← Zurück zur Liste

Stelle
· Senior
Senior Security Engineer
Security Engineer
• Senior
• Remote
• Vollzeit
•
North America (PT-ET Time Zones), EU/EMEA
Aptible builds a cloud platform for regulated industries and is hiring a hands-on security engineer to build security-by-default infrastructure, run the vulnerability management and pentesting programs, and lead incident response. This is an engineering role first, not a policy-writing or audit-management position.
Responsibilities
- ▹Design and build security-by-default infrastructure across the AWS-based PaaS, which spans a Ruby on Rails backend, a React-TypeScript web app, a Terraform client (Go), a CLI client (Go) and other distributed components (Python, Go, Ruby)
- ▹Own and mature the vulnerability management program, triaging findings from scanning tools and the AWS Security Agent with the Engineering team and prioritizing by real-world exploitability and risk
- ▹Own the pentesting program end to end: running automated assessments with XBOW, coordinating manual and third-party testing, and driving remediation to closure in the codebase (Ruby, Go, TypeScript) and infrastructure
- ▹Lead incident response operations: detection, containment, eradication and post-incident review, fixing root causes in code and infrastructure
- ▹Build and maintain detection tooling, alerting and runbooks, including tuning and extending the AWS Security Agent, to reduce time-to-response
- ▹Participate in the on-call rotation for security-relevant incidents and help drive follow-ups that prevent repeats
- ▹Run point on compliance recertifications and maintaining current standards (e.g., renewing SOC 2 or HITRUST): coordinating evidence collection and working with auditors, not authoring new policy from scratch
- ▹Use AI tools to improve your development and investigation workflow
Requirements
- ▹5+ years of experience in security engineering, with a track record of owning security-critical systems in production
- ▹Hands-on security engineering experience, not just as a reviewer or policy writer: able to read and write code, operate infrastructure and get into the weeds of a system under attack
- ▹Extremely good communication: clear, effective and proactive, in writing and live during an incident
- ▹Strong engineering fundamentals and coding ability, comfortable across a fullstack codebase (Ruby on Rails, React/TypeScript, Go Terraform client, Ruby CLI)
- ▹A prolific and thoughtful developer in at least one mainstream language, able to pick up new languages and frameworks quickly
- ▹Deep, hands-on experience with cloud infrastructure security (AWS strongly preferred), including AWS-native security tooling (e.g., AWS Security Agent, GuardDuty, Security Hub), and distributed systems
- ▹Real pentesting experience, including with automated/AI-assisted tools like XBOW, and a track record of driving remediation rather than just reporting findings
- ▹Experience running or significantly contributing to a vulnerability management program, from scanning and triage through verified remediation
- ▹Experience leading or heavily participating in incident response, staying calm and methodical under pressure
- ▹Comfort working across identity management, network security and detection tooling
- ▹Organized enough to run a compliance recertification as a project (tracking evidence, coordinating stakeholders, hitting deadlines) without it becoming the whole job
- ▹Knowing the difference between operating existing controls well and designing net-new policy
- ▹Wanting to be part of a small, highly collaborative team and working closely with Engineering
- ▹Taking ownership and driving to get unblocked when facing ambiguity or bumps in the road
Nice to have
- ▹Developer tools or platform engineering experience
Soft skills
Excellent written and verbal communicationProactivityOwnershipCalm under pressureOrganizationClose collaboration with Engineering
What we offer
- ▹Highly autonomous, trusted role where day-to-day priorities may shift
- ▹Small, tight-knit team with genuine ownership across the whole product
- ▹Compensated take-home project in the interview process
About the company
Since 2014, Aptible has automated security, compliance and reliability for engineering teams whose apps handle the most sensitive data in the most regulated industries. It is part of Opti9 Technologies and is a small, tight-knit, profitable team.
Ähnliche Stellen

Stelle
· Senior
Senior Infrastructure Security Engineer
Headway
Datadog
+5
196 320–245 400 €/Jahr
brutto
🌍 Remote
🗣️ EN

Stelle
· Senior
Senior Security Engineer - Threat Detection
Samsara
Databricks
+5
138 935–210 154 €/Jahr
brutto
🌍 Remote
CA
🗣️ EN

Stelle
· Senior
Senior Security Engineer
Pigment
ArgocdDatadog
+10
80 044–120 066 €/Jahr
brutto
🌍 Remote
🗣️ EN
Himalayas

Stelle
· Senior
Senior Product Security Engineer
Chainalysis Careers
ArtifactoryGithub Actions
+7
114 550–217 644 €/Jahr
brutto
🌍 Remote
New York Office
🗣️ EN

Stelle
· Senior
Senior Security Engineer - Threat Detection
Samsara
Databricks
+5
138 935–210 154 €/Jahr
brutto
🔀 Hybrid
Seattle
🗣️ EN

Stelle
· Senior
Senior Security Engineer - Threat Detection
Samsara
Databricks
+5
138 935–210 154 €/Jahr
brutto
🔀 Hybrid
Dallas
🗣️ EN