Senior Security Engineer
agora Senior Security Engineer
- Partner with Engineering and Product throughout the development lifecycle, from early design and threat modeling through launch and ongoing operation.
- Perform security reviews of system designs, application code, APIs, infrastructure as code, cloud environments, Kubernetes workloads, deployment pipelines, and production configurations.
- Identify vulnerabilities and design weaknesses, communicate their impact clearly, and work with engineers on pragmatic remediation.
- Serve as a trusted security subject-matter expert for application security, cloud and container security, identity and access management, secrets management, API security, data protection, and secure software development.
- Develop reusable security guidance, secure patterns, review checklists, and engineering standards that make the secure approach easier to adopt.
- Administer and improve Agora's security tooling, including AI-assisted security tools, SAST, DAST, software composition analysis, container and infrastructure-as-code scanning, CSPM, security monitoring, and related capabilities.
- Integrate security controls into developer workflows and CI/CD pipelines; tune rules, reduce noise, improve coverage, and ensure findings lead to action.
- Translate threat models and known attack paths into concrete logging, monitoring, and detection requirements.
- Identify gaps in application, cloud, identity, infrastructure, and blockchain-related security telemetry, then work with engineering teams to address them.
- Design, implement, test, document, and tune security alert rules and detection logic.
- Triage and investigate security detections, correlate activity across relevant data sources, and determine scope, impact, severity, and required response.
- Work closely with Agora's SOC to improve alert quality, escalation criteria, investigation procedures, and response runbooks.
- Participate in security incident response, including investigation, containment, eradication, recovery, stakeholder coordination, and evidence preservation.
- Lead or contribute to post-incident reviews and ensure lessons learned result in durable improvements to architecture, controls, monitoring, and operational processes.
- Own the day-to-day execution of the vulnerability management program, including intake, validation, risk-based prioritization, assignment, remediation tracking, exception management, verification, and reporting.
- Support third-party penetration tests, code reviews, architecture assessments, and other independent security engagements, from scoping and reviewer selection through remediation and closure.
- Assess the security implications of new vendors, technologies, integrations, and architectural changes.
- Build lightweight automation and metrics that improve security visibility, shorten investigation and remediation time, and help leadership understand material risk.
- Contribute to Agora's product security, platform security, detection engineering, vulnerability management, and incident-readiness roadmaps.
- 5+ years of hands-on experience in product security, application security, cloud security or a closely related security engineering role.
- Strong software engineering fundamentals and the ability to review application code. Experience with TypeScript, Node.js, JavaScript, or another modern language is especially relevant.
- Experience reviewing web applications, backend services, REST APIs, authentication and authorization systems, and relational database designs.
- Practical knowledge of common application and API vulnerabilities, threat-modeling techniques, secure design principles, and modern identity patterns.
- Experience securing AWS environments, containerized workloads, Kubernetes, infrastructure as code, and CI/CD or GitOps workflows.
- Hands-on experience implementing or administering security tools such as SAST, DAST, SCA, CSPM, container scanning, secrets detection, infrastructure-as-code scanning, SIEM, or cloud-native detection platforms.
- Experience developing or tuning security detections using application, cloud, identity, network, and infrastructure telemetry.
- Strong investigation skills, including the ability to analyze logs and system activity, develop and test hypotheses, establish timelines, and determine the scope and impact of suspicious behavior.
- Experience working with SOC, including alert escalation, investigation handoffs, runbook development, and detection-quality improvement.
- Experience participating in security incident response and coordinating effectively with engineering and operational teams under time pressure.
- Experience operating a vulnerability management process and driving remediation across multiple engineering teams.
- Ability to evaluate findings and detections based on exploitability, confidence, and business impact rather than relying exclusively on automated severity.
- Experience working with external penetration testers, auditors, or specialist security reviewers.
- Strong written and verbal communication skills, including the ability to explain technical risk and incident status clearly to technical and non-technical stakeholders.
- High autonomy and sound judgment. You can take an ambiguous concern, investigate it deeply, propose a path forward, and close the loop.
- A collaborative, low-ego approach to security. You build trust with engineers while maintaining a high bar for systems protecting financial assets and sensitive data.
- Experience securing fintech, payments, digital-assets or other high-assurance financial platforms.
- Familiarity with blockchain systems, smart-contract integrations, transaction flows, custody models, signing infrastructure, or cryptographic key management.
- Experience with TypeScript, Pulumi, AWS, Argo CD, Cloudflare, PostgreSQL, Prometheus, or Grafana.
- Experience with incident-response tooling, security data pipelines, log normalization, detection-as-code, or automated enrichment and response.
- Experience defining operational metrics such as detection coverage, false-positive rate, investigation time, and mean time to contain.
- Experience designing security controls for distributed, event-driven, multi-tenant, or high-availability systems.
- Ability to create security automation, internal tools, or CI/CD integrations using code.
- Experience applying AI-assisted tools to security investigations, detection engineering, or secure development.
- Relevant offensive-security, incident-response and cloud-security experience or certifications.
