> Markdown version of [/jobs/ext/1507507-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/1507507-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Rise Technical Recruitment Ltd - **Location:** Wilmington, United States (Remote available) - **Experience:** Expert - **Salary:** $220,000.0 - $260,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Cloud Computing, Continuous Integration, Github, Identity and Access Management, Python (Programming Language), OAuth, Open Source Technology, Open Web Application Security, AI Infrastructure, Delivery Pipeline, Large Language Models, Software Security, Adobe, Docker, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1cbb06fabfa8f2ff ## About the Role * Strong security generalist across application security, IT, CI/CD, cloud, and supply chain * Deep application-security expertise, including manually auditing production Python code * Experience at an early-stage security startup during its 0?1 journey * Strong grasp of OAuth2, JWT, mTLS, IAM, and high-throughput API authentication * Familiarity with prompt injection, LLM data exfiltration, and the OWASP Top 10 for LLM Applications * CTF, bug bounty, or independent vulnerability research background ## Description Are you a security generalist who genuinely enjoys the craft outside of work, through CTFs, vulnerability research, or independent experimentation? Do you have the depth to manually audit production Python code and work directly with engineers to close what you find, rather than just filing a report and moving on? This is an opportunity to join a fast-growing, profitable startup at the forefront of AI infrastructure, building the compliance and reliability layer that enterprise customers like Adobe, Netflix, and NASA depend on in production. They're profitable, with 8-figure ARR and you'd be joining them with seed-level equity ahead of a Series A raise. Backed by top-tier investors, the team has built the world's most widely used LLM Gateway, a unified platform that gives developers secure, scalable access to every major LLM provider. Now, they're looking for their first Security Engineer to help secure the application, infrastructure, and software-delivery pipeline behind it. As a hands-on security generalist, you'll spend most of your time reviewing and hardening the Python codebase, identifying new attack surfaces, and making secure development practices part of how the team builds, alongside owning security across IT, CI/CD, cloud infrastructure, and the software supply chain. If you're looking for a role where deep security expertise directly shapes how an open-source product used by enterprises around the world gets built, whilst benefiting from strong equity in an already profitable company before they raise their Series A, this is an outstanding opportunity., * Conduct deep security reviews of the Python proxy, APIs, authentication systems, and enterprise features * Identify and remediate vulnerabilities across authentication, authorization, secrets, tenant isolation, and injection * Build application-security tooling into the dev lifecycle, including SAST, DAST, and dependency scanning * Perform internal red teaming against APIs, proxy, and LLM-specific attack surfaces * Harden Docker images, PyPI packages, GitHub Actions workflows, and release infrastructure * Lead security incident response, vulnerability assessment, and remediation ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [3x Performance: A Humbling Journey](https://www.wearedevelopers.com/videos/100165-3x-performance-a-humbling-journey) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)