Senior Security Engineer

Rise Technical Recruitment Ltd
Wilmington, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$220,000.0 - $260,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Cloud Computing Continuous Integration Github Identity and Access Management Python (Programming Language) OAuth Open Source Technology Open Web Application Security AI Infrastructure Delivery Pipeline Large Language Models
+6 more
Software Security Adobe Docker Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Are you a security generalist who genuinely enjoys the craft outside of work, through CTFs, vulnerability research, or independent experimentation? Do you have the depth to manually audit production Python code and work directly with engineers to close what you find, rather than just filing a report and moving on?

This is an opportunity to join a fast-growing, profitable startup at the forefront of AI infrastructure, building the compliance and reliability layer that enterprise customers like Adobe, Netflix, and NASA depend on in production. They’re profitable, with 8-figure ARR and you’d be joining them with seed-level equity ahead of a Series A raise.

Backed by top-tier investors, the team has built the world’s most widely used LLM Gateway, a unified platform that gives developers secure, scalable access to every major LLM provider. Now, they’re looking for their first Security Engineer to help secure the application, infrastructure, and software-delivery pipeline behind it.

As a hands-on security generalist, you’ll spend most of your time reviewing and hardening the Python codebase, identifying new attack surfaces, and making secure development practices part of how the team builds, alongside owning security across IT, CI/CD, cloud infrastructure, and the software supply chain.

If you’re looking for a role where deep security expertise directly shapes how an open-source product used by enterprises around the world gets built, whilst benefiting from strong equity in an already profitable company before they raise their Series A, this is an outstanding opportunity., * Conduct deep security reviews of the Python proxy, APIs, authentication systems, and enterprise features

  • Identify and remediate vulnerabilities across authentication, authorization, secrets, tenant isolation, and injection
  • Build application-security tooling into the dev lifecycle, including SAST, DAST, and dependency scanning
  • Perform internal red teaming against APIs, proxy, and LLM-specific attack surfaces
  • Harden Docker images, PyPI packages, GitHub Actions workflows, and release infrastructure
  • Lead security incident response, vulnerability assessment, and remediation

Requirements

  • Strong security generalist across application security, IT, CI/CD, cloud, and supply chain
  • Deep application-security expertise, including manually auditing production Python code
  • Experience at an early-stage security startup during its 0?1 journey
  • Strong grasp of OAuth2, JWT, mTLS, IAM, and high-throughput API authentication
  • Familiarity with prompt injection, LLM data exfiltration, and the OWASP Top 10 for LLM Applications
  • CTF, bug bounty, or independent vulnerability research background

Benefits & conditions

4.04.0 out of 5 stars Remote $220,000 - $260,000 a year, Pulled from the full job description

  • 401(k), The salary advertised is the bracket available for this position. The actual salary paid will be dependent on your level of experience, qualifications and skill set and will be decided by our client, the employer. Rise are not responsible or liable for any hiring decisions made by the end client.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:17 min

Eco-friendly factory operations and generative AI image errors

Chris Heilmann +1 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all