Senior Security Engineer
Kestra Technologies- Location
- World
- Workplace
- Remote
- Employment
- Full Time
- Salary
- —
Posted today
About Kestra
Kestra is the universal orchestration platform
open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems.
Trusted by over 10,000 organizations worldwide, including JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole, Kestra orchestrates mission-critical workloads at scale. The open-source project has close to 30,000 GitHub stars, hundreds of contributors, and a fast-growing global community.
About the role
We’re looking for a Senior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem.
This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.
What you would do
- Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments.
- Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure.
- Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.
- Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats.
- Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.
- Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks.
- Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies.
Our Tech Stack
- Security & Vulnerability Tools: Trivy, GitHub Security / Dependabot, Elastic Security
- Infrastructure: Docker, Kubernetes, Terraform
- Cloud: GCP
- Programming language: Java, Typescript, Javascript
- Datastore: PostgreSQL, Elasticsearch
- Queuing: Redis, Kafka, AMQP
- Monitoring & Logs: ELK, Prometheus, Grafana
- Deployment & Repository: GitHub Actions, ArgoCD
What we are looking for
- 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.
- Strong hands-on penetration testing background, with proven ability to discover application, API, and network-level vulnerabilities.
- A builder/fixer mindset: You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers.
- Deep familiarity with cloud security (AWS or GCP) and containerized environments (Kubernetes, Docker).
- Experience with dependency and supply-chain security (CVE management, open-source licensing, SCA tools).
- Fluent in English and comfortable working autonomously in a fully remote environment.
- Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.
Perks & Benefits
- Work from anywhere: We’re a remote-first company, so you can work from wherever feels like home. Plus, you’ll have access to coworking spaces worldwide if you ever need a change of scenery.
- Health coverage: From medical support, dental, and vision, we've got you covered.
- Home office setup on us: We’ll provide all the equipment you need to work comfortably.
Our Hiring Process
We aim to move quickly (2-3 weeks), but we can adjust the timeline if needed.
- Technical scenario / Practical assessment (2 hours, asynchronous homework focusing on threat assessment and remediation)
- Intro call with the hiring manager (30 min)
- Team chat with one of your future colleagues (30 min)
- Final discussion with one of our co-founders (30 min)
Skills
- GitHub
- SCA
- GCP
- Kubernetes
- SAST
- DAST
- Trivy
- Dependabot
- Elastic
- Docker
- Terraform
- Java
- TypeScript
- JavaScript
- PostgreSQL
- Elasticsearch
- Redis
- Kafka
- AMQP
- ELK Stack
- Prometheus
- Grafana
- GitHub Actions
- Argo CD
- AWS
More jobs at Kestra Technologies
All 7Full Stack Engineer, Data Orchestration
Kestra Technologies · Europe · 1mo ago
Product Manager, Data Orchestration
Kestra Technologies · Europe · 1mo ago
QA Engineer
Kestra Technologies · Europe · 1mo ago
Senior DevOps Engineer
Kestra Technologies · Europe · 2mo ago
Product Manager, AI
Kestra Technologies · Europe · 2mo ago
Similar roles
NS-ECCOS_Cyber Security Analyst I Journeyman
NETSEA Technologies · Schriever SFB, Colorado, United States · Peterson SFB, Colorado, United States · Colorado Springs, Colorado, United States · today
NS-ECCOS_Cyber Security Analyst II VM Senior
NETSEA Technologies · Schriever SFB, Colorado, United States · Colorado Springs, Colorado, United States · Peterson SFB, Colorado, United States · today
Information Systems Security Engineer (6836)
MetroStar · Reston, VA · Washington, DC · today
Manager (Functional Team Lead)
Saliense · United States · USD 110,000–124,000/yr · today
Information Security Manager
Orcrist Technologies · Berlin · today
Security (f/m/d) Billionaire Dinner Show
Kempinski Hotels · St. Moritz, Switzerland · today