Senior Security Engineer
Leads security architecture and defense capabilities for a high-performance API gateway across hybrid and multi-cloud environments. The role requires 5+ years of cybersecurity engineering experience, expertise in WAF/IDS/IPS and Kubernetes security, and proficiency in Python, Go, or Rust.
About the job
Responsibilities
- Serve as the technical security lead for securing Kong Cloud and its API gateway.
- Architect and implement next-generation WAF, IDS, and IPS capabilities at the gateway level.
- Protect against OWASP Top 10 threats, zero-day exploits, and sophisticated API abuse.
- Design and implement Zero Trust security models across hybrid and multi-cloud environments, including AWS, Azure, GCP, and on-premises infrastructure.
- Partner with Product and Architecture leads to define the multi-year security roadmap for Kong Gateway.
- Balance the needs of the open-source community with enterprise requirements.
- Lead responses to complex security challenges, including supply-chain vulnerabilities in open-source dependencies and CVE remediation.
- Mentor engineers on secure coding practices and promote a security-first culture.
Requirements
- 5+ years of experience in cybersecurity engineering, focused on high-traffic infrastructure or API management.
- Expert-level knowledge of multi-cloud solution design, including securing traffic across cloud providers and Kubernetes environments.
- Experience designing and deploying WAF, IDS, and IPS systems at scale.
- Understanding of signature-based and machine-learning-based detection.
- Programming proficiency in Python, Go, or Rust.
- Ability to produce high-quality, high-performance security designs without compromising millisecond-level gateway latency.
Nice to Have
- Experience contributing to or maintaining open-source security projects.
Skills
Waf, Ids, Ips, Zero Trust, AWS, Microsoft Azure, GCP, Kubernetes, Python, Go, Rust, Owasp Top 10, Api Security, Open Source, Cve Remediation