> Markdown version of [/jobs/ext/2714494-security-engineer](https://www.wearedevelopers.com/jobs/ext/2714494-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Nova Ltd. - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Advanced Business Application Programming (ABAP), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Software as a Service, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, Identity and Access Management, Key Management, OAuth, Red Team (Cyber Security), Security Assertion Markup Language (SAML), SAP (Applications), SAP Project System, Enterprise Software Applications, Delivery Pipeline, Software Security, AI Platforms, Free and Open-Source Software, Vulnerability Analysis - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-security-engineer-nova-intelligence-8120047 ## About the Role * You have deep, hands-on security experience - application security, cloud security (AWS in particular), identity and access management, and the architectural intuition to spot a privilege escalation path two systems away. * You think adversarially by default, whether your background is offensive (red team, pentest, vulnerability research) or defensive engineering at a place that took it seriously. * You have informed opinions on AI security: prompt injection, agent action boundaries, tool-use vulnerabilities, sandbox escape, and what changes when agents have persistent infrastructure access. * You're fluent in the compliance frameworks customers care about (SOC 2, ISO 27001, GDPR, CCPA) - not as the goal, but as a baseline you can drive efficiently before building well past it. * You communicate clearly with both engineers and executives. Half this job is making security real with platform engineers; the other half is being credible to a CISO who needs to defend our platform internally. * You have a track record of public technical output - writing, talks, CVEs, open-source contributions. (Strong plus, not required.) Background we'd love to see (none required) * 5+ years of security engineering, security architecture, or offensive security work * Hands-on AWS security depth (IAM, KMS, networking, multi-account architectures) * Designing or hardening multi-tenant SaaS platforms in enterprise contexts * Leading SOC 2 Type II, ISO 27001, or comparable certification efforts * Familiarity with SAP, ABAP, or enterprise application security generally * Working directly with enterprise customer security teams (CISOs, DPOs, security architects) ## Description We're hiring Senior Security Engineers to design, harden, and continuously test the security of the Nova platform. Our mission is to build the most powerful AI platform for SAP - and that includes being the most secure. Nova operates inside the systems that run global business, with broad access and powerful capabilities; the security work is technically deep and central to the product. What you'll do Own platform security architecture. You'll harden the security model of the platform across cloud and (in the future) on-prem deployments - isolation between customers and environments, identity and access policy, secrets and key management, and network controls. You'll work on real problems like preventing cross-service privilege paths, evolving customer-side audit access, maintaining tight scoping of admin credentials, and ensuring the agent's execution sandboxes can run untrusted code safely. Lead our internal red team. You'll lead and extend our red team work - probing access controls and privilege boundaries, testing agent action boundaries (prompt injection, tool-use abuse, sandbox escape), validating tenant isolation under realistic attack patterns, and stress-testing our auth flows under adversarial pressure. Solve hard auth and identity problems in SAP. SAP's identity model is idiosyncratic and the customer landscape is complex: federated SSO via IAS or other IdPs, SAML and OAuth flows across multiple systems, RFC connections, technical users, and a long tail of legacy auth patterns. You'll own how identity propagates from the customer's IdP through Nova into their SAP systems. Raise our internal security baseline. SSO, deployment pipelines, secrets in CI/CD, code review controls, vendor onboarding, internal access. You'll set the standards, drive the implementation, and lead Nova's adherence to the compliance frameworks customers expect (SOC 2, ISO 27001, GDPR, CCPA). We treat these as the floor, not the ceiling. Partner with customer security teams. Our enterprise customers run some of the most sophisticated security organizations in the world. You'll be the technical voice in the room with their CISOs, security architects, and DPOs - translating their requirements into platform changes and Nova's design into language their teams can defend internally. Push the frontier on offensive and defensive AI for SAP. AI agents are uniquely powerful for security work in SAP - finding vulnerabilities in custom ABAP, auditing access patterns, identifying privilege escalation paths in customer landscapes. We use Nova to help customers find weaknesses in their own systems, and we use Nova to study Nova. You'll lead this research and shape it into product. Represent Nova on security in the SAP community. Write, speak, publish. Security at the AI-meets-SAP intersection is uncharted territory, and there's real work to do in defining the field. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [This App Reached 10,000 Users in One Week. Here's How.](https://www.wearedevelopers.com/videos/100329-this-app-reached-10-000-users-in-one-week-here-s-how) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)