Role overview

Staff Security Engineer

Requirements and responsibilities

Readable role content extracted into sections for faster review.

What you'll do:

  • Domain Expertise: Act as the lead subject matter expert for the Kong Cloud Security Operations.
  • Threat Defense Leadership: Architect and implement next-generation WAF, IDS, and IPS capabilities at the gateway level to protect against OWASP Top 10, zero-day exploits, and sophisticated API abuse.
  • Multi-Cloud Security: Design and implement "Zero Trust" security models that operate seamlessly across hybrid and multi-cloud environments (AWS, Azure, GCP, On-prem).
  • Strategic Roadmap: Partner with Product and Architecture leads to define the multi-year security roadmap for Kong Gateway, balancing the needs of the OSS community with Enterprise requirements.
  • Incident Resolution: Lead the response to complex, multi-faceted security challenges—from supply chain vulnerabilities in open-source dependencies to high-stakes CVE remediations.
  • Mentorship & Influence: Champion a "Security-First" culture by mentoring engineers on secure coding practices and influencing the long-term cybersecurity maturity of the entire organization.

What you'll bring:

  • 8+ years’ experience in Cybersecurity Engineering, with a focus on high-traffic infrastructure or API management.
  • Extensive experience with Kong Gateway, Nginx, eBPF, or similar technologies.
  • Cloud-Native & Multi-Cloud: Expert-level knowledge of multi-cloud solution design, specifically securing traffic across disparate cloud providers and Kubernetes environments.
  • Security Domain Specialist: Proven track record in designing/deploying WAF, IDS, and IPS systems at scale, with an understanding of signature-based vs. ML-based detection.
  • Programming Proficiency:Python, Go or Rust
  • Open Source Contributor: Experience contributing to or maintaining open-source security projects is a significant asset.
  • Design Excellence: Ability to produce high-quality, high-performance security designs that do not compromise the "millisecond-latency" promise of the gateway.
Similar roles

Keep a backup shortlist.

Browse stack
FocusStaff Security EngineerRole area
Seniority signalSeniorCandidate level
StackAWS, Azure, GCPPrimary skills
Location1 accepted countryEligibility

Stack

Use these tags to compare similar remote roles.

Location eligibility

Candidates should apply only when their profile country is listed here.

Your profileCountry not setSign in to check your country against this role.

Hiring flow

WithMira shows the role, then sends candidates to the company application.

1Check role fit, stack, and location eligibility in WithMira.
2Open the company application page from the tracked apply link.
3Save the role or subscribe for similar opportunities before leaving.
Apply on company siteCompany siteOpen link