Security Engineer
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-09-28
Listing for:
xbowcareers
Full Time
position Listed on 2026-09-28
Job specializations:
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Systems Engineer
Job Description & How to Apply Below
Role overview
A hands-on security engineer is needed to embed security into how a fast-moving, AI-driven organization designs, ships, and operates systems across cloud, infrastructure, and internal platforms. This is a technical individual contributor role with end-to-end ownership of preventive controls, detection quality, and response readiness, partnering closely with engineering and platform teams to remediate real production risk.
Responsibilities- Design and implement security controls across cloud, infrastructure, and internal platforms.
- Partner with engineering to harden cloud architecture, identity and access management, and infrastructure baselines.
- Own product security reviews for new features, services, and major architecture changes.
- Drive threat modeling and secure design decisions early in the software development lifecycle.
- Operate and improve application security workflows, including static analysis, software composition analysis, secrets scanning, and infrastructure-as-code scanning.
- Triage vulnerabilities across application, container, and cloud findings, and drive remediation under risk-based SLAs.
- Improve CNAPP coverage, Kubernetes and container security posture, and the organization's incident response capability through automation.
- 5+ years of experience in security engineering, product security, cloud or platform security, or closely related roles.
- Strong hands-on experience securing cloud environments, including AWS, Azure, and GCP.
- Hands-on product and application security experience, including secure design reviews, threat modeling, and code-level risk discussions.
- Experience operating application security tooling and processes at scale, including SAST, SCA, secrets scanning, and IaC scanning.
- Working knowledge of Kubernetes and container security in production systems.
- Experience with vulnerability triage, risk-based prioritization, incident response, and post-incident hardening in cloud-native environments.
- Multi-cloud experience beyond AWS, such as Azure, GCP, or OCI.
- Offensive security or pentesting background with the ability to convert findings into durable engineering fixes.
- Experience scaling security at a startup from early stage through audit-ready maturity.
- Relevant security certifications such as OSCP, OSCE, AWS Security Specialty, or Kubernetes security credentials.
- Competitive salary, meaningful equity, comprehensive benefits, and a 401k plan.
- Remote-first role with regular in-person collaboration opportunities; locations include US, Canada, and Argentina.
- Full-time contract with structured hiring process and timezone coverage expectations.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×