> Markdown version of [/jobs/ext/2120322-security-software-engineer](https://www.wearedevelopers.com/jobs/ext/2120322-security-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Software Engineer - **Company:** HOVER Inc. - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $165,000.0 - $239,000.0 - **Contract:** Permanent contract - **Skills:** C++ (Programming Language), Cloud Computing, Cloud Engineering, Code Review, Cyber Security, Continuous Integration, Identity and Access Management, Python (Programming Language), Machine Learning, Systems Development Life Cycle, Role-Based Access Control, Ruby, Secure Coding, Software Engineering, TypeScript, Google Cloud, Build Management, Kubernetes, Machine Learning Operations, Terraform, Docker, Static Application Security Testing, Vulnerability Analysis - **Published:** August 19, 2026 - **Apply:** https://hover.to/job-posts/8003885 ## About the Role * 5+ years of hands-on software engineering experience. * 3+ years of hands-on security-focused engineering experience. * Proficient in at least one programming language (Ruby, TypeScript, Python, C++, etc.) and willingness to ramp up in others. * Experience building scalable security systems (e.g., secret management, service authorization, data encryption) in a production environment. * Experience with threat modeling, security design reviews, or security incident response. * Experience integrating security directly into the software development lifecycle (SDLC). * Meticulous attention to detail; able to be the final checkpoint on security decisions. * Excellent communication and collaboration skills for cross-team interactions. * Ability to mentor and train engineers on secure development processes. * A proactive approach to continuous learning and staying current with emerging security trends. ## Description As a Security Software Engineer, you will build foundational security systems that protect our users and infrastructure. You will design and implement robust, scalable security services, acting as a primary partner for engineering teams to build secure-by-design solutions into our platform. You will take ownership of core functions such as authentication (login, MFA), identity management (SCIM, RBAC), secret management, and more. Your work will be crucial in maintaining and hardening compliance (e.g., SOC 2) and protecting sensitive data across our organization. The Team: The Infrastructure and Security team at Hover ensures the scalability, reliability, and security of our platform, empowering engineers to build and deploy applications faster, safer, and with greater stability. This collaborative team is composed of engineers with expertise in cloud infrastructure, security, automation, and CI/CD best practices. We handle everything from Kubernetes environments and cloud architecture to securing user authentication and automating vulnerability detection. Our mission is to make the best path the easiest path by providing robust automation, consistent patterns, and secure-by-design principles. We partner with engineering teams to tackle challenges like managing rich geospatial and machine learning workloads, hardening cloud infrastructure, and implementing security features across our stack (Ruby, TypeScript, Docker, GCP, Terraform, and more). Team members are supported with professional growth opportunities, a strong focus on learning, and a culture that values collaboration, innovation, and the continuous improvement of our systems and security posture. Join us to work on cutting-edge challenges that are critical to the foundation of Hover's success. You will contribute by * Security Service Development: Design and build core security services (e.g., permissions management, secrets orchestration, secure MLOps). Develop secure-by-default libraries and frameworks that empower other engineering teams to write secure code. * Security Infrastructure Automation: Enhance our CI/CD pipeline with automated self-serve security controls (e.g. SAST, supply chain security controls) * Architecture & Code Review: Conduct secure code and architecture reviews, enforce secure-by-design principles, and lead threat modeling. * System Hardening: Build and maintain resilient cloud infrastructure. Implement network isolation, automated vulnerability detection, and defense-in-depth strategies to harden our production environment. * Compliance & Process: Run security incident response, document risks, and support audits. * Collaboration & Education: Advise teams on security best practices, identify and solve for developer security friction points, and bring security awareness to engineering. ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)