Scan your resume against ATS criteria for this Senior Security Engineer role at Kestra.
Kestra is the
Trusted by
, including
, Kestra orchestrates mission-critical workloads at scale. The open-source project has close to
, hundreds of contributors, and a fast-growing global community.
Kestra runs arbitrary, user-defined code at scale. Our users write workflows that execute scripts, containers, and queries against their own production systems, through hundreds of community-built plugins, on a platform whose entire source code is public. That is an unusually rich attack surface, and securing it is a genuinely hard engineering problem rather than a checklist exercise.
We're looking for a
to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem.
This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.
Your first six months would focus on the first three points below. The rest is where the role grows.
and threat modeling across our web application, APIs, control plane, and cloud environments.
across our codebases, software dependencies (SCA), container images, and cloud infrastructure.
by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.
(GCP, Kubernetes clusters, and networking configurations) against external and internal threats.
into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.
and evaluate third-party dependencies, open-source integrations, and supply-chain risks.
efforts and establish continuous monitoring, detection, and mitigation strategies.
as an open-source project: vulnerability disclosure process, CVE handling, security advisories, and the trust model of our plugin ecosystem.
in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.
, with proven ability to discover application, API, and network-level vulnerabilities.
(AWS or GCP) and containerized environments (
, Docker).
(CVE management, open-source licensing, SCA tools).
Fluent in English and comfortable working autonomously in a fully remote environment.
Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.
We aim to move quickly (2-3 weeks), but we can adjust the timeline if needed.
with the hiring manager (30 min)
(2 hours, asynchronous homework focusing on threat assessment and remediation)
with of your future colleagues (30 min)
with of our co-founders (30 min)
Benefits
How to apply for Senior Security Engineer at Kestra?
Click the "Apply on Company Website" button on this page to submit your application directly on the employer's official portal.
What is the salary for this role?
Salary details will be discussed during the interview.
What experience is required?
5+ years of experience is required.
Is this position still open?
Yes, currently active and accepting applications.
Explore related active roles in security
Senior Security Engineer
Kestra · Europe