Security Engineer at Xbowcareers in US remote
- Company: Xbowcareers
- Location: US remote
- Posted: Sep 20, 2026
- Type: Full-time
- Experience: 5+ years
Overview
Application We're looking for an experienced, hands-on Security Engineer to secure XBOW's product, cloud, and platform as we scale. This is a technical individual contributor role focused on building security into how we design, ship, and operate systems.
Job description
- Application
- We're looking for an experienced, hands-on Security Engineer to secure XBOW's product, cloud, and platform as we scale. This is a technical individual contributor role focused on building security into how we design, ship, and operate systems.
- You'll work closely with engineering and platform teams across application security, cloud security, vulnerability management, and incident response. The core of this role is security engineering ownership: improving preventive controls, detection quality, and response readiness, while driving remediation of real risks in production.
Responsibilities
- Design and implement security controls across cloud, infrastructure, and internal platforms
- Partner with engineering to harden cloud architecture, IAM, and infrastructure
- Own product security reviews for new features, services, and major architecture changes
- Drive threat modeling and secure design decisions early in the SDLC
- Operate and improve AppSec workflows (SAST, SCA, secrets scanning, IaC scanning)
- Triage vulnerabilities across application, container, and cloud findings, and drive remediation with risk-based SLAs
- Define and run the vulnerability management lifecycle: intake, prioritization, exception handling, validation, and reporting
- Improve CNAPP coverage and finding quality across cloud accounts and workloads
- Improve Kubernetes and container security posture
- Monitor, investigate, and respond to security events and incidents
- Build automation to improve security operations, access workflows, and incident response
- Support the wider teams by providing timezone coverage for our fully remote organization.
Requirements
- Essential-
- 5+ years of experience in security engineering, product security, cloud/platform security, or closely related roles
- Strong hands-on experience securing cloud environments (AWS, Azure and GCP)
- Comfortable owning technical security problems end-to-end in fast-moving environments
- Hands-on experience with product/application security in engineering environments (secure design reviews, threat modeling, code-level risk discussions)
- Experience operating AppSec tooling and processes at scale (SAST, SCA, secrets, IaC scanning)
- Strong vulnerability triage and remediation management experience, including risk-based prioritization and SLAs
- Experience with CNAPP (or equivalent cloud security platforms) and tuning findings for engineering actionability
- Working knowledge of Kubernetes/container security in production systems
- Ability to partner with developers and platform teams to ship secure defaults without blocking delivery
- Comfortable writing scripts and automations to improve security reliability and scale
- Experience in incident response, investigation, and post-incident hardening in cloud-native environments
- Security-minded, detail-oriented, and a proactive communicator in remote-first teams
- Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI)
- Offensive security/pentesting background and ability to convert findings into durable engineering fixes
- Experience scaling security at a startup from early stage to audit-ready maturity
- Relevant security certifications (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certs)
Skills
Required
- Security engineering
- Cloud security (AWS, Azure, GCP)
- Product/application security
- Secure design reviews
- Threat modeling
- Vulnerability triage and remediation
- CNAPP
- Kubernetes/container security
- Scripting and automation
- Incident response
- Communication
Preferred
- Multi-cloud experience (Azure/GCP/OCI)
- Offensive security/pentesting
- Scaling security at a startup
Benefits
- Compensation & Equity: Competitive salary, meaningful stock options, comprehensive benefits and 401k plan
- Growth: Opportunity to learn from and collaborate with top security and AI experts
- Impact: Work on complex technical challenges that support the foundation of our company
- Remote-First:Work from anywhere, with regular opportunities to meet in person