- Location
- United States
- Workplace
- Remote
- Employment
- Full time
- Level
- Mid level
- Posted
- Last week
About this role
Your Role: Security Engineer
We're looking for an experienced, hands-on Security Engineer to secure XBOW's product, cloud, and platform as we scale. This is a technical individual contributor role focused on building security into how we design, ship, and operate systems.
You'll work closely with engineering and platform teams across application security, cloud security, vulnerability management, and incident response. The core of this role is security engineering ownership: improving preventive controls, detection quality, and response readiness, while driving remediation of real risks in production.
What You'll Do:
Design and implement security controls across cloud, infrastructure, and internal platforms
Partner with engineering to harden cloud architecture, IAM, and infrastructure
Own product security reviews for new features, services, and major architecture changes
Drive threat modeling and secure design decisions early in the SDLC
Operate and improve AppSec workflows (SAST, SCA, secrets scanning, IaC scanning)
Triage vulnerabilities across application, container, and cloud findings, and drive remediation with risk-based SLAs
Define and run the vulnerability management lifecycle: intake, prioritization, exception handling, validation, and reporting
Improve CNAPP coverage and finding quality across cloud accounts and workloads
Improve Kubernetes and container security posture
Monitor, investigate, and respond to security events and incidents
Build automation to improve security operations, access workflows, and incident response
Support the wider teams by providing timezone coverage for our fully remote organization.
Who You Are:
Essential-
5+ years of experience in security engineering, product security, cloud/platform security, or closely related roles
Strong hands-on experience securing cloud environments (AWS, Azure and GCP)
Comfortable owning technical security problems end-to-end in fast-moving environments
Hands-on experience with product/application security in engineering environments (secure design reviews, threat modeling, code-level risk discussions)
Experience operating AppSec tooling and processes at scale (SAST, SCA, secrets, IaC scanning)
Strong vulnerability triage and remediation management experience, including risk-based prioritization and SLAs
Experience with CNAPP (or equivalent cloud security platforms) and tuning findings for engineering actionability
Working knowledge of Kubernetes/container security in production systems
Ability to partner with developers and platform teams to ship secure defaults without blocking delivery
Comfortable writing scripts and automations to improve security reliability and scale
Experience in incident response, investigation, and post-incident hardening in cloud-native environments
Security-minded, detail-oriented, and a proactive communicator in remote-first teams
Advantageous-
Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI)
Offensive security/pentesting background and ability to convert findings into durable engineering fixes
Experience scaling security at a startup from early stage to audit-ready maturity
Relevant security certifications (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certs)
What We Offer:
Compensation & Equity: Competitive salary, meaningful stock options, comprehensive benefits and 401k plan
Growth: Opportunity to learn from and collaborate with top security and AI experts
Impact: Work on complex technical challenges that support the foundation of our company
Remote-First:Work from anywhere, with regular opportunities to meet in person
What Else You Should Know:
• Location: Remote: US, Canada, Argentina. All team members are remote but we meet regularly and you're supported to travel to collaborate with colleagues in person
• Contract: Full-time.
Hiring Process:
30-min introductory chat with your Talent Partner
30 minutes with the Hiring Manager.
1 hour technical deep dive.
30 minutes with the Deputy CISO
30-min final meeting with our CISO
We're a security company that builds with AI at the core - so you'll be protecting a team that moves fast, iterates aggressively, and lives in the command line. If that sounds like your kind of environment, let's talk.
As published by XBOW. Applications are handled on their site.
Skills this posting mentions
About XBOW
XBOW is the autonomous offensive security company redefining cyber defense for the AI era. Combining AI reasoning with offensive security workflows, the XBOW platform delivers expert-level security testing at machine speed. XBOW empowers security teams to transform from reactive to proactive defense at AI scale. For XBOW customers, autonomous offense is the best defense.
All 8 openings at XBOWOne click, then it is written
Apply to XBOW with a resume written for this role.
Queue Security Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in XBOW’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at XBOW
See all- 6 days ago
- 2 weeks ago
- 2 weeks ago
Information Security Analyst, GRC
Any Europe where Remote.com can hire, European UnionRemote
$65k - $160k/yrMid levelEngineering - 3 weeks ago
- 5 months ago
Software Engineer - Platform / Core Infrastructure - EMEA
Any Europe where Remote.com can hire, European UnionRemote
$100k - $350k/yrMid levelEngineering - 6 months ago
Similar roles elsewhere
See more- Today
Senior FullStack Engineer - Grafana Cloud Observability| US | Remote
Grafana LabsUnited States (Remote)Remote
$154k/yrSeniorEngineering - Today
Senior Staff Engineer, Guest & Host (Host Listings & Quality)
AirbnbUnited States
$248k - $310k/yrStaffEngineering - Today
Engineering Manager, Guest & Host (Host Listings & Quality)
AirbnbUnited States
$212k - $265k/yrManagerEngineering - Today
Staff Android Engineer, Pick & Deliver
InstacartUnited States - RemoteRemote
$254k - $280k/yrStaffEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board XBOW publishes. Refolk is not the employer and does not handle their hiring. Applications go to XBOW directly.