Security Engineer

Posted 6 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Security Engineer securing XBOW’s AI-powered security company across cloud, product, and platform systems. Building controls, managing vulnerabilities, and improving incident response.

Responsibilities

  • Design and implement security controls across cloud, infrastructure, and internal platforms
  • Partner with engineering to harden cloud architecture, IAM, and infrastructure
  • Own product security reviews for new features, services, and major architecture changes
  • Drive threat modeling and secure design decisions early in the SDLC
  • Operate and improve AppSec workflows (SAST, SCA, secrets scanning, IaC scanning)
  • Triage vulnerabilities across application, container, and cloud findings, and drive remediation with risk-based SLAs
  • Define and run the vulnerability management lifecycle: intake, prioritization, exception handling, validation, and reporting
  • Improve CNAPP coverage and finding quality across cloud accounts and workloads
  • Improve Kubernetes and container security posture
  • Monitor, investigate, and respond to security events and incidents
  • Build automation to improve security operations, access workflows, and incident response
  • Support wider teams by providing timezone coverage for the fully remote organization

Requirements

  • 5+ years of experience in security engineering, product security, cloud/platform security, or closely related roles
  • Strong hands-on experience securing cloud environments (AWS, Azure and GCP)
  • Comfortable owning technical security problems end-to-end in fast-moving environments
  • Hands-on experience with product/application security in engineering environments (secure design reviews, threat modeling, code-level risk discussions)
  • Experience operating AppSec tooling and processes at scale (SAST, SCA, secrets, IaC scanning)
  • Strong vulnerability triage and remediation management experience, including risk-based prioritization and SLAs
  • Experience with CNAPP (or equivalent cloud security platforms) and tuning findings for engineering actionability
  • Working knowledge of Kubernetes/container security in production systems
  • Ability to partner with developers and platform teams to ship secure defaults without blocking delivery
  • Comfortable writing scripts and automations to improve security reliability and scale
  • Experience in incident response, investigation, and post-incident hardening in cloud-native environments
  • Security-minded, detail-oriented, and a proactive communicator in remote-first teams
  • Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI) advantageous
  • Offensive security/pentesting background advantageous
  • Experience scaling security at a startup from early stage to audit-ready maturity advantageous
  • Relevant security certifications advantageous (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certs)

Benefits

  • Meaningful stock options
  • Comprehensive benefits
  • 401k plan
  • Opportunity to learn from and collaborate with top security and AI experts
  • Regular opportunities to meet in person
  • Support to travel to collaborate with colleagues in person

Job type

Full Time

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Tech skills

AWSAzureCloudGoogle Cloud PlatformKubernetesSDLC

Location requirements

RemoteUnited States

Report this job

Found something wrong with the page? Please let us know by submitting a report below.