Skip to content
StarburstStarburst

Security Engineer

Build production security automation, CI/CD guardrails, and AI-assisted workflows for Starburst’s Application Security program. The role requires a strong information security foundation, software engineering ability, and 2–4 years of relevant experience.

About the job

Responsibilities

  • Build automation and tooling for the Application Security program, including AI-assisted systems that scale security work.
  • Integrate security checks into CI/CD pipelines and develop reusable guardrails and secure-by-default components.
  • Support and extend SAST, DAST, SCA, and secrets-scanning tools, routing findings to engineering teams and helping developers remediate them.
  • Prototype and productionize AI-assisted workflows for security triage, analysis, and remediation.
  • Support vulnerability management by detecting, triaging, and routing newly disclosed vulnerabilities.
  • Improve secure coding standards, documentation, and remediation playbooks.
  • Collaborate closely with Engineering and Product.

Requirements

  • Bachelor's degree in Computer Science, Engineering, MIS, or equivalent practical experience.
  • 2–4 years of experience in security engineering, software engineering, or a related technical role.
  • Strong foundation in information security fundamentals and sound security judgment.
  • Understanding of application vulnerabilities and mitigation strategies, including OWASP Top 10 and CWE.
  • Experience building automation and tooling, especially using AI to solve practical problems.
  • Experience with Python, Go, Java, or JavaScript/TypeScript; Java and Python preferred.
  • Experience with CI/CD tooling, Git-based workflows, and modern development practices.
  • Familiarity with cloud security concepts and hands-on experience with at least one cloud platform: AWS, Azure, or Google Cloud.

Nice-to-haves

  • Experience in enterprise B2B software, self-managed software, and/or SaaS.

Skills

Application Security, Owasp Top 10, Cwe, Python, Go, Java, JavaScript, TypeScript, CI/CD, Git, AWS, Azure, GCP, SAST, DAST

Q4 Inc

Q4 Inc

India

Information Security Engineer
No salary listedOn-site2+ YOESecurity Engineering

The Information Security Engineer manages security compliance programs, audit readiness, client due diligence, and security questionnaires. The role requires 2+ years of experience with SOC 2, ISO 27001, data privacy frameworks, and compliance tooling.

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Glean

Glean

Bengaluru, India

Supply Chain Security Engineer
No salary listedHybrid3+ YOESecurity Engineering

Secures Glean's software supply chain by managing vulnerabilities, hardening images, protecting open-source dependencies, and embedding trusted release controls in CI/CD. Requires 3+ years in application security or vulnerability management, strong cloud-native and container security knowledge, and experience with FedRAMP audits.

Coinbase

Coinbase

India

Specialist, CSIRT
No salary listedRemote3+ YOESecurity Engineering

Owns frontline security alert triage, incident response, detection coverage, and automation across cloud, SaaS, container, and Web3 environments. Requires at least three years of hands-on security operations experience and proficiency with scripting, SIEM platforms, and threat intelligence tooling.