Senior Security Engineer

Posted Sep 9

This is a fully remote position, open to applicants in Malta.

📋 Description

• Design and lead the architecture and execution of security measures within cloud infrastructure, applications, and CI/CD pipelines.

• Develop security controls as part of a compact three-member security team.

• Provide coaching and mentorship to developers, engineers, and architects on secure design, threat modeling, and cloud security protocols.

• Manage vulnerability and attack surface oversight, focusing on exploitability and ensuring resolution of identified issues.

• Integrate and optimize SAST, DAST, and SCA throughout the software development lifecycle (SDLC).

• Engineer and uphold cloud security posture, primarily within AWS and Cloudflare environments.

• Strengthen configurations, automate compliance assessments, and proactively address security vulnerabilities.

• Oversee end-to-end detection and response processes, including logging, alerting, investigation, remediation, and conducting post-incident reviews.

• Architect and direct Identity and Access Management (IAM) strategies for least-privilege access for both human and machine identities.

• Conduct testing of systems using offensive techniques against infrastructure, applications, and identity flows.

• Leverage AI tools for triage, code reviews, detection engineering, evidence collection, and automation of repetitive tasks.

• Ensure security of AI systems as their adoption increases within the company.

• Automate recurring security processes.

• Deliver candid assessments accompanied by actionable plans and initial pull requests.


⛳️ Requirements

• Over 5 years of hands-on experience in a technical security engineering role.

• Proven track record of being responsible for implementing solutions and delivering security architectures in production settings.

• Sound judgment in areas of security engineering, IT security, security operations, and offensive security.

• Extensive experience with AWS security services: IAM, Organizations, SCPs, Security Hub, GuardDuty, WAF, and Cloudflare.

• Capability to identify and mitigate compromised roles.

• Experience in production coding with Python, Go, and Bash; proficiency in TypeScript is a significant advantage.

• Familiarity with Infrastructure as Code, including managing drift, overly permissive modules, state secrets, and pipeline privilege escalation.

• Direct involvement in vulnerability and attack surface management.

• Strong knowledge in SIEM and detection engineering.

• Practical experience in detection and response, including the investigation of real alerts and authoring post-incident reviews.

• Working knowledge of offensive security, including linking misconfigurations into attack vectors.

• Current practical experience utilizing AI in security operations.

• Specific insights into AI-driven threats.

• Experience with SDLC security, including integration and tuning of SAST, DAST, and SCA.

• Ability to work independently while collaborating closely with engineers.

• Comfort with engaging in technical discussions.

• Preferred: hands-on experience with PCI DSS compliance.

• Preferred: experience in building and maintaining a SIEM.

• Preferred: familiarity with serverless and event-driven architectures at scale.

• Preferred: experience in iGaming, fintech, or other regulated, high-value-target industries.

• Preferred: background in corporate IT security, including SSO, identity providers, MDM, SaaS security posture, and third-party/vendor access.

• Preferred: experience in securing AI or autonomous systems.

• Preferred: knowledge of NIST CSF, CIS Benchmarks, or CSA CCM.

• Preferred: public contributions such as released tools, write-ups, CVEs, CTF results, or presentations.

• Certifications like CISSP, AWS Certified Security, or CEH are valued, but demonstrated practical experience carries more weight.


🏝️ Benefits

• Flexible working environment.

• Opportunity to collaborate with and learn from a highly skilled and talented team.

• Company culture that emphasizes accountability, transparency, and competence.

• A close-knit and supportive community.

• Choice of work equipment.

• Private health insurance.

• Learning budget.

• Company-wide and team-oriented gatherings.

People also viewed

WorkOS23 hours ago

Product Security Engineer

US flagUnited States, +1 more countryFull-timeCybersecurity / Security Engineer$175k – $275k/year
ApplyView job
Fortive23 hours ago

Information Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Brown and Caldwell1 day ago

Cybersecurity, OT-IT Security Consultant

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$129k – $212k/year
ApplyView job
Galileo1 day ago

IT and Security Generalist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$110k – $120k/year
ApplyView job
Mercor1 day ago

Cybersecurity Practitioner – SOC, Incident Response, Detection, AppSec

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer$125 – $175/hour
ApplyView job
Peek1 day ago

Security and Compliance Analyst

MX flagMexico OnlyFull-timeCybersecurity / Security Engineer$80k – $90k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers