Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Kestra

Senior Security Engineer

Kestra

. Conduct hands-on penetration testing and threat modeling across the web application, APIs, control plane, and cloud environments .

Posted 9/18/2026full-timeRemoteSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in penetration testing, vulnerability management, and cloud security, with a strong focus on automating security processes within CI/CD pipelines. Proficient in incident response and risk evaluation, particularly in containerized environments and third-party dependencies.

Highest-signal resume keywords
Penetration TestingCloud Security (AWS or GCP)KubernetesVulnerability ManagementSecurity Code Review

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Penetration TestingVulnerability TrackingSecurity PatchingSAST AutomationDAST AutomationDependency ScanningIncident ResponseThreat ModelingCVE ManagementOpen-Source Licensing
Soft Skills
AdaptabilityAutonomyCollaboration
Tools & Technologies
GCPKubernetesDockerCI/CD PipelinesSCA Tools
Industry Keywords
DevSecOpsOffensive SecurityDefensive SecuritySupply-Chain Security

Tech Stack

Tools & technologies
AWSCloudDockerGoogle Cloud PlatformKubernetes

About the role

Key responsibilities & impact
  • Conduct hands-on penetration testing and threat modeling across the web application, APIs, control plane, and cloud environments
  • Manage end-to-end vulnerability tracking across codebases, software dependencies, container images, and cloud infrastructure
  • Fix security flaws by writing patches, submitting pull requests, or collaborating with product teams on remediation
  • Audit and harden GCP, Kubernetes clusters, and networking configurations
  • Automate SAST, DAST, and dependency scanners into CI/CD pipelines
  • Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks
  • Lead incident response and establish continuous monitoring, detection, and mitigation strategies

Requirements

What you’ll need
  • 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role
  • Strong hands-on penetration testing background, with proven ability to discover application, API, and network-level vulnerabilities
  • Ability to read code, understand exploits, write fixes, or provide clear remediation steps to engineers
  • Deep familiarity with cloud security (AWS or GCP) and containerized environments (Kubernetes, Docker)
  • Experience with dependency and supply-chain security, CVE management, open-source licensing, and SCA tools
  • Fluent in English
  • Comfortable working autonomously in a fully remote environment
  • Adaptability to a fast-paced open-source startup environment

Benefits

Comp & perks
  • Work from anywhere
  • Access to coworking spaces worldwide
  • Medical, dental, and vision coverage
  • Home office equipment provided