Security Engineer
Quick Summary
Design and implement security controls across cloud, infrastructure, and internal platforms Partner with engineering to harden cloud architecture, IAM,
We're looking for an experienced, hands-on Security Engineer to secure XBOW's product, cloud, and platform as we scale. This is a technical individual contributor role focused on building security into how we design, ship, and operate systems.
You'll work closely with engineering and platform teams across application security, cloud security, vulnerability management, and incident response. The core of this role is security engineering ownership: improving preventive controls, detection quality, and response readiness, while driving remediation of real risks in production.
Responsibilities
~1 min read- →
Design and implement security controls across cloud, infrastructure, and internal platforms
- →
Partner with engineering to harden cloud architecture, IAM, and infrastructure
- →
Own product security reviews for new features, services, and major architecture changes
- →
Drive threat modeling and secure design decisions early in the SDLC
- →
Operate and improve AppSec workflows (SAST, SCA, secrets scanning, IaC scanning)
- →
Triage vulnerabilities across application, container, and cloud findings, and drive remediation with risk-based SLAs
- →
Define and run the vulnerability management lifecycle: intake, prioritization, exception handling, validation, and reporting
- →
Improve CNAPP coverage and finding quality across cloud accounts and workloads
- →
Improve Kubernetes and container security posture
- →
Monitor, investigate, and respond to security events and incidents
- →
Build automation to improve security operations, access workflows, and incident response
- →
Support the wider teams by providing timezone coverage for our fully remote organization.
5+ years of experience in security engineering, product security, cloud/platform security, or closely related roles
Strong hands-on experience securing cloud environments (AWS, Azure and GCP)
Comfortable owning technical security problems end-to-end in fast-moving environments
Hands-on experience with product/application security in engineering environments (secure design reviews, threat modeling, code-level risk discussions)
Experience operating AppSec tooling and processes at scale (SAST, SCA, secrets, IaC scanning)
Strong vulnerability triage and remediation management experience, including risk-based prioritization and SLAs
Experience with CNAPP (or equivalent cloud security platforms) and tuning findings for engineering actionability
Working knowledge of Kubernetes/container security in production systems
Ability to partner with developers and platform teams to ship secure defaults without blocking delivery
Comfortable writing scripts and automations to improve security reliability and scale
Experience in incident response, investigation, and post-incident hardening in cloud-native environments
Security-minded, detail-oriented, and a proactive communicator in remote-first teams
Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI)
Offensive security/pentesting background and ability to convert findings into durable engineering fixes
Experience scaling security at a startup from early stage to audit-ready maturity
Relevant security certifications (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certs)
What We Offer
~1 min read-
• Location: Remote: US, Canada, Argentina. All team members are remote but we meet regularly and you're supported to travel to collaborate with colleagues in person
• Contract: Full-time.
30-min introductory chat with your Talent Partner
30 minutes with the Hiring Manager.
1 hour technical deep dive.
30 minutes with the Deputy CISO
30-min final meeting with our CISO
We're a security company that builds with AI at the core — so you'll be protecting a team that moves fast, iterates aggressively, and lives in the command line. If that sounds like your kind of environment, let's talk.
Location & Eligibility
Listing Details
- Posted
- September 17, 2026
- First seen
- September 25, 2026
- Last seen
- September 26, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 42%
- Scored at
- September 26, 2026
Signal breakdown
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.