> Markdown version of [/jobs/ext/2383457-security-engineer](https://www.wearedevelopers.com/jobs/ext/2383457-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Kamis Professional Staffing, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cloud Engineering, Continuous Integration, Software Debugging, Cryptographic Protocols, Intrusion Detection and Prevention, Network Configuration and Change Management, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Security Software, Software Deployment, Software Engineering, Stemming, Systems Integration, Software Security, Technical Debt, Containerization, Tenable Nessus, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=829e65236f0e3346 ## About the Role * Hands-on Engineering Depth: You have 5-8+ years of experience in an Application Security or Security Engineering role. You don't just know how to run security scanners; you know how to read code, identify architectural flaws, and write the necessary fixes or scripts to resolve them. * Dependency & Legacy Management: Proven experience managing technical debt, identifying out-of-life or legacy code paths, and safely updating third-party libraries/dependencies without breaking production features. * Documentation & Collaboration Focus: Excellent written skills with a knack for building clean security playbooks. You enjoy working side-by-side with developers, pairing to debug technical issues, and assisting teams in pushing code fixes over the finish line. * Modern Tooling & Environments: Familiarity with cloud-native architectures, containerized applications, CI/CD integrations, and configuring automated security testing systems (SAST/DAST/SCA). * Proactive Problem Solving: You possess a strong builder mindset. When a security weakness is exposed, you don't just pass off a ticket-you enjoy digging into the architecture to implement lasting infrastructure or code-level safeguards. * Application Security Fundamentals: Exposure to application security fundamentals, specifically with OWASP, is required or preferred. * Network & Deployment: Experience with network configuration and application deployment is preferred. ## Description As a Security Engineer at Kami, you won't just be identifying risks and writing reports-you will be the one actively fixing them. We are expanding our in-house security team and need a hands-on engineer who thrives on pure engineering remediation. In this role, you will leverage our automated security tools, scanning platforms, and risk/vulnerability processes to pinpoint faults and defects across our systems and applications. Instead of just passing off a ticket, you will jump directly into the codebase to patch those vulnerabilities, refactor out-of-life or legacy code, upgrade outdated libraries and dependencies to ensure our environment is secure and modernized. You will act as a core technical resource for the broader engineering team, writing clear security documentation and playbooks, and actively assisting and guiding developers to successfully remediate defects within their own workflows. You will be the ultimate bridge between automated threat detection and active engineering execution, embedding robust security guardrails directly into our software development life cycle. If you are a builder who loves deep, code-level troubleshooting, enjoys replacing stale legacy infrastructure with secure code, and wants to protect a platform supporting over 50 million global users, this is the perfect place to make a massive impact. What You'll Do Vulnerability & Legacy Code Remediation * Utilize automated scanners and internal risk processes to hunt down defects. Actively dive into code bases to update outdated libraries, rewrite out-of-life legacy components, and resolve critical technical debt. * Ensure continuous modernization of Kami's codebase by wiping out vulnerabilities stemming from deprecated packages and old dependencies before they can be exploited. Developer Support & Cross-Team Guidance * Collaborate actively with engineering pods, reviewing their security posture and directly assisting them in troubleshooting and executing defect remediation. * Accelerate internal security engineering cycles by clearing remediation blockers for engineering teams, turning security into a supportive peer function. Security Documentation & Playbooks * Draft comprehensive, easy-to-follow security playbooks, coding standards guidelines, and remediation documentation for internal distribution. Create a standardized knowledge base that upskills the entire engineering group on modern secure coding practices and streamlined defect fixing. * Secure SDLC Integration * Embed automated security scanning tools, analysis processes, and proactive guardrails cleanly inside the active software development lifecycle. * Ensure systematic and early-stage identification of technical faults across applications, moving toward a continuous 'shift-left' security model. Infrastructure Hardening * Implement and maintain robust cloud infrastructure protections, including customized firewalls, intrusion detection mechanisms, and advanced encryption protocols. * Preserve the absolute structural integrity of our global digital infrastructure, securely partitioning and safeguarding core assets. Incident Response Automation * Manage and execute the emergency incident response lifecycle, building automated logic to spot, flag, and contain system anomalies instantly. * Deliver rapid technical resolution timelines during active security incidents, significantly minimizing structural exposure or system downtime. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Multilingual NLP pipeline up and running from scratch](https://www.wearedevelopers.com/videos/901-multilingual-nlp-pipeline-up-and-running-from-scratch) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Software Engineer Career: Things You Should Know](https://www.wearedevelopers.com/magazine/143-software-engineer-career-things-you-should-know) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023)