> Markdown version of [/jobs/ext/1900112-security-engineer](https://www.wearedevelopers.com/jobs/ext/1900112-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Censys, Inc. - **Location:** Ann Arbor, MI, United States (Remote available) - **Experience:** Expert - **Salary:** $198,000.0 - $233,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Application Firewall, Bash Shell, Static Program Analysis, Code Review, Cyber Security, Computer Networks, Information Leak Prevention, DDoS Mitigation, Github, Monitoring of Systems, Python (Programming Language), Systems Development Life Cycle, Reliability Engineering, Cloud Services, Tensorflow, Prometheus, Systems Integration, Google Cloud, Pytorch, Delivery Pipeline, Grafana, Software Security, Mitre Att&ck, Kubernetes, Machine Learning Operations, Terraform, Data Pipelines, Devsecops, Vulnerability Analysis - **Published:** August 1, 2026 - **Apply:** https://www.dice.com/job-detail/4b20721e-05a1-4573-8b1e-5e66dd44bb83 ## About the Role * 10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles, with a track record of leading security initiatives that span multiple teams * Deep expertise securing Kubernetes environments, including container images, network policies, and supply chain protections (e.g., Helm, Crossplane) * Strong experience with Application Security tooling - dependency scanning, static analysis, and policy enforcement - integrated into CI/CD pipelines such as GitHub Actions and ArgoCD, and the ability to bridge engineering practices with Security Operations * Strong understanding of attacker tactics, techniques, and procedures (TTPs), and familiarity with frameworks like MITRE ATT&CK * Strong grasp of cloud services (Google Cloud Platform preferred), especially securing data pipelines, model hosting endpoints, and related infrastructure * Proficiency with Infrastructure-as-Code (Terraform, Crossplane, or similar) and security scanning for cloud resources * Proficiency with scripting and automation (e.g., Python, Bash) * The ability to thoughtfully participate in technical discussions and drive towards data-driven decisions amidst ambiguity and competing priorities * Strong communication skills and empathy for developer needs, with a demonstrated ability to embed secure practices without creating friction, * Experience building or scaling an AppSec or DevSecOps program from early maturity, including establishing paved roads and measuring adoption * Familiarity with commercial security platforms such as Orca Security (CNAPP/cloud security posture) and Aikido Security (application security scanning) is a plus * Experience securing ML toolchains (e.g., TensorFlow, PyTorch) and familiarity with AI-specific threats such as data leakage, model inversion, prompt injection, and adversarial inputs * Hands-on experience integrating and managing Web Application Firewalls (WAF), anti-DDoS systems, and edge protection technologies * Familiarity with monitoring and observability systems (e.g., Prometheus, Grafana, OpenTelemetry) with a focus on detecting security anomalies * Familiarity with AI governance and compliance standards (e.g., EU AI Act, NIST AI Risk Management Framework) * Strong interest in harnessing AI and LLM tools as a force multiplier - using them to code smarter, iterate faster, boosting productivity and enhancing product capabilities ## Description * Own and drive the AppSec/DevSecOps program roadmap across engineering, defining the strategy for embedding security into the SDLC through shift-left practices, paved roads, and automation rather than gates * Design, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform (Google Cloud Platform), including support for AI/ML workloads * Lead the integration of security into CI/CD pipelines - code scanning, secret detection, software composition analysis, and infrastructure policy enforcement - partnering with engineering teams to adopt them without friction * Deliver capabilities such as hardened service templates, secure service catalogs, and guardrails that reduce developer cognitive load and risk across the organization * Set the security architecture direction for AI/ML workflows, implementing controls around model training, deployment, and inference pipelines, including access control, artifact validation, input/output sanitization, and model provenance tracking * Partner with CorpSec on company security and compliance initiatives, owning the engineering side of the requirements by designing and implementing controls for SOC 2 and ISO27001 audit readiness, as well as improving tooling around BCDR, infrastructure policies, and service inventory accuracy * Provide technical leadership and mentorship, raising the security bar through design reviews, threat modeling, and pragmatic guidance to engineers across all teams * Participate in a shared on-call rotation with the Infrastructure and SRE teams, supporting production uptime and security incident response readiness, To ensure the integrity of our hiring process and facilitate a more personal connection, we require all candidates to keep their cameras on during video interviews. Additionally, if hired, we would love to bring you to our HQ in Ann Arbor for in-person onboarding., Pursuant to the California Consumer Privacy Act (CCPA), we are providing you with notice that we collect personal information from job applicants for business purposes, including evaluating your candidacy for employment, conducting interviews, and, if applicable, completing the hiring process. The categories of information we may collect include identifiers (such as name and contact information), professional or employment-related information (such as work history, education, and references), and other information you provide in your application. We do not sell or share your personal information. For more information on how we use and protect your personal information, and your rights under the CCPA, please refer to our Privacy Policy. ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [5 steps for running a Kubernetes environment at scale](https://www.wearedevelopers.com/videos/88-5-steps-for-running-a-kubernetes-environment-at-scale) - [Photonic Computing: Programming a New Class of AI Accelerators (incl. Live Coding)](https://www.wearedevelopers.com/videos/100196-photonic-computing-programming-a-new-class-of-ai-accelerators-incl-live-coding) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)