
Senior Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Malta.
• Design and lead the implementation of security controls across cloud infrastructure, applications, and CI/CD pipelines.
• Develop security controls directly.
• Mentor and coach developers, engineers, and architects on secure design, threat modeling, and cloud security.
• Manage vulnerability and attack surface management, prioritizing based on exploitability and ensuring findings are resolved.
• Oversee SDLC security by integrating and fine-tuning SAST, DAST, and SCA.
• Engineer and uphold cloud security posture in AWS and Cloudflare.
• Strengthen configurations, automate compliance checks, and mitigate security vulnerabilities.
• Manage detection and response comprehensively, including logging, alerting, investigation, remediation, and post-incident documentation.
• Architect and direct IAM strategy for least-privilege human and machine identities.
• Conduct tests on company systems utilizing offensive techniques against infrastructure, applications, and identity flows.
• Employ AI for triage, code review, detection engineering, evidence gathering, and automation of repetitive tasks.
• Secure AI systems as the company incorporates them.
• Automate repetitive processes.
• Provide honest security assessments along with actionable plans and initial pull requests.
• Over 5 years of hands-on experience in a technical security engineering position, with responsibility for implementing solutions.
• Proven track record in designing and delivering security architecture and controls in production environments.
• Strong judgment across security engineering, IT security, security operations, and offensive security.
• Extensive experience with AWS security: IAM, Organizations and SCPs, Security Hub, GuardDuty, WAF, and Cloudflare.
• Experience in production programming using Python, Go, Bash; TypeScript is a significant advantage.
• Knowledge of Infrastructure as Code, including drift, over-permissive modules, secrets in state, and pipeline privilege escalation.
• Experience managing vulnerability and attack surface, including driving remediation efforts with other teams.
• Solid understanding of SIEM and detection engineering.
• Hands-on experience in detection and incident response, including investigating real alerts and drafting post-incident reviews.
• Familiarity with offensive security, including linking misconfigurations into attack paths.
• Practical experience utilizing AI in security tasks and the ability to assess its outputs.
• Current and specific understanding of AI-driven threats.
• Experience with integrating and tuning SAST, DAST, and SCA within the SDLC.
• Ability to work independently while collaborating closely with engineers.
• Willingness to engage in open technical discussions.
• Experience with PCI DSS, building/maintaining SIEM, serverless and event-driven architecture, regulated industries, corporate IT security, AI or agentic system security, security frameworks, public artifacts, and certifications such as CISSP, AWS Certified Security, or CEH is a plus.
• While certifications are valued, demonstrated experience is prioritized.
• A streamlined, focused company offering a flexible work environment.
• The chance to collaborate with and learn from a highly skilled and talented team.
• A positive company culture, where accountability is inherent, transparency is crucial, and competency is esteemed.
• Being part of a close-knit, supportive community.
• Choice of work equipment.
• Private health insurance.
• Learning budget.
• Company-wide and team-based gatherings.
NVIDIA
Soteria - Security Solutions & Advisory
BMO U.S.
Abnormal Security
Get handpicked remote jobs straight to your inbox weekly.