Security Engineer
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Large language models are transforming software engineering — developers can now go from idea to code faster than ever. But that just shifts complexity downstream: deployment, observability, cost, security, reliability — all of that has to scale too, and LLMs don't yet solve the problem.
That's where Aptible comes in. Since 2014, our cloud delivery platform has been automating security, compliance, and reliability for engineering teams whose apps handle the most sensitive data, in the most highly regulated industries.
The need for a platform like Aptible has never been greater. If you're passionate about cloud infrastructure and ensuring DevOps evolves to meet the pressure of AI-assisted development — and you're excited to join a small and highly talented team — we’d love to hear from you.
Overview
In this role, you'll be a hands-on security engineer defending and hardening a platform that regulated companies build their businesses on. This is an engineering role first; you'll design security-by-default infrastructure, run our vulnerability management program, drive our pentesting program (including working with tools like XBOW) from finding to fix, and lead incident response when things go wrong. You'll also bring the organizational rigor to run a compliance recertification when the underlying technical controls are already sound, but this is not a policy-writing or audit-management role, and it's not the core of the job.
This role reports to the VP of Security, but works day-to-day in close collaboration with the Engineering team — not as a siloed security function reviewing work from a distance, but as an embedded partner co-owning the fixes, the infrastructure, and the outcomes.
What You'll Do
Engineering
Design and build security-by-default infrastructure across our AWS-based PaaS, which spans Ruby on Rails backend systems, a web app (React/TypeScript), a Terraform client (Go), a CLI client (Go), and several other distributed components (Python, Go, Ruby)
Own and mature our vulnerability management program — triaging findings and working with findings from scanning tools and the AWS Security Agent in collaboration with the Engineering team, prioritizing by real-world exploitability and risk
Own our pentesting program end to end — running automated assessments with XBOW, coordinating manual and third-party testing, and driving remediation to closure in our codebase (Ruby, Go, TypeScript) and infrastructure alongside Engineering, rather than just filing tickets and waiting
Lead incident response operations: detection, containment, eradication, and post-incident review, with a bias toward fixing root causes in the code and infrastructure, not just symptoms
Build and maintain detection tooling, alerting, and runbooks — including tuning and extending the AWS Security Agent — to reduce time-to-response
Participate in on-call rotation for security-relevant incidents and help drive follow-ups that prevent repeats
Compliance
Run point on compliance recertifications and maintaining current standards (e.g., renewing SOC 2 or HITRUST) when the technical controls are already in place, this means being organized, coordinating evidence collection, and working with auditors, not authoring new policy from scratch
Use AI tools to improve your development and investigation workflow
What We're Looking For
General Experience
5+ years of experience in security engineering, with a track record of owning security-critical systems in production
You have experience as a hands-on security engineer, not just a security reviewer or policy writer — you can read and write code, operate infrastructure, and get into the weeds of a system under attack
You communicate extremely well — clear, effective, and proactive, both in writing and live during an incident
Developer tools or platform engineering experience is a plus
Technical Expertise
Strong engineering fundamentals and coding ability, with comfort working across a full-stack codebase — our stack includes Ruby on Rails, React/TypeScript, Go (Terraform client), and Ruby (CLI)
You're a prolific and thoughtful developer in at least one mainstream language, and can pick up new languages/frameworks quickly
Deep, hands-on experience with cloud infrastructure security (AWS strongly preferred), including AWS-native security tooling (e.g., AWS Security Agent, GuardDuty, Security Hub), and distributed systems
Real pentesting experience, including with automated/AI-assisted tools like XBOW, and a track record of driving remediation rather than just reporting findings
Experience running or significantly contributing to a vulnerability management program, from scanning and triage through verified remediation
Experience leading or heavily participating in incident response — you stay calm and methodical under pressure
Comfort working across identity management, network security, and detection tooling
Organizational Strength
You're organized enough to run a compliance recertification as a project — tracking evidence, coordinating stakeholders, and hitting deadlines — without that becoming your whole job
You know the difference between operating existing controls well and designing net-new policy, and you're energized by the former
Startup Compatibility
You want to be part of a small, highly collaborative team, and you work closely with Engineering rather than operating at arm's length
You don't let ambiguity or bumps in the road stop you: you identify what's blocking you, take ownership, and drive to get unblocked
You Should Apply If
You appreciate working in a highly autonomous, trusted role, where the day-to-day priorities may shift.
You want to do hands-on security engineering, designing, building, breaking, and fixing in real code — not just governance and paperwork
You're a deeply curious problem solver, and you're not tied to a specific language or technology
You're energized by incident response, vulnerability management, and pentesting, and see compliance as something you keep running smoothly, not something you build from scratch
You're invested in team ownership — you care about what your teammates are building, not just your own corner
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
Explore Top Companies in this Space
Qumulo
Enterprise Software / Cloud Computing / Data Storage / AI Infrastructure
Azumo
Artificial Intelligence / Software Development / Cloud Computing / Enterprise Software
Atmosera
Information Technology & Services / Systems and Information Management / Cloud Computing / Enterprise Software
SpryPoint
Enterprise Software / Cloud Computing / Energy & Utilities / Customer Engagement
Aptible
View Company ProfileAptible (operating at aptible.com) is a platform-as-a-service (PaaS) company engineered for modern digital health and scaling enterprises. Founded in 2013 by Chas Ballew and Frank Macreery, Aptible specializes in automating the complexities of cloud infrastructure provisioning, management, and scaling—eliminating the need for deep compliance expertise or flawless developer behavior. Unlike traditional infrastructure solutions, Aptible embeds compliance and security directly into its platform, ensuring regulated environments like healthcare or finance can deploy production-grade applications without manual overhead. Under the hood, the platform runs entirely within a customer’s AWS account, abstracting away the operational friction of scaling resources while maintaining strict governance controls. This allows developers and engineering teams to focus on innovation rather than infrastructure, accelerating time-to-market for applications in highly regulated industries. Backed by over $12 million in venture funding, Aptible serves a niche but critical segment of enterprises prioritizing compliance and operational efficiency.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.



