Security Engineer
Summary
A remote Security Engineer role focusing on cloud (AWS), application, and AI security, embedding controls, integrating security tools into pipelines, hardening environments, automating tasks, and remediating vulnerabilities.
This is a remote position.
Strengthen cloud, application, and AI security by embedding practical controls across infrastructure, delivery pipelines, and incident workflows.
What you will do
- Conduct threat modeling and security reviews for cloud infrastructure and LLM/AI integrations.
- Integrate SAST, DAST, and SCA tools directly into CI/CD pipelines.
- Harden AWS environments, Infrastructure as Code scripts, and Kubernetes workloads and containers.
- Automate repetitive security tasks, alerting, and incident-response workflows using custom scripts.
- Triage, investigate, and remediate vulnerabilities identified through automated scans and Bug Bounty programs.
What you bring
- At least 3 years of professional experience in Security Engineering, DevSecOps, or a related role.
- Scripting proficiency in Python, Go, or Ruby.
- Deep hands-on experience with AWS cloud security services (IAM, VPC, GuardDuty, WAF, Inspector).
- Practical experience with AppSec tooling (Burp Suite, OWASP ZAP, Snyk, or SonarQube).
- Experience with container and orchestration security controls (Docker, Kubernetes).
- Knowledge of Infrastructure as Code (IaC) security reviews (Terraform or CloudFormation).
- Familiarity with AI/LLM security risks (OWASP Top 10 for LLMs, RAG architectures, API security).
Contracting party: You will contract directly with Apricot, which will manage contracting, invoicing/payroll, payments, and administrative support. Day to day, you will work closely with the client team and follow the agreed scope, deliverables, and security requirements.
You are expected to provide your own laptop and basic equipment, maintain reliable connectivity and a secure working environment, and follow required security controls, including two-factor authentication.
Planned check-ins are at month 1 to see how the engagement is working and help address issues, given the shorter 6–8 month duration.