> Markdown version of [/jobs/ext/2723137-lead-security-engineer](https://www.wearedevelopers.com/jobs/ext/2723137-lead-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - **Company:** CIRCLE, INC. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Applicant Tracking Systems, Software System Penetration Testing, Build Automation, Microsoft Azure, Cloud Computing Security, Cyber Security, Continuous Integration, Python (Programming Language), Open Web Application Security, Secure Coding, Security Information and Event Management, Software Vulnerability Management, Large Language Models, Software Security, GWAPT, Kubernetes, Cortex XSOAR Platform, Splunk, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Golang, Microservices, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/lead-security-engineer-260-circles-life-asia-techno-8732922 ## About the Role * 10-12 years of hands-on experience in Application Security and Security Engineering * Demonstrated, hands-on strength in: + Threat modeling and secure architecture review + Microservice architecture + Penetration testing[Web, API, Mobile] and vulnerability management + SAST, DAST, SCA, Containers, IaC including container/Kubernetes workload security.. + Software supply-chain security + SOC operations and incident response + DevSecOps and CI/CD security integration + Python (or equivalent) scripting for security automation * Solid working knowledge of the OWASP Top 10, OWASP API Security Top 10, secure coding practices, and cloud security fundamentals * Capability to identify AI-specific vulnerabilities such as prompt injection, data poisoning, system prompt leakage, and insecure output handling. * Ability to read and understand code to identify vulnerabilities; proficiency in Java or Go (Golang) is a strong plus. * Strong communicator, able to influence engineering teams on remediation priority and translate technical risk into terms executives act on, * Certifications: OSCP, OSWE, GWAPT, GPEN, CISSP, or equivalent * Experience securing AWS, Azure, or GCP environments, and Kubernetes/container workloads * Hands-on experience with SIEM/SOAR platforms (e.g., Splunk, Sentinel, XSOAR, or similar) * Familiarity with security maturity frameworks: OWASP SAMM, BSIMM, or NIST CSF * Exposure to securing AI/LLM implementations ## Description We're looking for a hands-on Lead Security Engineer to strengthen our security posture across applications, APIs, cloud infrastructure, and engineering platforms. This IC role owns secure architecture, application security, penetration testing, SOC incident response, and security automation - partnering closely with Engineering, DevOps, and Product to embed security throughout the SDLC rather than bolt it on at the end., * Lead threat modeling (STRIDE, PASTA, or equivalent) for new applications, features, and major platform changes * Conduct security architecture reviews for applications, APIs, cloud infrastructure, and third-party services before go-live * Define secure design patterns and reference architectures; provide hands-on security guidance at every stage of the SDLC, not just at release gates, * Integrate security testing natively into CI/CD pipelines and DevSecOps workflows so findings surface before merge, not after deploy * Assess REST and GraphQL APIs against the OWASP API Security Top 10 (broken object/function-level authorization, excessive data exposure, rate limiting, business logic abuse) * Partner with engineering leads to prioritize findings by exploitability and business impact, and drive remediation within agreed SLAs, * Plan and execute internal penetration tests across web applications, APIs, cloud, and infrastructure; scope and oversee external pen test engagements * Manually validate findings to separate real risk from noise before they reach engineering backlogs * Own the vulnerability management lifecycle - from discovery through remediation to verified closure - and continuously tighten SLAs as maturity improves, * Serve as a technical escalation point for security incidents; lead or support incident response - triage, containment, root cause analysis, and post-incident reviews * Improve detection and response capability through SIEM/SOAR rule tuning, informed directly by incident and threat intelligence learnings * Close the loop between offensive findings (pen test, threat model) and detective controls (SIEM/SOAR), so known risks are also monitored, not just documented, * Build automation in Python (or equivalent) for security scanning, findings de-duplication, ticketing, and reporting workflows * Integrate security tooling across CI/CD and SOC operations to eliminate repetitive manual work and shorten detection-to-remediation time * Treat automation as a core deliverable, not a side project - every recurring manual security task is a candidate for a pipeline ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Retooling and refactoring - an investment in people.](https://www.wearedevelopers.com/videos/371-retooling-and-refactoring-an-investment-in-people) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)