685,738open jobs
39,768companies
98,997added this week
Browse all
Salary
$126k – $229k per year (Estimated)
Location
Remote (United States, Argentina, Canada)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
XBOW is an autonomous offensive security platform that simulates real attacks to find and validate vulnerabilities in your applications. Get a demo today.

Your Role: Security Engineer

We're looking for an experienced, hands-on Security Engineer to secure XBOW's product, cloud, and platform as we scale. This is a technical individual contributor role focused on building security into how we design, ship, and operate systems.

You'll work closely with engineering and platform teams across application security, cloud security, vulnerability management, and incident response. The core of this role is security engineering ownership: improving preventive controls, detection quality, and response readiness, while driving remediation of real risks in production.

What You'll Do:

  • Design and implement security controls across cloud, infrastructure, and internal platforms

  • Partner with engineering to harden cloud architecture, IAM, and infrastructure

  • Own product security reviews for new features, services, and major architecture changes

  • Drive threat modeling and secure design decisions early in the SDLC

  • Operate and improve AppSec workflows (SAST, SCA, secrets scanning, IaC scanning)

  • Triage vulnerabilities across application, container, and cloud findings, and drive remediation with risk-based SLAs

  • Define and run the vulnerability management lifecycle: intake, prioritization, exception handling, validation, and reporting

  • Improve CNAPP coverage and finding quality across cloud accounts and workloads

  • Improve Kubernetes and container security posture

  • Monitor, investigate, and respond to security events and incidents

  • Build automation to improve security operations, access workflows, and incident response

  • Support the wider teams by providing timezone coverage for our fully remote organization.

Who You Are:

Essential-

  • 5+ years of experience in security engineering, product security, cloud/platform security, or closely related roles

  • Strong hands-on experience securing cloud environments (AWS, Azure and GCP)

  • Comfortable owning technical security problems end-to-end in fast-moving environments

  • Hands-on experience with product/application security in engineering environments (secure design reviews, threat modeling, code-level risk discussions)

  • Experience operating AppSec tooling and processes at scale (SAST, SCA, secrets, IaC scanning)

  • Strong vulnerability triage and remediation management experience, including risk-based prioritization and SLAs

  • Experience with CNAPP (or equivalent cloud security platforms) and tuning findings for engineering actionability

  • Working knowledge of Kubernetes/container security in production systems

  • Ability to partner with developers and platform teams to ship secure defaults without blocking delivery

  • Comfortable writing scripts and automations to improve security reliability and scale

  • Experience in incident response, investigation, and post-incident hardening in cloud-native environments

  • Security-minded, detail-oriented, and a proactive communicator in remote-first teams

Advantageous-

  • Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI)

  • Offensive security/pentesting background and ability to convert findings into durable engineering fixes

  • Experience scaling security at a startup from early stage to audit-ready maturity

  • Relevant security certifications (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certs)

What We Offer:

  • Compensation & Equity: Competitive salary, meaningful stock options, comprehensive benefits and 401k plan

  • Growth: Opportunity to learn from and collaborate with top security and AI experts

  • Impact: Work on complex technical challenges that support the foundation of our company

  • Remote-First:Work from anywhere, with regular opportunities to meet in person

What Else You Should Know:

  • Location: Remote: US, Canada, Argentina. All team members are remote but we meet regularly and you're supported to travel to collaborate with colleagues in person
  • Contract: Full-time.

Hiring Process:

30-min introductory chat with your Talent Partner

30 minutes with the Hiring Manager.

1 hour technical deep dive.

30 minutes with the Deputy CISO

30-min final meeting with our CISO

We're a security company that builds with AI at the core - so you'll be protecting a team that moves fast, iterates aggressively, and lives in the command line. If that sounds like your kind of environment, let's talk.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
685,738 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$140k – $232k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
Python
Go
JavaScript
SQL
Ruby
Node JS
Python
Django
AI/ML
Copilot
Cursor
Claude
Claude Code
Frontend
GraphQL
React.js
DevOps
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Apply
$45k – $134k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Mexico City
Python
JavaScript
TypeScript
SQL
C#
C#
.NET
DevOps
GCP
Azure
AWS
Docker
Kubernetes
Management
Agile
Apply
Solution Architect 3 hours ago
$39k – $88k per year (Estimated) • In office • Full-Time • Sofia
DevOps
GCP
Azure
AWS
FinOps
Cybersecurity
ISO 27001
SOC 2
Zero Trust
Microsoft Entra ID
Apply
$32k – $64k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Hyderabad
AI/ML
AI Agents
Anomaly Detection
Amazon SageMaker
DevOps
Terraform
CloudFormation
Azure
CI/CD
GitOps
AWS
Kubernetes
Self-Healing
Amazon EKS
Azure AKS
FinOps
AIOps
Incident Management
Amazon CloudWatch
Management
Agile
Apply
$18k – $40k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Hyderabad
Python
JavaScript
Node JS
Databases
GraphDB
DynamoDB
OpenSearch
AI/ML
Copilot
Windsurf
LLM
DevOps
GCP
Azure
AWS
Apply
$106k – $185k per year (Estimated) • Equity • In office • Full-Time • 7+ years exp
Apply
$180k – $270k per year • Equity • Remote • Full-Time • 5+ years exp
AI/ML
Copilot
DevOps
GitHub
Apply
$91k – $205k per year (Estimated) • Equity • Remote • Full-Time • 7+ years exp
AI/ML
Copilot
ISO 42001
DevOps
GitHub
Cybersecurity
ISO 27001
SOC 2
GDPR
HIPAA
FedRAMP
Apply
$110k – $249k per year (Estimated) • Equity • In office • Full-Time • 7+ years exp
Apply
$100k – $350k per year • Equity • In office • Full-Time
Go
Kotlin
TypeScript
Databases
ElasticSearch
Apache Kafka
OpenSearch
AI/ML
Copilot
Edge AI
DevOps
Terraform
Azure
AWS
Docker
Kubernetes
GitHub
Apply
See all jobs
This is one of many
685,738 more open roles from verified company boards, updated every day.