> Markdown version of [/jobs/ext/115576-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/115576-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Ngrok Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $234,000.0 - $286,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Amazon Web Services, Audit Trail, C++ (Programming Language), Cloud Computing Security, Code Generation, Cyber Security, Continuous Integration, Identity and Access Management, Intrusion Detection and Prevention, Large Language Models, Amazon Virtual Private Cloud (VPC), Virtual Private Clouds, Vulnerability Analysis - **Published:** May 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c7a2995d1c2ff6d3 ## About the Role Do you have experience in Virtual Private Clouds?, * You've worked in a security engineering role where you shipped tooling, built automation, or owned security infrastructure - not just reviewed it * You have strong engineering fundamentals and are comfortable writing quality code in Go or Java, Rust, C, C++ * You know how to integrate security checks into CI/CD pipelines without slowing teams down * You have hands-on experience with cloud security, particularly AWS (IAM, VPC, CloudTrail, GuardDuty) * You understand AI/ML security risks like prompt injection, insecure code generation, and LLM-assisted attack vectors * Bonus Points: + You've built internal security platforms or developer-facing security tooling + You've done detection engineering - writing detection rules, tuning signals, reducing alert fatigue + You've secured networking or developer infrastructure products, All candidates must be US-based, and legally authorized to work in the United States. ## Description Security at ngrok is being built from the ground up, and this role is the foundation. ngrok sits at a uniquely sensitive position in the internet stack: traffic flows through us, and the developers and companies who rely on us trust us with that. As our first dedicated Security Engineer, you won't be inheriting a sprawling program or a backlog of someone else's decisions. You'll be defining how security works here - partnering closely with engineering, infrastructure, and leadership to build automated guardrails, opinionated defaults, and self-service tooling that scale with the team rather than slow it down. The threat landscape is shifting fast, and we want a security posture we're proud to stand behind., * Audit the current state of security tooling, pipeline coverage, cloud posture, and detection capabilities, and turn that into a prioritized security roadmap tied to ngrok's business objectives * Ship developer-facing security tooling: automated checks in CI/CD, secrets scanning, dependency vulnerability tracking, and secure-by-default libraries that make the right choice the easy choice * Run a structured risk assessment across product and infrastructure to document what we know, what we don't, and what needs to change * Establish guardrails for how we use AI in our engineering pipeline - policies and tooling that let us move fast without introducing new risk classes * Stand up baseline detection and response: log coverage, alerting, and a documented incident response process * Own the security engineering program end-to-end over time - clear ownership, documented controls, meaningful metrics, and an internal security platform (reusable libraries, self-service tooling, automation) that reduces the security burden on every engineer, This is a remote position for candidates outside of the Bay Area and a hybrid role for candidates within commuting distance to San Francisco. Our Bay Area employees commute to the office on Tuesdays and Wednesdays. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Leapter: The Reinvention of Software Development? A Future Built On AI Generated Code.](https://www.wearedevelopers.com/videos/1663-leapter-the-reinvention-of-software-development-a-future-built-on-ai-generated-code) - [GenAI Is a Junior Dev With Root Access](https://www.wearedevelopers.com/videos/100191-genai-is-a-junior-dev-with-root-access) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)