Security Engineer – DevSecOps and Security Architect
Core
Design and implement secure development practices, integrate security into CI/CD pipelines, and lead security reviews for web applications and APIs.
Role type
Principal Security Engineer (DevSecOps)
Builds
Secure CI/CD pipelines, threat models, secure design reviews, and secure development playbooks
Domain
Deep-tech, AI-driven simulation software for engineering and manufacturing
Deliverable
production ML models | product features | infrastructure
Required skills
DevSecOps, application security, secure coding, OWASP Top 10, threat modeling, SDLC integration, CI/CD, IaC, containerization, SAST tooling, Python, Go
Preferred skills
AI security fundamentals, cloud infrastructure security, bug bounty management, BSIMM framework, cloud-native services, identity and access management
Technologies
GitHub, GitLab, Semgrep, Snyk
Responsibilities
Architect and integrate security tooling into CI/CD pipelines; Lead threat modeling and secure design reviews; Oversee end-to-end product vulnerability lifecycle; Drive secure coding standards and mentorship; Collaborate cross-functionally to scale secure development practices; Engage with customers during security reviews
Seniority
Principal, hands-on IC with mentorship