
Senior Security Engineer
Posted Sep 10

Posted Sep 10
This is a fully remote position, open to applicants in Malta.
• Design and implement security measures across cloud infrastructure, applications, and CI/CD pipelines.
• Provide guidance and mentorship to developers, engineers, and architects on secure design practices, threat modeling, and cloud security principles.
• Take ownership of vulnerability management and attack surface management, focusing on real exploitability and ensuring issues are resolved.
• Enhance the SDLC by integrating and fine-tuning SAST, DAST, and SCA tools.
• Build and uphold the cloud security posture primarily in AWS and Cloudflare environments.
• Strengthen configurations, automate compliance audits, and address security vulnerabilities.
• Manage detection and response processes comprehensively, including logging, alerting, investigation, remediation, and post-incident documentation.
• Design and oversee least-privilege IAM for both human and machine identities.
• Conduct offensive security testing on infrastructure, applications, and identity flows.
• Leverage AI for triage, code reviews, detection engineering, evidence gathering, and automating repetitive tasks.
• Ensure the security of AI systems as they are integrated into operations.
• Automate recurring security tasks.
• Deliver straightforward security evaluations along with actionable recommendations and initial pull requests.
• Over 5 years of hands-on experience in a technical security engineering role.
• Proven track record of implementing solutions and delivering security fixes.
• Capability to design and implement architectures that are production-ready.
• Sound judgment in security engineering, IT security, security operations, and offensive security.
• In-depth knowledge of AWS security, including IAM, Organizations and SCPs, Security Hub, GuardDuty, WAF, and Cloudflare.
• Practical programming experience in Python, Go, and Bash; TypeScript knowledge is a significant advantage.
• Familiarity with Infrastructure as Code, including drift management, overly permissive modules, state secrets, and pipeline privilege elevation.
• Personal experience managing vulnerability and attack surface assessments.
• Strong knowledge of SIEM and detection engineering.
• Hands-on experience in detection and response, including alert investigation and writing post-incident reviews.
• Working knowledge of offensive security, including the ability to chain misconfigurations into attack vectors.
• Current practical use of AI in security tasks.
• Up-to-date understanding of AI-driven threats.
• Experience in SDLC security, particularly in integrating and tuning SAST, DAST, and SCA tools.
• Ability to work independently while maintaining effective communication.
• Capable of collaborating closely with engineering teams.
• Comfort with engaging in open technical discussions.
• Nice to have: hands-on experience with PCI DSS.
• Nice to have: experience in building and maintaining SIEM systems.
• Nice to have: experience with serverless and event-driven architectures at scale.
• Nice to have: background in iGaming, fintech, or regulated high-value-target industries.
• Nice to have: experience in corporate IT security.
• Nice to have: experience securing AI or autonomous systems.
• Nice to have: familiarity with NIST CSF, CIS Benchmarks, or CSA CCM.
• Nice to have: public contributions such as tools, write-ups, CVEs, CTF results, or presentations.
• Nice to have: certifications like CISSP, AWS Certified Security, or CEH.
• A streamlined, focused company that offers a flexible work environment.
• The chance to collaborate with and learn from a highly skilled and talented team.
• A vibrant company culture where accountability is fundamental, transparency is essential, and competence is valued.
• Be part of a close-knit, caring community.
• Work equipment of your choice.
• Private health insurance.
• Learning budget for professional development.
• Company-wide and team-oriented gatherings.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.