities.
• Conduct testing of systems using offensive techniques against infrastructure, applications, and identity flows.
• Leverage AI tools for triage, code reviews, detection engineering, evidence collection, and automation of repetitive tasks.
• Ensure security of AI systems as their adoption increases within the company.
• Automate recurring security processes.
• Deliver candid assessments accompanied by actionable plans and initial pull requests.
• Over 5 years of hands-on experience in a technical security engineering role.
• Proven track record of being responsible for implementing solutions and delivering security architectures in production settings.
• Sound judgment in areas of security engineering, IT security, security operations, and offensive security.
• Extensive experience with AWS security services: IAM, Organizations, SCPs, Security Hub, GuardDuty, WAF, and Cloudflare.
• Capability to identify and mitigate compromised roles.
• Experience in production coding with Python, Go, and Bash; proficiency in TypeScript is a significant advantage.
• Familiarity with Infrastructure as Code, including managing drift, overly permissive modules, state secrets, and pipeline privilege escalation.
• Direct involvement in vulnerability and attack surface management.
• Strong knowledge in SIEM and detection engineering.
• Practical experience in detection and response, including the investigation of real alerts and authoring post-incident reviews.
• Working knowledge of offensive security, including linking misconfigurations into attack vectors.
• Current practical experience utilizing AI in security operations.
• Specific insights into AI-driven threats.
• Experience with SDLC security, including integration and tuning of SAST, DAST, and SCA.
• Ability to work independently while collaborating closely with engineers.
• Comfort with engaging in technical discussions.
• Preferred: hands-on experience with PCI DSS compliance.
• Preferred: experience in building and maintaining a SIEM.
• Preferred: familiarity with serverless and event-driven architectures at scale.
• Preferred: experience in iGaming, fintech, or other regulated, high-value-target industries.
• Preferred: background in corporate IT security, including SSO, identity providers, MDM, SaaS security posture, and third-party/vendor access.
• Preferred: experience in securing AI or autonomous systems.
• Preferred: knowledge of NIST CSF, CIS Benchmarks, or CSA CCM.
• Preferred: public contributions such as released tools, write-ups, CVEs, CTF results, or presentations.
• Certifications like CISSP, AWS Certified Security, or CEH are valued, but demonstrated practical experience carries more weight.
• Flexible working environment.
• Opportunity to collaborate with and learn from a highly skilled and talented team.
• Company culture that emphasizes accountability, transparency, and competence.
• A close-knit and supportive community.
• Choice of work equipment.
• Private health insurance.
• Learning budget.
• Company-wide and team-oriented gatherings.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.