Security Engineer Opportunity
We are seeking a Security Engineer with 2–5 years of experience in cloud security, application security, and enterprise risk management. You’ll play a critical role in protecting XenonStack’s AI platforms and enterprise clients by designing and implementing security controls, monitoring for threats, and ensuring compliance with global standards.
This role is ideal for someone who thrives at the intersection of cybersecurity, cloud infrastructure, and AI innovation.
Key Responsibilities
- Cloud Security – Implement and monitor security best practices across AWS, Azure, and GCP environments.
- Application Security – Conduct security reviews, code analysis, and vulnerability assessments for AI/ML and web applications.
- Identity & Access Management (IAM) – Design and enforce secure authentication, authorization, and role-based access controls.
- Threat Detection & Response – Monitor security alerts, investigate incidents, and support SOC teams with remediation.
- DevSecOps – Integrate security into CI/CD pipelines with automated scanning and policy enforcement.
- Compliance & Governance – Ensure adherence to ISO 27001, SOC 2, GDPR, and AI governance frameworks.
- Data Security – Protect sensitive enterprise data with encryption, tokenization, and secure storage practices.
- Security Automation – Build scripts, tools, and dashboards for continuous monitoring and risk detection.
- Collaboration – Partner with engineering, DevOps, and product teams to embed security by design in agentic AI systems.
- Research & Improvement – Stay updated with emerging threats, AI security risks, and zero‑trust frameworks.
Must‑Have Skills & Qualifications
- 2–5 years of hands‑on experience in cloud, application, or platform security.
- Strong knowledge of AWS/Azure/GCP security services (IAM, KMS, GuardDuty, Security Hub).
- Familiarity with DevSecOps practices and CI/CD security (Jenkins, GitLab CI, Terraform).
- Experience with threat modeling, vulnerability scanning, and penetration testing tools.
- Knowledge of encryption, PKI, and secure communication protocols.
- Proficiency in Python, Bash, or Go for security automation.
- Understanding of compliance frameworks (ISO, SOC 2, GDPR, PCI‑DSS).
Good‑to‑Have Skills & Qualifications
- Experience securing AI/ML pipelines, model inference endpoints, and data lakes.
- Exposure to Zero Trust architectures and microservices security.
- Familiarity with SIEM/SOAR tools (Splunk, ELK, Sentinel).
- Security certifications such as CISSP, CISM, CEH, OSCP, CCSK add value.