Security Engineer
Role details
Job location
Tech stack
Job description
As a Security Engineer (AppSec) reporting to the Head of Application Security, you'll be a key member of our growing security function, focusing on our product and platform security. This role combines hands-on security engineering with technical leadership, requiring someone to implement security controls and guide other engineers in secure development practices. You'll be the technical cornerstone of our product security initiatives, working to ensure our platform remains secure by design as we scale., Technical Security Leadership
-
Enhance and expand security controls across our cloud-native infrastructure.
-
Lead security architecture reviews and threat modeling sessions.
-
Develop, evolve, and implement secure coding standards and practices.
-
Extend our security automation tooling and strengthen CI / CD pipeline security.
-
Build upon our existing security testing frameworks and procedures. Application Security Implementation
-
Perform security code reviews and penetration testing of our codebases.
-
Implement security controls for our distributed systems (AWS-based).
-
Design and implement secure container runtime environments.
-
Build secure API endpoints and review API security architecture.
-
Implement supply chain security controls and verification systems. Security Engineering & Architecture
-
Enhance our security monitoring solutions using DataDog, AWS Security Hub, etc.
-
Strengthen our secure deployment pipelines using CircleCI and GitHub Actions.
-
Drive implementation of our secure artifact storage and processing systems.
-
Design and implement additional customer and environment isolation controls.
-
Develop security automation tools and frameworks and apply them.
-
Partner with the Head of AppSec + CTO on security architecture decisions. Security Culture & Education
-
Provide security guidance and mentorship to engineering teams.
-
Develop and deliver security training materials.
-
Create security documentation and guidelines.
-
Participate in security incident response.
-
Contribute to security policies and standards. Team Collaboration
-
Work closely with the Head of AppSec + CTO to implement security strategies.
-
Collaborate with engineering teams to embed security practices.
-
Support security audit and compliance initiatives.
-
Participate in security incident response as a technical lead (incl. red / blue team).
-
Help evaluate and implement new security tools and technologies.
-
Automate everything, write code (if you want to!), and make proofs ('sploits)., This role offers the chance to enhance security in a platform already trusted by organizations worldwide for software supply chain security. You'll join an ISO 27001-certified organization and work with cutting-edge technologies, implementing security controls that protect critical infrastructure. From startups to Fortune 500 customers, your work will directly impact how organizations secure their software supply chains while helping us maintain our position as the most trusted name in artifact management.
Requirements
-
3+ years of security engineering experience or equivalent.
-
Deep expertise in application security and secure software development.
-
Experience with implementing SAST, DAST, and RASP (Runtime Security).
-
Strong programming skills in Python, with familiarity in TypeScript / Node.js or similar.
-
Extensive experience with : Cloud security (AWS-based, preferably).
-
Web application security.
-
API security (REST or GraphQL, etc.).
-
Infrastructure as Code security.
-
CI / CD pipeline security.
-
Container security (Docker, OCI).
-
Database security. Security Engineering Skills
-
Experience building security tools and automation.
-
Strong background in threat modeling and risk assessment.
-
Expertise in penetration testing and vulnerability assessment.
-
Knowledge of cryptography and secure communication protocols.
-
Experience with security monitoring and incident response. Domain Knowledge
-
Understanding of software supply chain security.
-
Experience with artifact management systems.
-
Knowledge of modern development practices and tools.
-
Familiarity with compliance frameworks (ISO 27001, SOC2). Bonus Points
-
Experience with : Data enclave implementations.
-
Secure runtime environments (Firecracker, gVisor).
-
Software Composition Analysis.
-
Contributions to open-source security tools.
-
Security-focused certifications (OSCP, CSSLP, etc.).
-
Experience securing package management systems. Cultural Values We're Looking For
-
Technical Mastery : Demonstrate deep security expertise and engineering craftsmanship.
-
Security Innovation : Drive automated, cloud-native security solutions to excellence.
-
Knowledge Champion : Share security expertise openly and mentor engineering teams.
-
Pragmatic Builder : Deliver practical security solutions with customer needs in mind.
-
Continuous Growth : Actively expand security knowledge and embrace sustainable practices.
Benefits & conditions
Note : You must be based in Ireland or the United Kingdom and have the right to work independently without requiring sponsorship. Headlines
- A remote-first position based in Ireland or the United Kingdom.
- A competitive compensation package, including equity.
- With comprehensive health, dental, and vision insurance.
- Plus, generous annual leave and flexible working policies to suit your lifestyle.
- Including a professional development budget for conferences and training.
- In a dynamic, innovative, trust-centric, and supportive work environment.
- With the opportunity to shape a fast-growing Series A startup (and beyond).
- Regular (monthly-ish) travel may be required for team meetings.
- Regular (quarterly-ish) travel may also be required for events and customers.