Back to Jobs
Kestra
Engineering & Architecture Just now

Senior Security Engineer at Kestra

Kestra
United StatesUnited States
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

DevOps1h 38mFree Trial ✨
Start 10-Day Free Trial
CybersecurityDASTGCPSASTKubernetes

Want to know if you're a match for this job?

Calculate My Match Score

Kestra is the universal orchestration platform: open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems.

Trusted by over 10,000 organizations worldwide, including JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole, Kestra orchestrates mission-critical workloads at scale. The open-source project has close to 30,000 GitHub stars, hundreds of contributors, and a fast-growing global community.

About the Role

We’re looking for a Senior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem.

This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.

What You Would Do

  • Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments.

  • Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure.

  • Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.

  • Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats.

  • Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.

  • Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks.

  • Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies.

Our Tech Stack

  • Security & Vulnerability Tools: Trivy, GitHub Security / Dependabot, Elastic Security

  • Infrastructure: Docker, Kubernetes, Terraform

  • Cloud: GCP

  • Programming Languages: Java, TypeScript, JavaScript

  • Datastore: PostgreSQL, Elasticsearch

  • Queuing: Redis, Kafka, AMQP

  • Monitoring & Logs: ELK, Prometheus, Grafana

  • Deployment & Repository: GitHub Actions, ArgoCD

What We Are Looking For

  • 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.

  • Strong hands-on penetration testing background, with proven ability to discover application, API, and network-level vulnerabilities.

  • A builder/fixer mindset: You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers.

  • Deep familiarity with cloud security (GCP) and containerized environments (Kubernetes, Docker).

  • Experience with dependency and supply-chain security (CVE management, open-source licensing, SCA tools).

  • Fluent in English and comfortable working autonomously in a fully remote environment.

  • Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.

How would you rate this job post?

See what other professionals think about this role.

banner

Kestra is a highly disruptive, open-source orchestration platform fundamentally designed to unify data, infrastructure, and AI workflows for modern engineering teams. Founded by Emmanuel Darras and Ludovic Dehon, the company operates as the ultimate declarative control plane for the entire enterprise stack. Under the hood, Kestra bypasses clunky legacy glue code by allowing developers to write workflows in YAML and seamlessly integrate with over 1,200 plugins—from Kubernetes and Docker to Python, dbt, and Airbyte. Their primary target audience spans aggressive data engineers, platform engineers, and software developers who desperately need to automate complex pipelines, manage CI/CD rollouts, and operationalize AI without production chaos. What sets Kestra apart in the fiercely competitive orchestration landscape is its "adopt once, standardize everywhere" philosophy and massive scalability; backed by over $36M in funding from visionary founders (Datadog, Airbyte, dbt Labs), it empowers organizations to completely transform fragmented, siloed operations into a governed, API-first, event-driven powerhouse.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More