Security Engineer
New
Q
QdrantAI Infrastructure
Remote-firstFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 3+ years
- Required Skills
- AWSPythonKubernetesGoRustCI/CD
Requirements
- 3+ years in a hands-on security engineering, product security, or vulnerability management role.
- Ability to read and navigate an unfamiliar codebase (Rust, Go, Python) to validate vulnerabilities.
- Proficiency in writing and maintaining automation and security tooling.
- Practical knowledge of cloud and container security, particularly AWS and Kubernetes.
- Familiarity with GitHub security features and securing CI/CD pipelines.
- Methodical approach to investigating alerts and vulnerabilities to distinguish risk from noise.
- Clear written communication skills for working with external researchers and internal teams.
- Self-directed approach and comfort independently managing a security queue.
- Experience triaging vulnerability reports or working with a bug bounty/vulnerability disclosure program.
- Offensive security background (penetration testing, CTF, vulnerability research) is a plus.
- Experience in an open-source company or contributing to open-source projects is a plus.
Responsibilities
- Run our public bug bounty program: triage reports, reproduce and validate findings, communicate clearly with security researchers, and drive remediation through to closure.
- Investigate reported vulnerabilities at the code level, including our Rust core, Go and Python tooling.
- Enable engineers to build secure systems: provide tooling, paved-road defaults, documentation, and practical guidance.
- Harden and maintain our GitHub organization’s security posture, including secret scanning, push protection, branch protection and rulesets, dependency alerts, and code scanning.
- Monitor, investigate, and respond to security alerts across AWS, Kubernetes, CI/CD, and related infrastructure.
- Track and report security metrics (vulnerability remediation SLAs, MTTR, patch latency, critical findings).
- Build security automation and guardrails that scale across the development lifecycle: CI/CD security checks, policy-as-code, GitHub automation, and automated cloud security controls.
- Participate in threat modeling and architecture reviews for new services and major changes.
View Full Description & ApplyYou'll be redirected to the employer's site