> Markdown version of [/jobs/ext/2710150-security-engineer](https://www.wearedevelopers.com/jobs/ext/2710150-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Ngrok Inc. - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $218,250.0 - $266,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Amazon Web Services, Audit Trail, C++ (Programming Language), Cloud Computing Security, Code Generation, Cyber Security, Continuous Integration, Identity and Access Management, Intrusion Detection and Prevention, Large Language Models, Amazon Virtual Private Cloud (VPC), Vulnerability Analysis - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-security-engineer-ngrok-inc-9638304 ## About the Role * You've worked in a security engineering role where you shipped tooling, built automation, or owned security infrastructure - not just reviewed it * You have strong engineering fundamentals and are comfortable writing quality code in Go or Java, Rust, C, C++ * You know how to integrate security checks into CI/CD pipelines without slowing teams down * You have hands-on experience with cloud security, particularly AWS (IAM, VPC, CloudTrail, GuardDuty) * You understand AI/ML security risks like prompt injection, insecure code generation, and LLM-assisted attack vectors * Bonus Points: + You've built internal security platforms or developer-facing security tooling + You've done detection engineering - writing detection rules, tuning signals, reducing alert fatigue + You've secured networking or developer infrastructure products, All candidates must be US-based, and legally authorized to work in the United States. ## Description Security at ngrok is being built from the ground up, and this role is the foundation. ngrok sits at a uniquely sensitive position in the internet stack: traffic flows through us, and the developers and companies who rely on us trust us with that. As our first dedicated Security Engineer, you won't be inheriting a sprawling program or a backlog of someone else's decisions. You'll be defining how security works here - partnering closely with engineering, infrastructure, and leadership to build automated guardrails, opinionated defaults, and self-service tooling that scale with the team rather than slow it down. The threat landscape is shifting fast, and we want a security posture we're proud to stand behind., * Audit the current state of security tooling, pipeline coverage, cloud posture, and detection capabilities, and turn that into a prioritized security roadmap tied to ngrok's business objectives * Ship developer-facing security tooling: automated checks in CI/CD, secrets scanning, dependency vulnerability tracking, and secure-by-default libraries that make the right choice the easy choice * Run a structured risk assessment across product and infrastructure to document what we know, what we don't, and what needs to change * Establish guardrails for how we use AI in our engineering pipeline - policies and tooling that let us move fast without introducing new risk classes * Stand up baseline detection and response: log coverage, alerting, and a documented incident response process * Own the security engineering program end-to-end over time - clear ownership, documented controls, meaningful metrics, and an internal security platform (reusable libraries, self-service tooling, automation) that reduces the security burden on every engineer ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Leapter: The Reinvention of Software Development? A Future Built On AI Generated Code.](https://www.wearedevelopers.com/videos/1663-leapter-the-reinvention-of-software-development-a-future-built-on-ai-generated-code) - [GenAI Is a Junior Dev With Root Access](https://www.wearedevelopers.com/videos/100191-genai-is-a-junior-dev-with-root-access) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)