# Lead Security Engineer

**Company:** [GoHighLevel](https://hotfix.jobs/companies/gohighlevel)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 8+ years
**Skills:** AWS, GCP, Microsoft Azure, Cloud Security, Threat Modeling, Penetration Testing, Owasp Top 10, Stride, Burp Suite, Zap, Snyk, Metasploit, Semgrep, Kubernetes, Terraform
**Posted:** 2026-03-02

> Leads cloud security architecture, penetration testing, threat modeling, and secure-by-default practices for large-scale cloud-native applications. Requires 8+ years of application, product, or cloud security experience and strong expertise across cloud platforms, containers, and security tooling.

## Job Description

## Responsibilities
- Design secure, scalable cloud environments across AWS, GCP, and Azure, focusing on identity, network security, encryption, and compliance.
- Conduct security architecture reviews for distributed systems and cloud-native applications; identify design risks and recommend secure architectural patterns.
- Lead manual and automated penetration testing across applications, APIs, and cloud services.
- Drive threat modeling and secure architecture reviews across application and infrastructure layers.
- Collaborate with Infrastructure and DevOps teams on VPC design, security groups, routing, and network segmentation.
- Design and advise on cloud-native security controls, including IAM hardening, role boundaries, secrets management, and least privilege.
- Evaluate and improve Kubernetes and container security across runtime, image, and network layers.
- Implement secure-by-default patterns across the SDLC, CI/CD, and infrastructure as code.
- Monitor emerging threats, CVEs, and vulnerabilities relevant to web, cloud, and infrastructure environments.
- Influence security tooling, automation pipelines, and security review processes.
- Advise engineering, SRE, and product teams on security for key projects.

## Requirements
- 8+ years of experience in application security, product security, or cloud security, focused on large-scale cloud-native applications.
- Strong hands-on experience with threat modeling, secure architecture reviews, and penetration testing.
- Familiarity with OWASP Top 10, STRIDE, and modern security frameworks.
- Experience with Burp Suite, ZAP, Snyk, Metasploit, and Semgrep.
- Ability to read and analyze code, such as JavaScript, Go, PHP, or Node.js.
- Working knowledge of cloud security principles, preferably AWS.

## Nice-to-Haves
- Experience with multi-tenant SaaS platforms or white-labeled architectures.
- Familiarity with VPC design, IAM, and zero-trust networks.
- Exposure to Docker and Kubernetes security.
- Background in B2B SaaS serving regulated industries such as health, legal, or finance.
- Hands-on experience with infrastructure-as-code security and CI/CD pipelines, including GitHub Actions and Terraform.

## Similar jobs

- [Senior Security Engineer](https://hotfix.jobs/jobs/2a1ede09-d608-462e-bb14-223603034206) - Greenlight - Bengaluru, India
- [Lead Security Engineer - Penetration Testing & AI Security](https://hotfix.jobs/jobs/ac8bc34d-2a43-4c67-870e-a1e01edee0cb) - GoHighLevel - Remote
- [Senior Security Engineer - DART](https://hotfix.jobs/jobs/8f733ffe-5874-43b6-9dcb-4a76ac35e099) - Rippling - Bengaluru, India
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Detection and Response Engineer](https://hotfix.jobs/jobs/ebb8ac3d-4282-4505-bdb8-4699d594df80) - Anyscale - $200k – $240k/yr

**Apply:** https://hotfix.jobs/jobs/59f364b8-53e7-4677-bfc5-9dc046e034c4
**Canonical:** https://hotfix.jobs/jobs/59f364b8-53e7-4677-bfc5-9dc046e034c4