InterviewHack.ai
Start free
Jobs / Kestra Technologies

Senior Security Engineer

Kestra Technologies·Europesenior

In short

  • →Ingeniero de seguridad senior que construye y mantiene la seguridad de una plataforma de orquestación abierta y de código abierto.
  • →Hace pruebas de penetración, repara vulnerabilidades con código y automatiza herramientas de seguridad en CI/CD.
  • →Es el primer ingeniero de seguridad dedicado, con responsabilidad total sobre la seguridad del producto, infraestructura y ecosistema abierto.

Fluent in English

Apply on company site ↗Share on WhatsApp

In ~1 minute you get: who interviews you, the likely questions answered from your CV, and your CV tailored to this job. Free, no card.

🎧Land the interview? Bring the copilot. Our free extension listens to the live interview and flashes 3-4-word anchors from your resume and prep — glance, connect, talk. Get the extension →

What they ask for

  • ✓5+ años en ingeniería de seguridad, seguridad de productos o DevSecOps.
  • ✓Experiencia comprobada en pruebas de penetración de aplicaciones, APIs y redes.
  • ✓Capacidad para escribir parches, PRs y guiar correcciones técnicas a equipos de producto.
  • ✓Conocimiento profundo de seguridad en cloud (GCP) y entornos contenerizados (Kubernetes, Docker).
  • ✓Experiencia con análisis de dependencias y riesgos de cadena de suministro (SCA, CVEs).
  • ✓Inglés fluido y capacidad para trabajar de forma autónoma en entorno remoto.

Don't tick every box? That's normal — your free dossier shows your gaps and how to cover them in the interview.

TrivyGitHub SecurityDependabotElastic SecurityDockerKubernetesTerraformGCPJavaTypescript

Who should you write to at Kestra Technologies?

Your free dossier identifies the people who'd interview you — their background, what they value, and how to reach out so you stand out before applying.

About Kestra Kestra is the universal orchestration platform : open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems. Trusted by over 10,000 organizations worldwide , including JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole , Kestra orchestrates mission-critical workloads at scale. The open-source project has close to 30,000 GitHub stars , hundreds of contributors, and a fast-growing global community. About the role Kestra runs arbitrary, user-defined code at scale. Our users write workflows that execute scripts, containers, and queries against their own production systems, through hundreds of community-built plugins, on a platform whose entire source code is public. That is an unusually rich attack surface, and securing it is a genuinely hard engineering problem rather than a checklist exercise. You would be our first dedicated security hire. We're looking for a Senior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem. This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you. This is a hands-on engineering role, not a GRC or compliance one. What you would do Your first six months would focus on the first three points below. The rest is where the role grows. Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments. Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure. Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation. Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats. Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production. Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks. Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies. Own our public security posture as an open-source project: vulnerability disclosure process, CVE handling, security advisories, and the trust model of our plugin ecosystem. Tech Stack Security & Vulnerability Tools : Trivy, GitHub Security / Dependabot, Elastic Security Infrastructure : Docker, Kubernetes, Terraform Cloud : GCP Programming language : Java, Typescript, Javascript Datastore : PostgreSQL, Elasticsearch Queuing : Redis, Kafka, AMQP Monitoring & Logs : ELK, Prometheus, Grafana Deployment & Repository : GitHub Actions, ArgoCD What we are looking for 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role. Strong hands-on penetration testing background , with proven ability to discover application, API, and network-level vulnerabilities. A builder/fixer mindset : You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers. Deep familiarity with cloud security (AWS or GCP) and containerized environments ( Kubernetes , Docker). Experience with dependency and supply-chain security (CVE management, open-source licensing, SCA tools). Fluent in English and comfortable working autonomously in a fully remote environment. Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter. Perks & Benefits Work from anywhere : W

More jobs like this

Remote Security Engineer jobs

Looking for something similar?

Leave your email and we'll alert you when matching jobs appear.

Don't apply unprepared

We research who's interviewing you, tailor your CV and rehearse you live — first one free.

InterviewHack.ai

Prepare for the exact interview: who's interviewing you, a tailored CV, and a real coach.

Product

JobsFree ATS checkerInterview-English checkSalary checkLATAM salary reportFree coursesBlogTailored CVSpoken practiceIt's free

Remote jobs

ReactPythonFull-StackLATAMArgentinaMexicoSee all →

Prepare

Spoken practiceFrontendBackendAI EngineerBy companySell with your CV

Company

For employersAboutContactPrivacyTerms

© 2026 InterviewHack.ai · Your CV is yours. Never used to train anything. · A product of IA-PTY