> Markdown version of [/jobs/ext/3250115-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/3250115-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Kestra Technologies - **Location:** Villeneuve-d'Ascq, France (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Advanced Message Queuing Protocol, Software System Penetration Testing, Software as a Service, Cloud Computing, Cloud Computing Security, Code Review, Data Stores, Elasticsearch, Github, PostgreSQL, Network Control, Open Source Technology, Redis, Prometheus, Tripwire, TypeScript, Web Applications, Google Cloud, Cloud Platform System, Grafana, Software Security, Containerization, Kubernetes, Apache Kafka, Terraform, Devsecops, Docker, Static Application Security Testing, Programming Languages, Dynamic Application Security Testing - **Published:** September 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e9cd993b51222b72 ## About the Role * 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role. * Strong hands-on penetration testing background, with proven ability to discover application, API, and network-level vulnerabilities. * A builder/fixer mindset: You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers. * Deep familiarity with cloud security (AWS or GCP) and containerized environments (Kubernetes, Docker). * Experience with dependency and supply-chain security (CVE management, open-source licensing, SCA tools). * Fluent in English and comfortable working autonomously in a fully remote environment. * Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter. ## Description Kestra runs arbitrary, user-defined code at scale. Our users write workflows that execute scripts, containers, and queries against their own production systems, through hundreds of community-built plugins, on a platform whose entire source code is public. That is an unusually rich attack surface, and securing it is a genuinely hard engineering problem rather than a checklist exercise. You would be our first dedicated security hire. We're looking for a Senior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem. This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you. This is a hands-on engineering role, not a GRC or compliance one., Your first six months would focus on the first three points below. The rest is where the role grows. * Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments. * Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure. * Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation. * Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats. * Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production. * Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks. * Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies. * Own our public security posture as an open-source project: vulnerability disclosure process, CVE handling, security advisories, and the trust model of our plugin ecosystem. Our Tech Stack * Security & Vulnerability Tools: Trivy, GitHub Security / Dependabot, Elastic Security * Infrastructure: Docker, Kubernetes, Terraform * Cloud: GCP * Programming language: Java, Typescript, Javascript * Datastore: PostgreSQL, Elasticsearch * Queuing: Redis, Kafka, AMQP * Monitoring & Logs: ELK, Prometheus, Grafana * Deployment & Repository: GitHub Actions, ArgoCD ## Related Videos - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Accelerating Authentication Architecture: Taking Passwordless to the Next Level](https://www.wearedevelopers.com/videos/733-accelerating-authentication-architecture-taking-passwordless-to-the-next-level) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)