Point your AI agent at freehire and let it find you a job.

Get the CLI →

Senior Security Engineer

NewBe an early applicant

Shape the Future of AI Infrastructure with VAST Data

This is a rare opportunity to join one of the fastest-growing infrastructure companies in tech history, right at the epicenter of the AI revolution.

Recognized by Forbes as "the future of the market," VAST Data is building the foundational enterprise software powering the AI era. We engineer platforms that capture, catalog, refine, and protect massive datasets across data centers, edge, and cloud, making real-time analytics, AI training, and inference simpler and faster than ever before.

Our explosive growth is fueled by relentless engineering innovation, a customer-first mindset, and a team of fearless VASTronauts who thrive on solving computing's hardest problems. Join us at this pivotal moment in technology history and make a lasting impact on how the world processes data.

We are looking for a hands-on, forward-thinking Security Engineer to join our growing security team. In this role, you will lead offensive security initiatives, build internal automation using modern workflows and AI agents, and manage cloud and infrastructure risks. You will conduct penetration tests across our architecture, analyze deep protocol flaws, write custom tooling, and take security findings from discovery all the way to resolution.


Requirements

Core Responsibilities:

  • Penetration Testing & AI Automation: Conduct comprehensive penetration tests across all components of our architecture—ranging from Web APIs down to S3 protocols—and design systems to automate routine pentesting using AI tools.
  • Protocol & Flaw Analysis: Leverage a deep understanding of network and application protocols to identify architectural and implementation flaws, using AI prompts and modern tooling to uncover edge-case security risks.
  • Tooling & Process Automation: Write custom internal security tools and leverage AI agents to automate repetitive tasks, incident responses, and continuous security workflows.

Secondary Responsibilities:

  • Cloud Security Monitoring: Monitor and manage cloud security posture using CNAPP (Cloud-Native Application Protection Platform) tools, maintaining oversight of our cloud infrastructure and containerized environments.
  • Vulnerability Management & Remediation: Run and maintain regular SAST and DAST scans across operating systems, Docker containers, and source code. Own security findings from discovery through code remediation and validation.
  • Jira & Delivery Tracking: Manage, prioritize, and promote security Jira tickets through the full lifecycle—from initial triage and assignment through to final delivery and verification.
  • Software Supply Chain Security: Generate, analyze, and manage Software Bill of Materials (SBOMs) to track third-party dependencies and address supply-chain vulnerabilities.

Qualifications & Skills

Required Qualifications:

  • Offensive Security & Pentesting: Solid background in penetration testing covering APIs, microservices, cloud storage protocols (S3), and distributed network architectures.
  • Protocol & Code Analysis: Strong knowledge of underlying network and storage protocols with a demonstrated ability to uncover implementation flaws. Familiarity with C/C++ source code is a distinct advantage for low-level analysis and AI prompt engineering.
  • AI Integration: Experience or strong interest in leveraging AI agents and prompt engineering to automate security scanning, triage, and security research.

Preferred Qualifications (Advantage):

  • Development & Automation: Proficiency in scripting/programming (Python, Go, or Bash) to build internal security tools, integrate APIs, and automate workflows.
  • Cloud Security Expertise: Hands-on experience with CNAPP, CSPM, or CWPP solutions in public cloud environments (AWS, GCP, or Azure).
  • Application & Infrastructure Security: Demonstrated experience with SAST/DAST tools, container security (Docker/Kubernetes), OS hardening, and secure code review.
  • Process & Ticket Lifecycle Management: Strong organizational skills to manage security backlogs, triage tickets in Jira, and collaborate cross-functionally with engineering teams to drive remediation to delivery.


See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available