Lead Security Engineer
CIRCLE, INC.
United States
1 day ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on startup.jobs
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source
Tech stack
Java (Programming Language)
Application Programming Interfaces (APIs)
Artificial Intelligence
Amazon Web Services
Applicant Tracking Systems
Software System Penetration Testing
Build Automation
Microsoft Azure
Cloud Computing Security
Cyber Security
Continuous Integration
Python (Programming Language)
+17 more
Open Web Application Security
Secure Coding
Security Information and Event Management
Software Vulnerability Management
Large Language Models
Software Security
GWAPT
Kubernetes
Cortex XSOAR Platform
Splunk
Devsecops
Security Orchestration, Automation & Response
Static Application Security Testing
Vulnerability Analysis
Golang
Microservices
Dynamic Application Security Testing
Job description
We’re looking for a hands-on Lead Security Engineer to strengthen our security posture across applications, APIs, cloud infrastructure, and engineering platforms. This IC role owns secure architecture, application security, penetration testing, SOC incident response, and security automation - partnering closely with Engineering, DevOps, and Product to embed security throughout the SDLC rather than bolt it on at the end., * Lead threat modeling (STRIDE, PASTA, or equivalent) for new applications, features, and major platform changes
- Conduct security architecture reviews for applications, APIs, cloud infrastructure, and third-party services before go-live
- Define secure design patterns and reference architectures; provide hands-on security guidance at every stage of the SDLC, not just at release gates, * Integrate security testing natively into CI/CD pipelines and DevSecOps workflows so findings surface before merge, not after deploy
- Assess REST and GraphQL APIs against the OWASP API Security Top 10 (broken object/function-level authorization, excessive data exposure, rate limiting, business logic abuse)
- Partner with engineering leads to prioritize findings by exploitability and business impact, and drive remediation within agreed SLAs, * Plan and execute internal penetration tests across web applications, APIs, cloud, and infrastructure; scope and oversee external pen test engagements
- Manually validate findings to separate real risk from noise before they reach engineering backlogs
- Own the vulnerability management lifecycle - from discovery through remediation to verified closure - and continuously tighten SLAs as maturity improves, * Serve as a technical escalation point for security incidents; lead or support incident response - triage, containment, root cause analysis, and post-incident reviews
- Improve detection and response capability through SIEM/SOAR rule tuning, informed directly by incident and threat intelligence learnings
- Close the loop between offensive findings (pen test, threat model) and detective controls (SIEM/SOAR), so known risks are also monitored, not just documented, * Build automation in Python (or equivalent) for security scanning, findings de-duplication, ticketing, and reporting workflows
- Integrate security tooling across CI/CD and SOC operations to eliminate repetitive manual work and shorten detection-to-remediation time
- Treat automation as a core deliverable, not a side project - every recurring manual security task is a candidate for a pipeline
Requirements
- 10-12 years of hands-on experience in Application Security and Security Engineering
- Demonstrated, hands-on strength in:
- Threat modeling and secure architecture review
- Microservice architecture
- Penetration testing[Web, API, Mobile] and vulnerability management
- SAST, DAST, SCA, Containers, IaC including container/Kubernetes workload security..
- Software supply-chain security
- SOC operations and incident response
- DevSecOps and CI/CD security integration
- Python (or equivalent) scripting for security automation
- Solid working knowledge of the OWASP Top 10, OWASP API Security Top 10, secure coding practices, and cloud security fundamentals
- Capability to identify AI-specific vulnerabilities such as prompt injection, data poisoning, system prompt leakage, and insecure output handling.
- Ability to read and understand code to identify vulnerabilities; proficiency in Java or Go (Golang) is a strong plus.
- Strong communicator, able to influence engineering teams on remediation priority and translate technical risk into terms executives act on, * Certifications: OSCP, OSWE, GWAPT, GPEN, CISSP, or equivalent
- Experience securing AWS, Azure, or GCP environments, and Kubernetes/container workloads
- Hands-on experience with SIEM/SOAR platforms (e.g., Splunk, Sentinel, XSOAR, or similar)
- Familiarity with security maturity frameworks: OWASP SAMM, BSIMM, or NIST CSF
- Exposure to securing AI/LLM implementations
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on startup.jobs
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
7 months ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
24 days ago
LM
Luis Minvielle
Why Upskilling And Reskilling is Important For Developers
over 2 years ago