Kestra Logo

Kestra

Senior Security Engineer

Posted Yesterday
Remote
Hiring Remotely in Greece
Senior level
Remote
Hiring Remotely in Greece
Senior level
Own and improve the security posture of Kestra’s platform, infrastructure, and open-source ecosystem. Responsibilities include penetration testing, threat modeling, vulnerability management, remediation, cloud and Kubernetes hardening, security automation in CI/CD, code reviews, supply-chain risk assessment, incident response, and continuous monitoring.
The summary above was generated by AI
About Kestra

Kestra is the universal orchestration platform: open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems.

Trusted by over 10,000 organizations worldwide, including JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole, Kestra orchestrates mission-critical workloads at scale. The open-source project has close to 30,000 GitHub stars, hundreds of contributors, and a fast-growing global community.

About the role

Kestra runs arbitrary, user-defined code at scale. Our users write workflows that execute scripts, containers, and queries against their own production systems, through hundreds of community-built plugins, on a platform whose entire source code is public. That is an unusually rich attack surface, and securing it is a genuinely hard engineering problem rather than a checklist exercise.
You would be our first dedicated security hire. We're looking for a Senior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem.
This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.
This is a hands-on engineering role, not a GRC or compliance one.

What you would do

Your first six months would focus on the first three points below. The rest is where the role grows.

  • Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments.

  • Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure.

  • Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.

  • Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats.

  • Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.

  • Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks.

  • Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies.

  • Own our public security posture as an open-source project: vulnerability disclosure process, CVE handling, security advisories, and the trust model of our plugin ecosystem.

Our Tech Stack
  • Security & Vulnerability Tools: Trivy, GitHub Security / Dependabot, Elastic Security

  • Infrastructure: Docker, Kubernetes, Terraform

  • Cloud: GCP

  • Programming language: Java, Typescript, Javascript

  • Datastore: PostgreSQL, Elasticsearch

  • Queuing: Redis, Kafka, AMQP

  • Monitoring & Logs: ELK, Prometheus, Grafana

  • Deployment & Repository: GitHub Actions, ArgoCD

What we are looking for
  • 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.

  • Strong hands-on penetration testing background, with proven ability to discover application, API, and network-level vulnerabilities.

  • A builder/fixer mindset: You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers.

  • Deep familiarity with cloud security (AWS or GCP) and containerized environments (Kubernetes, Docker).

  • Experience with dependency and supply-chain security (CVE management, open-source licensing, SCA tools).

  • Fluent in English and comfortable working autonomously in a fully remote environment.

  • Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.

Perks & Benefits
  • Work from anywhere: We’re a remote-first company, so you can work from wherever feels like home. Plus, you’ll have access to coworking spaces worldwide if you ever need a change of scenery.

  • Health coverage: From medical support, dental, and vision, we've got you covered.

  • Home office setup on us: We’ll provide all the equipment you need to work comfortably.

     
Our Hiring Process

We aim to move quickly (2-3 weeks), but we can adjust the timeline if needed.

  • Intro call with the hiring manager (30 min)

  • Technical scenario / Practical assessment (2 hours, asynchronous homework focusing on threat assessment and remediation)

  • Team chat with one of your future colleagues (30 min)

  • Final discussion with one of our co-founders (30 min)

Similar Jobs

15 Days Ago
In-Office or Remote
Senior level
Senior level
Cloud • Information Technology • Internet of Things • Professional Services • Software
Lead software security practices across the development lifecycle by building and tuning vulnerability detection tools, triaging findings, prioritizing risks, improving security processes, and partnering with development and security teams. The role includes automating security workflows, evaluating vulnerabilities and mitigations, tracking security metrics, and promoting best practices across product teams.
Top Skills: AWSAzureBashDastFuzzingGCPGoKubernetesLinuxLlmsPythonSastTerraform
15 Days Ago
In-Office or Remote
Senior level
Senior level
Cloud • Information Technology • Internet of Things • Professional Services • Software
Lead software security lifecycle improvements by deploying and tuning vulnerability detection tools, triaging findings, prioritizing security risks, and standardizing security processes. Partner with development, release, and Cisco security teams to remediate vulnerabilities, measure security posture, and promote best practices. Automate security workflows using Go, Python, Bash, or Terraform, with opportunities to apply LLMs, fuzzing, DAST, Kubernetes, and cloud security expertise.
Top Skills: AWSAzureBashCloud Security ScannersDastFuzzersGCPGoKubernetesLinuxLlmsPythonSastTerraform
One Month Ago
In-Office or Remote
49 Locations
Senior level
Senior level
Big Data • Healthtech • Software • Biotech
Lead security engineering across web apps, APIs, cloud (AWS/OCI), Kubernetes, and on-prem systems. Build CI/CD security, secure genomic and PHI/PII pipelines (HIPAA), run monitoring and incident response, prepare for HIPAA/SOC2/ISO27001 audits, perform pentesting/vulnerability discovery, improve logging/SIEM, and drive remediation with engineering and DevOps while raising company-wide security awareness.
Top Skills: AWSBurp SuiteCi/CdCloudflareCloudtrailCodeqlContainersDockerFalcoGitGitGoogle WorkspaceIamKubernetesLog AggregationMetasploitNetwork PoliciesOciOwasp ZapRbacSecrets ManagementSemgrepSIEMTerraform

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account