CareerScanCareerScan
JobsCompanies
BlogContact
For Employers
Sign InRegister Free
CareerScanCareerScan

India's verified job platform connecting candidates directly with employers. 100% free applications with instant ATS resume scoring.

Chennai, Bengaluru & Hyderabad
Jobs by location
Jobs in ChennaiJobs in BengaluruJobs in HyderabadJobs in PuneJobs in Mumbai
Popular roles
AR Caller JobsHealthcare Medical CodingReact / Full Stack DeveloperData & Power BI AnalystCustomer Support Executive
Top companies
TCS CareersCognizant JobsInfosys OpeningsApollo HospitalsOmega Healthcare
Career services
Free ATS Resume CheckerAI Resume Builder (Free)AI Job MatcherSalary Guide & BenchmarksJob Alerts on WhatsApp
© 2026 CareerScan India. All rights reserved.256-bit SSL encrypted & verified
Back to all jobs
  1. Home
  2. Jobs
  3. Senior Security Engineer
K
Kestra

Senior Security Engineer

Europe
5+ years exp
Full-time
Posted 3d ago
0 views
Actively Hiring Urgent Opening Direct 1-Click Apply

Check Your Resume Match Score

Scan your resume against ATS criteria for this Senior Security Engineer role at Kestra.

Apply for this position

Apply on Company Website
Notice a broken link or wrong info?

Job Description

About Kestra

Kestra is the

  • universal orchestration platform: open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems.

Trusted by

over 10,000 organizations worldwide

, including

JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole

, Kestra orchestrates mission-critical workloads at scale. The open-source project has close to

30,000 GitHub stars

, hundreds of contributors, and a fast-growing global community.

About the role

Kestra runs arbitrary, user-defined code at scale. Our users write workflows that execute scripts, containers, and queries against their own production systems, through hundreds of community-built plugins, on a platform whose entire source code is public. That is an unusually rich attack surface, and securing it is a genuinely hard engineering problem rather than a checklist exercise.

You would be our first dedicated security hire.

We're looking for a

Senior Security Engineer

to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem.
This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.

This is a hands-on engineering role, not a GRC or compliance.

What you would do

Your first six months would focus on the first three points below. The rest is where the role grows.

Conduct hands-on penetration testing

and threat modeling across our web application, APIs, control plane, and cloud environments.

Manage end-to-end vulnerability tracking

across our codebases, software dependencies (SCA), container images, and cloud infrastructure.

Proactively fix security flaws

by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.

Audit and harden our cloud infrastructure

(GCP, Kubernetes clusters, and networking configurations) against external and internal threats.

Automate security tooling

into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.

Perform security code reviews

and evaluate third-party dependencies, open-source integrations, and supply-chain risks.

Lead incident response

efforts and establish continuous monitoring, detection, and mitigation strategies.

Own our public security posture

as an open-source project: vulnerability disclosure process, CVE handling, security advisories, and the trust model of our plugin ecosystem.

Our Tech Stack

  • Security & Vulnerability Tools: Trivy, GitHub Security / Dependabot, Elastic Security
  • Infrastructure: Docker, Kubernetes, Terraform
  • Cloud: GCP
  • Programming language: Java, Typescript, Javascript
  • Datastore: PostgreSQL, Elasticsearch
  • Queuing: Redis, Kafka, AMQP
  • Monitoring & Logs: ELK, Prometheus, Grafana
  • Deployment & Repository: GitHub Actions, ArgoCD

What we are looking for

5+ years of experience

in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.

Strong hands-on penetration testing background

, with proven ability to discover application, API, and network-level vulnerabilities.

  • A builder/fixer mindset: You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers.

Deep familiarity with cloud security

(AWS or GCP) and containerized environments (

Kubernetes

, Docker).

  • Experience with

dependency and supply-chain security

(CVE management, open-source licensing, SCA tools).

  • Fluent in English and comfortable working autonomously in a fully remote environment.

  • Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.

Perks & Benefits

  • Work from anywhere: We’re a remote-first company, so you can work from wherever feels like home. Plus, you’ll have access to coworking spaces worldwide if you ever need a change of scenery.
  • Health coverage: From medical support, dental, and vision, we've got you covered.
  • Home office setup on us: We’ll provide all the equipment you need to work comfortably.

 

Our Hiring Process

We aim to move quickly (2-3 weeks), but we can adjust the timeline if needed.

Intro call

with the hiring manager (30 min)

Technical scenario / Practical assessment

(2 hours, asynchronous homework focusing on threat assessment and remediation)

Team chat

with of your future colleagues (30 min)

Final discussion

with of our co-founders (30 min)

Benefits & Perks

Benefits

  • Work from anywhere: We’re a remote-first company, so you can work from wherever feels like home. Plus, you’ll have access to coworking spaces worldwide if you ever need a change of scenery.

Frequently Asked Questions

How to apply for Senior Security Engineer at Kestra?

Click the "Apply on Company Website" button on this page to submit your application directly on the employer's official portal.

What is the salary for this role?

Salary details will be discussed during the interview.

What experience is required?

5+ years of experience is required.

Is this position still open?

Yes, currently active and accepting applications.

ApplicationActively Hiring
Apply on Company Website
Broken link or expired?
K

Kestra

More jobs at Kestra

Senior Business Development Representative

United States

Senior Field Engineer, France

France

Account Executive

Germany

Share this Opening

Job Alerts for security

Receive email alerts whenever new security roles in Europe are posted.

Set Free Alert →

Similar Openings

Explore related active roles in security

View all
UrgentActively Hiring
Doppel
Product Security
Doppel Verified
7+ years
₹12.1L – ₹13.8L/mo
US Remote
securityFull-timeRemote
Posted 1d ago
Apply Now
UrgentActively Hiring
Immersivelabs
Solutions Consultant (Cyber Security) - Portugal
Immersivelabs Verified
2+ years
₹1,245/mo
Portugal
securityFull-time
Posted 1d ago
Apply Now
UrgentActively Hiring
Teciem
Job Role – IAM and PAM Security Lead
Teciem Verified
8+ years
Salary not disclosed
TCMi - Bengaluru
securityFull-time
Posted 1d ago
Apply Now

Senior Security Engineer

Kestra · Europe

Apply on Company Website