Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
K

Senior Security Engineer

Kestra
Location not stated
Remote
Senior
17 hours ago
  • AI
  • Bloomberg
  • GitHub
  • Penetration Testing
  • Threat Modeling
  • GCP
  • Kubernetes
  • CI/CD
  • SAST
  • DAST
  • Incident Response
  • Trivy
  • Dependabot
  • Elastic
  • Docker
  • Terraform
  • Java
  • TypeScript
  • JavaScript
  • PostgreSQL
  • Elasticsearch
  • Redis
  • AMQP
  • Prometheus
  • Grafana
  • GitHub Actions
  • ArgoCD
  • DevSecOps
  • AWS
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

About Kestra

Kestra is theuniversal orchestration platform: open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems.

Trusted byover 10,000 organizations worldwide, includingJPMorgan Chase, Bloomberg, FILA, and Crédit Agricole, Kestra orchestrates mission-critical workloads at scale. The open-source project has close to30,000 GitHub stars, hundreds of contributors, and a fast-growing global community.

About the role

We’re looking for aSenior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem.

This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.

What you would do

  • Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments.

  • Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure.

  • Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.

  • Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats.

  • Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.

  • Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks.

  • Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies.

Our Tech Stack

  • Security & Vulnerability Tools: Trivy, GitHub Security / Dependabot, Elastic Security

  • Infrastructure: Docker, Kubernetes, Terraform

  • Cloud: GCP

  • Programming language: Java, Typescript, Javascript

  • Datastore: PostgreSQL, Elasticsearch

  • Queuing: Redis, Kafka, AMQP

  • Monitoring & Logs: ELK, Prometheus, Grafana

  • Deployment & Repository: GitHub Actions, ArgoCD

What we are looking for

  • 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.

  • Strong hands-on penetration testing background, with proven ability to discover application, API, and network-level vulnerabilities.

  • A builder/fixer mindset: You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers.

  • Deep familiarity with cloud security (AWS or GCP) and containerized environments (Kubernetes, Docker).

  • Experience withdependency and supply-chain security (CVE management, open-source licensing, SCA tools).

  • Fluent in English and comfortable working autonomously in a fully remote environment.

  • Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.

Perks & Benefits

  • Work from anywhere: We’re a remote-first company, so you can work from wherever feels like home. Plus, you’ll have access to coworking spaces worldwide if you ever need a change of scenery.

  • Health coverage: From medical support, dental, and vision, we've got you covered.

  • Home office setup on us: We’ll provide all the equipment you need to work comfortably.

     

Our Hiring Process

We aim to move quickly (2-3 weeks), but we can adjust the timeline if needed.

  • Technical scenario / Practical assessment (2 hours, asynchronous homework focusing on threat assessment and remediation)

  • Intro call with the hiring manager (30 min)

  • Team chat with one of your future colleagues (30 min)

  • Final discussion with one of our co-founders (30 min)

Senior Security Engineer · Kestra

Auto apply with Likeremote