Lead Security Engineer
Core
Lead security engineering and penetration testing for a high-scale SaaS platform handling billions of API hits and microservices.
Role type
Lead Security Engineer (Application Security & Penetration Testing)
Builds
Secure cloud-native architecture, automated security tooling, and hardened SaaS infrastructure for global agencies and businesses.
Domain
Cloud Security, Application Security, Penetration Testing
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing (manual & automated), Threat modeling, Secure architecture reviews, Cloud security (AWS), Container security (Kubernetes/Docker), IaC security, CI/CD security, Code analysis (JS/Go/PHP/Node.js), Security frameworks (OWASP, STRIDE)
Preferred skills
Multi-tenant SaaS experience, Zero-trust network design, Regulated industry background (health/legal/finance), GitHub Actions, Terraform
Technologies
AWS, Kubernetes, Docker, Burp Suite, ZAP, Snyk, Metasploit, Semgrep, Terraform, GitHub Actions
Responsibilities
Perform and lead manual and automated penetration testing across applications, APIs, and cloud services; Drive threat modeling and secure architecture reviews; Collaborate on cloud network architecture (VPC, security groups, routing); Design and advise on cloud-native security controls (IAM, secrets management); Evaluate and improve Kubernetes and container security posture; Influence internal security tooling and automation pipelines; Serve as a security advisor to engineering and product teams.
Seniority
Senior, hands-on IC with leadership responsibilities