Aptible logo
AptibleΒ·

Senior Security Engineer - Aptible

Fully remoteFull-timeSeniorUTC-8–-4Americas#AWS#security#compliance

About Aptible

Large language models are transforming software engineering, shifting complexity downstream to deployment, observability, cost, security, and reliability. Since 2014, Aptible's cloud delivery platform has been automating security, compliance, and reliability for engineering teams handling sensitive data in highly regulated industries.

Aptible is part of Opti9 Technologies, a cloud solutions provider specializing in managed cloud, security, disaster recovery, and compliance.

About This Role

As a Senior Security Engineer, you will be a hands-on security engineer defending and hardening the platform that regulated companies build their businesses on. This is an engineering role first: you'll design security-by-default infrastructure, run our vulnerability management program, drive our pentesting program (including working with tools like XBOW), and lead incident response.

You will report to the VP of Security and work day-to-day in close collaboration with the Engineering team as an embedded partner.

What You'll Do

Engineering

  • Design and build security-by-default infrastructure across our AWS-based PaaS, which spans Ruby on Rails backend systems, a React-TypeScript web app, Go Terraform and CLI clients, and other distributed components (Python, Go, Ruby).
  • Own and mature our vulnerability management program, triaging findings from scanning tools and the AWS Security Agent in collaboration with Engineering, prioritizing by real-world exploitability and risk.
  • Own our pentesting program end-to-end, running automated assessments with XBOW, coordinating manual and third-party testing, and driving remediation to closure.
  • Lead incident response operations: detection, containment, eradication, and post-incident review, with a bias toward fixing root causes.
  • Build and maintain detection tooling, alerting, and runbooks, including tuning and extending the AWS Security Agent.
  • Participate in an on-call rotation for security-relevant incidents.

Compliance

  • Run point on compliance recertifications and maintaining current standards (e.g., SOC 2 or HITRUST) by coordinating evidence collection and working with auditors.
  • Use AI tools to improve your development and investigation workflows.

What We're Looking For

  • 5+ years of experience in security engineering with a track record of owning security-critical systems in production.
  • Strong hands-on engineering fundamentals and coding ability across full-stack codebases (Ruby on Rails, React/TypeScript, Go, Python).
  • