Search Remote Jobs

Security Engineer

đŸ”„ 12 minutes ago

🌏 Anywhere in the World

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ‘źâ€â™‚ïž Cybersecurity / Security Engineer

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of CINC Systems

CINC Systems

201 - 500 employees

Founded 2005

☁ SaaS

🏠 Real Estate

đŸ€ B2B

💰 Private Equity Round - CINC Systems on 2023-12

SaaS ‱ Real Estate ‱ B2B

CINC Systems is a cloud-based, all-in-one software platform for community association management (HOAs and COAs) that helps management companies, boards, and homeowners streamline operations and improve resident experience. The platform provides financial management and oversight (including online payments and a secure payment portal), AI-driven reporting and forecasting (Cephai), communication and resident engagement tools, online voting and surveys, maintenance/work-order coordination, compliance tracking, and centralized data and insights. CINC targets professional association management firms and homeowner boards with automation, security, and scalability; the company reports 1,000+ association management company customers, 51,000+ homeowner associations served, 6M+ doors, and $11B+ payments processed annually.

📋 Description

‱ Lead security reviews for web applications, APIs, microservices, AWS workloads, internal platforms and AI-enabled products. ‱ Perform advanced application security testing using SAST, DAST, SCA, manual code review, API testing and business logic testing. ‱ Identify vulnerabilities across authentication, authorization, session management, access control, injection, SSRF, deserialization, insecure file handling, data exposure and insecure API design. ‱ Conduct threat modeling for new products, critical features, AWS architectures, AI workflows, identity systems and high-risk data flows. ‱ Build and improve secure SDLC processes, including security requirements, code scanning, dependency review, CI/CD security gates and release risk assessments. ‱ Review infrastructure-as-code templates such as Terraform, CloudFormation, AWS CDK, Helm charts and Kubernetes manifests for security misconfigurations. ‱ Assess AWS environments for IAM weaknesses, exposed services, insecure networking, public S3 buckets, secrets leakage, logging gaps, encryption issues, workload risks and privilege escalation paths. ‱ Review AWS IAM policies, roles, trust relationships, permission boundaries, service control policies, identity federation and cross-account access patterns. ‱ Assess AWS services such as EC2, S3, Lambda, ECS, EKS, RDS, API Gateway, CloudFront, WAF, KMS, Secrets Manager, Systems Manager, ECR, VPC, Route 53 and IAM Identity Center. ‱ Conduct red team exercises, adversary simulations, attack path analysis and controlled exploitation to validate real-world risk. ‱ Develop proof-of-concept exploits, custom scripts and automation to reproduce vulnerabilities and demonstrate business impact. ‱ Evaluate containerized and Kubernetes environments, including EKS, for workload isolation, RBAC issues, exposed services, image risks, secrets handling and runtime security gaps. ‱ Assess CI/CD pipelines for insecure workflows, overprivileged tokens, secrets exposure, supply chain risks, artifact integrity and deployment abuse paths. ‱ Perform software composition analysis to identify vulnerable dependencies, license risks, malicious packages, transitive dependency exposure and supply chain weaknesses. ‱ Use SIEM and security telemetry to support investigations, validate attack paths, improve detections and measure control effectiveness. ‱ Build detection logic, threat hunting queries, dashboards and alerting workflows using SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, Chronicle or AWS-native telemetry. ‱ Use AWS security services such as GuardDuty, Security Hub, CloudTrail, AWS Config, Inspector, Detective, Macie, IAM Access Analyzer, Security Lake and CloudWatch to improve visibility and detection coverage. ‱ Automate security workflows using Python, Bash, PowerShell, Go or similar scripting languages. ‱ Develop threat automation for vulnerability enrichment, alert triage, AWS posture checks, attack simulation, evidence collection and remediation tracking. ‱ Partner with DevOps and platform teams to improve secrets management, identity controls, network segmentation, logging, monitoring and secure deployment patterns. ‱ Assess AI and LLM-based systems for risks such as prompt injection, indirect prompt injection, data leakage, insecure tool use, excessive agency, jailbreaks, model abuse, retrieval poisoning and unsafe agent behavior. ‱ Review AI workloads using AWS services such as Amazon Bedrock, SageMaker, Lambda, API Gateway, S3, KMS and IAM for secure design, data protection and access control. ‱ Produce clear technical reports with evidence, exploitability, impact, likelihood, risk rating and actionable remediation guidance. ‱ Mentor engineers and security team members on secure coding, AWS security, offensive testing, threat modeling and AI security risks.

