Lead / Senior Engineer – Application & Platform Security and CloudOps
6 - 8
Full-Time
About the Role
We are looking for a hands-on Lead / Senior Engineer to own Application and Platform Security
alongside CloudOps for our engineering organization. This role sits at the intersection of security
engineering and cloud infrastructure, and is responsible for hardening our applications, cloud
environment, and CI/CD pipelines while enabling teams to ship quickly and safely. This is a high-
ownership role for someone who enjoys building secure-by-default systems and mentoring engineers
along the way.
Key Responsibilities
- Own the application security strategy — secure coding standards, threat modeling, SAST/DAST integration, and vulnerability management across services.
- Lead cloud security posture management (CSPM) across AWS/Azure/GCP — IAM hardening, network segmentation, secrets management, and compliance guardrails.
- Own CloudOps responsibilities including infrastructure provisioning, cost optimization, environment reliability, and cloud governance.
- Drive security automation into CI/CD pipelines (shift-left security), including container and dependency scanning.
- Define and enforce security policies, access controls, and audit processes; lead incident response and root-cause analysis for security events.
- Partner with engineering leads to review architecture and infrastructure changes from a security and cloud-operations lens.
- Mentor and guide engineers on secure coding practices and cloud operations best practices; act as a technical escalation point.
- Stay current with emerging security threats, cloud-native security tooling, and compliance
Required Skills & Experience
- 7+ years of experience in application security, cloud security, or DevSecOps, with at least 2+ years in a lead / senior capacity.
- Strong hands-on experience with at least one major cloud provider (AWS, Azure, or GCP) — IAM, VPC/networking, KMS, security groups.
- Solid understanding of application security fundamentals — OWASP Top 10, secure SDLC, threat modeling, SAST/DAST/SCA tools.
- Experience with Infrastructure as Code (Terraform / CloudFormation) and CI/CD tools (Jenkins, GitHub Actions, GitLab CI).
- Working knowledge of container security (Docker, Kubernetes) and secrets management tools (Vault, AWS Secrets Manager).
- Scripting/programming proficiency (Python, Go, or similar) for automation and tooling.
- Familiarity with compliance frameworks and security audits (SOC2, ISO 27001, PCI-DSS, or similar).
- Excellent communication skills with the ability to influence engineering practices without slowing
Good to Have
- Relevant certifications — CISSP, CCSP, OSCP, AWS/Azure Security Specialty, or CKS.
- Experience running bug bounty or penetration testing programs.
- Prior experience setting up a security function or CloudOps practice from the ground up.
What We Offer
- Ownership of a critical, high-visibility function shaping how the entire engineering org builds and ships securely.
- A collaborative culture that values pragmatic security over box-ticking.
- Competitive compensation, benefits, and growth opportunities.