Senior Security Engineer

kestra

United States

Remote

USD 140,000 - 190,000

Full time

13 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health coverage
Home office equipment
Fully remote

Job summary

kestra is seeking an experienced security engineer to own the full security posture of an open-source orchestration platform and its cloud SaaS. The role blends offensive and defensive work, including threat modeling, hands-on testing, patching, and code contributions.

The ideal candidate has 5+ years in security engineering, deep cloud security expertise on AWS or GCP, and strong Kubernetes/Docker experience. This is a fully remote role with global collaboration and fast-paced OSS development.

Qualifications

  • At least 5+ years in security engineering or similar roles.
  • Hands-on penetration testing across applications, APIs, and networks.
  • Able to read code and produce fixes or remediation guidance.
  • Deep knowledge of cloud security on AWS or GCP and containerization with Kubernetes and Docker.
  • Experience managing CVEs, OSS licensing, and software composition analysis tools.

Responsibilities

  • Conduct penetration testing and threat modeling across web, APIs, control plane, and cloud.
  • Remediate vulnerabilities in code, dependencies, containers, and cloud configs.
  • Submit patches or PRs and collaborate with engineers to drive fixes.
  • Harden cloud infrastructure, including Kubernetes clusters and IAM configurations.
  • Embed SAST/DAST and dependency scanning into CI/CD pipelines.
  • Review third-party libraries and assess OSS risk.
  • Lead incident response and improve monitoring, detection, and response.

Skills

Security testing
Threat modeling
Cloud security
Code patching
Autonomous work

Tools

Kubernetes
Docker
GitHub Actions
SAST/DAST tools

Job description

Role overview

A remote-first opportunity for an experienced security professional to own the full security posture of an open-source orchestration platform and its cloud SaaS counterpart. The position blends offensive and defensive work: actively probing systems for weaknesses, hardening infrastructure, and patching issues directly through code contributions. It suits someone who enjoys moving between threat modeling, hands-on exploitation, and remediation in a fast-moving open-source environment.

Responsibilities
  • Conduct penetration testing and structured threat modeling across the web application, APIs, control plane, and cloud environments.
  • Track and remediate vulnerabilities spanning source code, third-party dependencies, container images, and cloud configuration.
  • Write and submit patches or pull requests, or collaborate closely with product engineers to drive fixes to completion.
  • Audit and harden cloud infrastructure, including Kubernetes clusters, networking, and identity configurations.
  • Embed security tooling (SAST, DAST, dependency scanners) into CI/CD pipelines so vulnerabilities surface before production.
  • Review code, evaluate third-party libraries, and assess open-source supply-chain risks.
  • Lead incident response and shape continuous monitoring, detection, and mitigation practices.
Requirements
  • 5+ years in security engineering, product security, DevSecOps, or a combined offensive/defensive role.
  • Demonstrated hands-on penetration testing background across applications, APIs, and network layers.
  • Builder mentality: ability to read code, understand exploits, write fixes, or produce actionable remediation guidance.
  • Deep familiarity with cloud security on GCP or AWS and with containerized environments such as Kubernetes and Docker.
  • Experience managing CVEs, open-source licensing concerns, and software composition analysis tools.
  • Fluent written and spoken English, with the discipline to operate autonomously in a fully remote setup.
Nice to have
  • Comfort working in a fast-paced open-source startup where pragmatism and execution speed are valued.
  • Familiarity with infrastructure-as-code, GitHub Actions, ArgoCD, or similar deployment tooling.
Benefits and work setup
  • Fully remote-first with access to coworking spaces worldwide.
  • Health coverage including medical, dental, and vision.
  • Home office equipment provided.
  • Hiring process typically completes in 2-3 weeks, starting with an asynchronous practical assessment followed by intro, team, and leadership conversations.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

xbowcareers • United States

Remote
USD 140,000 - 210,000
Competitive salary
Equity or incentive plan
401k plan
Security Engineer
Security Engineer

calahealth • United States

Remote
USD 155,000 - 190,000
Remote-first
Staff Security Engineer
Staff Security Engineer

turing • United States

Remote
USD 208,000 - 282,000
Senior Security Engineer — Remote, Open-Source Security
Senior Security Engineer — Remote, Open-Source Security

kestra • United States

Remote
USD 140,000 - 190,000
Health coverage
Home office equipment
Fully remote
Freelance Senior DevSecOps Engineer
Freelance Senior DevSecOps Engineer

Toloka • United States

Remote
USD 140,000 - 210,000
Product Security Engineer
Product Security Engineer

Modernhealth • United States

Remote
USD 101,000 - 140,000
health and insurance coverage
flexible time off
family-support programs
+4
Senior Product Security Engineer
Senior Product Security Engineer

Gofractional • Northern (KY)

On-site
USD 83,000 - 165,000
Medical coverage
Dental coverage
Vision coverage
+7
Product Security Engineer
Product Security Engineer

GoMining • Town of Poland (NY)

On-site
USD 120,000 - 190,000
Professional growth support
Flexible hours
Vacation and holidays
Product Security Engineer
Product Security Engineer

GoMining • Georgia

On-site
USD 120,000 - 180,000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
Staff Security Operations Engineer (Fully Remote)
Staff Security Operations Engineer (Fully Remote)

Jobgether SRL • United States

Remote
USD 90,000 - 150,000
Remote-first environment
In-person team sprints twice a year
Annual learning budget USD 2000
+1