🎯 Requirements

‱ Strong hands-on experience in application security, product security, AWS cloud security, offensive security or security engineering. ‱ Deep understanding of secure SDLC practices and experience embedding security into engineering workflows. ‱ Practical experience with SAST, DAST, SCA, manual penetration testing, code review and vulnerability validation. ‱ Strong knowledge of OWASP Top 10, OWASP API Security Top 10, OWASP ASVS, common CWE classes and real-world application attack techniques. ‱ Experience testing web applications, APIs, microservices, cloud services, containers and distributed systems. ‱ Strong understanding of authentication, authorization, identity federation, OAuth, OIDC, SAML, JWT, session security and access control design. ‱ Hands-on experience securing AWS environments in production. ‱ Strong knowledge of AWS IAM, VPC networking, encryption, KMS, Secrets Manager, S3 security, CloudTrail, GuardDuty, Security Hub, AWS Config and workload hardening. ‱ Experience reviewing infrastructure-as-code and identifying security issues in Terraform, CloudFormation, AWS CDK, Kubernetes YAML, Helm, Dockerfiles or similar technologies. ‱ Experience with CI/CD security across tools such as bitbucket pipelines, Jenkins, AWS CodePipeline, or similar platforms. ‱ Experience with red teaming, adversary emulation, penetration testing, exploit development, attack path mapping or offensive security assessments. ‱ Familiarity with SIEM platforms and the ability to write detection or hunting queries using SPL, KQL, SQL, Lucene, YARA, Sigma or similar languages. ‱ Strong scripting ability in Python, Bash, PowerShell, JavaScript or similar languages. ‱ Ability to automate repetitive security tasks and build internal tools that improve security testing, visibility and response. ‱ Familiarity with container and Kubernetes security, including ECS,EKS, RBAC, admission controls, image scanning, runtime controls, network policies and secrets handling. ‱ Ability to review code in languages such as Python, JavaScript, TypeScript, Java, Go, Kotlin, C# or similar. ‱ Strong written and verbal communication skills, with the ability to explain complex technical risks to engineering and leadership teams.

đŸ–ïž Benefits

‱ Flexible work arrangements ‱ Professional development opportunities

Apply Now

Similar Jobs

🕒 July 14

NEAR Foundation

1 - 10

🔌 API

₿ Crypto

🌐 Web 3

Senior IT Security Engineer leading information security program at NEAR Foundation. Driving security engineering and compliance initiatives to protect the NEAR ecosystem.

🕒 July 11

Python Software Foundation

1 - 10

đŸ€ Non-profit

📚 Education

Security Developer coordinating vulnerabilities and malware issues for the Python Software Foundation. Collaborating with teams to enhance security practices and document threat models.

🌏 Anywhere in the World

đŸ’” $70k - $170k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ‘źâ€â™‚ïž Cybersecurity / Security Engineer

🕒 June 11

Brightidea

51 - 200

☁ SaaS

⚡ Productivity

🏱 Enterprise

Security Researcher simulating advanced adversaries against Bright Data's collection products. Engaging in R&D while influencing team direction in a fully remote role.

🌏 Anywhere in the World

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ‘źâ€â™‚ïž Cybersecurity / Security Engineer

🕒 May 27

Supabase

51 - 200

☁ SaaS

🔌 API

đŸ€– Artificial Intelligence

Product Security Engineer at Supabase focusing on integrating security in developer workflows. Collaborating with teams to enhance product security without hindering development speed.

🌏 Anywhere in the World

💰 $80M Series B on 2022-05

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ‘źâ€â™‚ïž Cybersecurity / Security Engineer

🕒 April 1

Canonical

501 - 1000

đŸ€– Artificial Intelligence

Linux Engineer enhancing security technology for Canonical’s Ubuntu. Collaborating on FIPS and CC certification while implementing security frameworks and benchmarks.

🌏 Anywhere in the World

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ‘źâ€â™‚ïž Cybersecurity / Security Engineer