> Markdown version of [/jobs/ext/239155-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/239155-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Beyond Inc. - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $140,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Build Automation, Cloud Computing Security, Code Review, Continuous Integration, Data Deduplication, DevOps, Github, Identity and Access Management, Mobile Application Software, Python (Programming Language), Key Management, Network Segmentation, OpenID, Open Web Application Security, Ruby on Rails, Ruby, Zero Trust Network Access, Secure Coding, Software Vulnerability Management, Data Logging, Software Security, Kubernetes, Cloudflare, Codebase, React Native, Terraform, Software Version Control, Docker, Static Application Security Testing, Golang, Programming Languages, Dynamic Application Security Testing - **Published:** May 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=761a6479135ea3ac ## About the Role Do you have experience in Vulnerability management?, * 5+ years of hands-on security engineering experience across cloud security and/or application security, with demonstrated depth in at least one. * Strong AWS security background, including IAM, networking, container orchestration (ECS, EKS, or Kubernetes), and logging and audit. Hands-on experience with Wiz CNAPP. * Hands-on experience operating a WAF in production, including writing and tuning rules, managing false positives, and responding when something gets through. * Experience securing CI/CD pipelines and Infrastructure as Code, with Terraform required. * Working knowledge of OWASP Top 10, secure code review, SAST/DAST/SCA tooling, and threat modeling. * Experience running or substantially contributing to a vulnerability management program. * Proficiency in at least one programming language used in modern application stacks, such as Python, Go, or Ruby. * Operates independently and drives projects without day-to-day oversight., * Experience with the tools we use day to day: Wiz, Cloudflare (WAF, Gateway, Zero Trust), GitHub Advanced Security, Spacelift, and AWS-native security services such as GuardDuty, Security Hub, Macie, and Inspector. * Container and orchestration security depth across Docker, Kubernetes, and ECS/EKS. * Familiarity with AI/ML security risks such as prompt injection, data poisoning, and model abuse, and the controls that mitigate them. * Experience with secrets management platforms such as AWS Secrets Manager, Keeper, and/or Infisical. * Identity security across human and non-human identities, including service accounts, API keys, and OIDC federation. * Experience in a PCI-regulated environment or financial services. * Familiarity with Ruby on Rails, Python, or Go. ## Description You'll partner with DevOps, Engineering, and our Application Security Engineer to build preventative controls across infrastructure, identity, CI/CD, and applications. The work is hands-on: configuring tooling, writing and tuning detection and blocking rules, reviewing architecture, hardening pipelines, and supporting application security work where your range is needed., * Operate and tune our WAF, including managed and custom rule sets, rate limiting, bot mitigation, and the day-to-day work of keeping false positives low. * Own cloud security posture across our AWS environment using a CSPM or CNAPP platform alongside AWS-native security services. * Reduce risk across IAM, network segmentation, ECS and container security, secrets management, and data exposure. * Establish secure defaults in our Infrastructure as Code through reusable modules, guardrails, and policy as code. * Harden CI/CD pipelines and the secrets that flow through them in partnership with DevOps. * Build controls the SOC can monitor and respond to, and document the runbooks for the systems you own. Application Security * Operate and tune SAST, SCA, and Secret Scanning tooling integrated with our source control. * Partner with our Application Security Engineer on code reviews and threat modeling across our Ruby on Rails, React Native, Python, and Go codebases. * Mobile App Security (iOS and Android) Vulnerability Management * Run our vulnerability management program across cloud and application findings: intake, prioritization, SLA tracking, and reporting. * Partner with engineering teams to drive remediation, advising on fixes and unblocking the work where you can. * Build automation that scales the program - pipelines for ingestion, deduplication, prioritization logic, and developer-facing workflows. AI Security * Contribute to our growing AI security program, including controls for AI-assisted development tooling, secure use of AI in our products, and emerging risks like prompt injection. ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)