# Senior Security Engineer

**Company:** [Agora](https://hotfix.jobs/companies/agora)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** AWS, Kubernetes, TypeScript, Node.js, JavaScript, REST APIs, Docker, Pulumi, Argo Cd, GitOps, SAST, DAST, SIEM, Threat Modeling, Vulnerability Management
**Posted:** 2026-09-02

> The Senior Security Engineer partners with engineering teams on application, cloud, infrastructure, detection, vulnerability, and incident security. The role requires at least five years of security engineering experience, strong software review skills, and hands-on expertise across AWS, Kubernetes, CI/CD, monitoring, and incident response.

## Job Description

## Responsibilities
- Partner with Engineering and Product throughout the development lifecycle, from threat modeling and design through launch and operation.
- Review system designs, application code, APIs, infrastructure as code, cloud environments, Kubernetes workloads, deployment pipelines, and production configurations.
- Identify vulnerabilities and design weaknesses; communicate impact and drive pragmatic remediation.
- Provide security expertise across application, cloud, container, identity and access management, secrets, API, data protection, and secure software development.
- Develop reusable security guidance, secure patterns, checklists, and engineering standards.
- Administer and improve SAST, DAST, software composition analysis, container and infrastructure-as-code scanning, CSPM, AI-assisted security tools, and security monitoring.
- Integrate security controls into developer workflows and CI/CD pipelines; tune rules, reduce noise, and improve coverage.
- Define telemetry and detection requirements, implement and tune alert rules, and investigate security events.
- Work with the SOC on alert quality, escalation criteria, investigation procedures, and response runbooks.
- Participate in incident response, including investigation, containment, eradication, recovery, coordination, and evidence preservation.
- Lead post-incident reviews and implement durable improvements.
- Own vulnerability management, including intake, validation, prioritization, assignment, remediation tracking, exceptions, verification, and reporting.
- Support penetration tests, code reviews, architecture assessments, vendor evaluations, and other independent security engagements.
- Build automation and metrics to improve security visibility and reduce investigation and remediation time.
- Contribute to product security, platform security, detection engineering, vulnerability management, and incident-readiness roadmaps.

## Requirements
- 5+ years of hands-on experience in product security, application security, cloud security, or a closely related security engineering role.
- Strong software engineering fundamentals and application code review experience; TypeScript, Node.js, JavaScript, or another modern language is especially relevant.
- Experience reviewing web applications, backend services, REST APIs, authentication and authorization systems, and relational database designs.
- Practical knowledge of application and API vulnerabilities, threat modeling, secure design, and modern identity patterns.
- Experience securing AWS environments, containerized workloads, Kubernetes, infrastructure as code, and CI/CD or GitOps workflows.
- Hands-on experience with SAST, DAST, SCA, CSPM, container scanning, secrets detection, infrastructure-as-code scanning, SIEM, or cloud-native detection platforms.
- Experience developing or tuning security detections using application, cloud, identity, network, and infrastructure telemetry.
- Strong investigation skills, including log and system-activity analysis, hypothesis testing, timeline development, and scope and impact assessment.
- Experience working with a SOC, including alert escalation, investigation handoffs, runbook development, and detection-quality improvement.
- Experience participating in security incident response and coordinating with engineering and operations teams under time pressure.
- Experience operating a vulnerability management process and driving remediation across multiple engineering teams.
- Ability to evaluate findings and detections based on risk and business impact.

## Nice to Have
- Experience with TypeScript and Node.js security reviews.
- Experience with Pulumi, Argo CD, GitOps, Cloudflare, blockchain infrastructure, or AI-assisted security tooling.
- Experience supporting third-party penetration tests and independent security assessments.
- Familiarity with financial infrastructure or crypto-native environments.

## Work Arrangement
- Remote within the United States, with preference for candidates near Eastern Time and substantial overlap with Eastern Time business hours.

## Similar jobs

- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/3ac667bf-62fa-4280-8ccb-2af3468d8579) - Discord - $196k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/6852f2f8-c100-4e69-94df-f2fbba37a8d6
**Canonical:** https://hotfix.jobs/jobs/6852f2f8-c100-4e69-94df-f2fbba37a8d6