---
title: "Senior Security Engineer"
company: "Kestra"
company_url: "https://www.remjobs.works/companies/kestra"
url: "https://www.remjobs.works/job/kestra-senior-security-engineer-97e8f0e0-52a1-4592-878b-bb911d32f86d"
apply_url: "https://jobs.ashbyhq.com/kestra/48a6eb68-1ff3-4947-89e5-324831c22859"
workplace: remote
location: "World"
remote_scope: "World"
employment_type: full-time
seniority: senior
role: devops-infrastructure
region: other
skills: ["aws", "docker", "gcp", "java", "javascript", "kafka", "kubernetes", "postgres", "redis", "terraform", "typescript"]
date_posted: 2026-09-18T12:11:33.443Z
first_seen_by_remjobs: 2026-09-18T12:16:18.914Z
---

# Senior Security Engineer

**Kestra** · World

Apply: https://jobs.ashbyhq.com/kestra/48a6eb68-1ff3-4947-89e5-324831c22859

## About Kestra

Use declarative language to build simpler, faster, scalable and flexible workflows

## About the role

##### About Kestra

Kestra is the **universal orchestration platform**: open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems.

Trusted by **over 10,000 organizations worldwide**, including **JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole**, Kestra orchestrates mission-critical workloads at scale. The open-source project has close to **30,000 GitHub stars**, hundreds of contributors, and a fast-growing global community.

##### About the role

We’re looking for a **Senior Security Engineer** to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem.

This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.

##### What you would do

- Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments.

- Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure.

- Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.

- Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats.

- Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.

- Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks.

- Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies.

##### Our Tech Stack

- Security & Vulnerability Tools: Trivy, GitHub Security / Dependabot, Elastic Security

- Infrastructure: Docker, Kubernetes, Terraform

- Cloud: GCP

- Programming language: Java, Typescript, Javascript

- Datastore: PostgreSQL, Elasticsearch

- Queuing: Redis, Kafka, AMQP

- Monitoring & Logs: ELK, Prometheus, Grafana

- Deployment & Repository: GitHub Actions, ArgoCD

##### What we are looking for

- 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.

- Strong hands-on penetration testing background, with proven ability to discover application, API, and network-level vulnerabilities.

- A builder/fixer mindset: You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers.

- Deep familiarity with cloud security (AWS or GCP) and containerized environments (Kubernetes, Docker).

- Experience with dependency and supply-chain security (CVE management, open-source licensing, SCA tools).

- Fluent in English and comfortable working autonomously in a fully remote environment.

- Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.

##### Perks & Benefits

- Work from anywhere: We’re a remote-first company, so you can work from wherever feels like home. Plus, you’ll have access to coworking spaces worldwide if you ever need a change of scenery.

- Health coverage: From medical support, dental, and vision, we've got you covered.

- Home office setup on us: We’ll provide all the equipment you need to work comfortably.

##### Our Hiring Process

We aim to move quickly (2-3 weeks), but we can adjust the timeline if needed.

- Technical scenario / Practical assessment (2 hours, asynchronous homework focusing on threat assessment and remediation)

- Intro call with the hiring manager (30 min)

- Team chat with one of your future colleagues (30 min)

- Final discussion with one of our co-founders (30 min)

---

Source: Kestra's own career page, read by RemJobs. Canonical HTML version: https://www.remjobs.works/job/kestra-senior-security-engineer-97e8f0e0-52a1-4592-878b-bb911d32f86d
