NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in United States of America
2 days ago
Apply with autofill
Apply with autofill
Xbowcareers·2 days ago
2 days ago

Security Engineer

US remoteFull-timeRemoteMid · 5+ yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at xbowcareers

How you compare FREE

?
Your scoreYour score: not yet known
→
49
Top 10%Top 10%: 49 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in United States.

Must-have skills for this role

  • aws
  • threat modeling
  • incident response
  • vulnerability management

PDF or DOCX · no account needed

Apply faster with autofill FREExbowcareers uses Ashby - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Design and implement security controls across cloud, infrastructure, and internal platforms
  • Partner with engineering to harden cloud architecture, IAM, and infrastructure
  • Own product security reviews for new features, services, and major architecture changes
  • Drive threat modeling and secure design decisions early in the SDLC
  • Operate and improve AppSec workflows (SAST, SCA, secrets scanning, IaC scanning)
  • Triage vulnerabilities across application, container, and cloud findings, and drive remediation with risk-based SLAs
  • Define and run the vulnerability management lifecycle: intake, prioritization, exception handling, validation, and reporting
  • Improve CNAPP coverage and finding quality across cloud accounts and workloads
  • Improve Kubernetes and container security posture
  • Monitor, investigate, and respond to security events and incidents
  • Build automation to improve security operations, access workflows, and incident response
  • Support the wider teams by providing timezone coverage for our fully remote organization.

What they're looking for

  • 5+ years of experience in security engineering, product security, cloud/platform security, or closely related roles
  • Strong hands-on experience securing cloud environments (AWS, Azure and GCP)
  • Comfortable owning technical security problems end-to-end in fast-moving environments
  • Hands-on experience with product/application security in engineering environments (secure design reviews, threat modeling, code-level risk discussions)
  • Experience operating AppSec tooling and processes at scale (SAST, SCA, secrets, IaC scanning)
  • Strong vulnerability triage and remediation management experience, including risk-based prioritization and SLAs
  • Experience with CNAPP (or equivalent cloud security platforms) and tuning findings for engineering actionability
  • Working knowledge of Kubernetes/container security in production systems
  • Ability to partner with developers and platform teams to ship secure defaults without blocking delivery
  • Comfortable writing scripts and automations to improve security reliability and scale
  • Experience in incident response, investigation, and post-incident hardening in cloud-native environments
  • Security-minded, detail-oriented, and a proactive communicator in remote-first teams

Nice to have

  • Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI)
  • Offensive security/pentesting background and ability to convert findings into durable engineering fixes
  • Experience scaling security at a startup from early stage to audit-ready maturity
  • Relevant security certifications (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certs)

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Your Role: Security Engineer

We're looking for an experienced, hands-on Security Engineer to secure XBOW's product, cloud, and platform as we scale. This is a technical individual contributor role focused on building security into how we design, ship, and operate systems.

You'll work closely with engineering and platform teams across application security, cloud security, vulnerability management, and incident response. The core of this role is security engineering ownership: improving preventive controls, detection quality, and response readiness, while driving remediation of real risks in production.

What You'll Do:

  • Design and implement security controls across cloud, infrastructure, and internal platforms

  • Partner with engineering to harden cloud architecture, IAM, and infrastructure

  • Own product security reviews for new features, services, and major architecture changes

  • Drive threat modeling and secure design decisions early in the SDLC

  • Operate and improve AppSec workflows (SAST, SCA, secrets scanning, IaC scanning)

  • Triage vulnerabilities across application, container, and cloud findings, and drive remediation with risk-based SLAs

  • Define and run the vulnerability management lifecycle: intake, prioritization, exception handling, validation, and reporting

  • Improve CNAPP coverage and finding quality across cloud accounts and workloads

  • Improve Kubernetes and container security posture

  • Monitor, investigate, and respond to security events and incidents

  • Build automation to improve security operations, access workflows, and incident response

  • Support the wider teams by providing timezone coverage for our fully remote organization.

Who You Are:

Essential-

  • 5+ years of experience in security engineering, product security, cloud/platform security, or closely related roles

  • Strong hands-on experience securing cloud environments (AWS, Azure and GCP)

  • Comfortable owning technical security problems end-to-end in fast-moving environments

  • Hands-on experience with product/application security in engineering environments (secure design reviews, threat modeling, code-level risk discussions)

  • Experience operating AppSec tooling and processes at scale (SAST, SCA, secrets, IaC scanning)

  • Strong vulnerability triage and remediation management experience, including risk-based prioritization and SLAs

  • Experience with CNAPP (or equivalent cloud security platforms) and tuning findings for engineering actionability

  • Working knowledge of Kubernetes/container security in production systems

  • Ability to partner with developers and platform teams to ship secure defaults without blocking delivery

  • Comfortable writing scripts and automations to improve security reliability and scale

  • Experience in incident response, investigation, and post-incident hardening in cloud-native environments

  • Security-minded, detail-oriented, and a proactive communicator in remote-first teams

Advantageous-

  • Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI)

  • Offensive security/pentesting background and ability to convert findings into durable engineering fixes

  • Experience scaling security at a startup from early stage to audit-ready maturity

  • Relevant security certifications (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certs)

What We Offer:

  • Compensation & Equity: Competitive salary, meaningful stock options, comprehensive benefits and 401k plan

  • Growth: Opportunity to learn from and collaborate with top security and AI experts

  • Impact: Work on complex technical challenges that support the foundation of our company

  • Remote-First:Work from anywhere, with regular opportunities to meet in person

What Else You Should Know:

• Location: Remote: US, Canada, Argentina. All team members are remote but we meet regularly and you're supported to travel to collaborate with colleagues in person

• Contract: Full-time.

Hiring Process:

30-min introductory chat with your Talent Partner

30 minutes with the Hiring Manager.

1 hour technical deep dive.

30 minutes with the Deputy CISO

30-min final meeting with our CISO

We're a security company that builds with AI at the core — so you'll be protecting a team that moves fast, iterates aggressively, and lives in the command line. If that sounds like your kind of environment, let's talk.

Company

Xbowcareers
US remote

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Xbowcareers's careers site·first seen 18 Sept 2026·last verified 18 Sept 2026·How we source jobs

Similar jobs

  • Staff Security Engineer at robotsandpencilsUS - Remote–match not yet calculated
  • IT Security Engineer at zollChelmsford, United States of America–match not yet calculated
  • Cybersecurity Summer 2027 Intern (Undergraduate) at centeneRemote-MO–match not yet calculated
  • AI Security Engineer at trimbleUS - Remote, CO–match not yet calculated
  • Medical Device Cybersecurity Co-Op at Johnson & JohnsonDanvers, United States of America–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United States
  • Security Analyst jobs in United States
  • Cloud Security Engineer jobs in United States
  • Penetration Tester jobs in United States
  • Security Engineer jobs in India
  • Security Engineer jobs in United Kingdom