VOTRE PROCHAIN CHAPITRE
Senior Security Engineer
À propos du poste
• Design and build security-by-default infrastructure across Aptible's AWS-based PaaS
• Own and mature the vulnerability management program, including triage, prioritization, and verified remediation
• Own the end-to-end penetration testing program using XBOW, manual testing, and third-party testing
• Drive remediation in Ruby, Go, TypeScript codebases and infrastructure
• Lead incident response, including detection, containment, eradication, and post-incident review
• Build and maintain detection tooling, alerting, and runbooks
• Tune and extend the AWS Security Agent
• Participate in the on-call rotation for security-relevant incidents
• Run compliance recertifications and maintain standards such as SOC 2 or HITRUST
• Coordinate evidence collection and work with auditors
• Use AI tools to improve development and investigation workflows
• Collaborate closely with the Engineering team and report to the VP of Security
• 5+ years of experience in security engineering
• Track record of owning security-critical systems in production
• Hands-on security engineering experience, including reading and writing code and operating infrastructure
• Strong communication skills in writing and during incidents
• Strong engineering fundamentals and coding ability across a fullstack codebase
• Proficiency in at least one mainstream programming language and ability to learn new languages/frameworks quickly
• Hands-on cloud infrastructure security experience, preferably AWS
• Experience with AWS-native security tooling such as AWS Security Agent, GuardDuty, and Security Hub
• Experience with distributed systems
• Real penetration testing experience, including automated/AI-assisted tools such as XBOW
• Experience driving penetration-test remediation to completion
• Experience running or significantly contributing to a vulnerability management program
• Experience leading or heavily participating in incident response
• Familiarity with identity management, network security, and detection tooling
• Ability to run compliance recertifications as a project
• Ability to work collaboratively with Engineering in a small, autonomous team
• Ability to work in the Pacific, Mountain, Central, or Eastern Time Zone
• Must live and work in an eligible North American time zone and have legal authorization to work in the country of residence
• Compensated take-home project
• Remote work arrangement
• Participation in an on-call rotation
• Final in-person onsite interview
• Accommodation support for disabilities or special needs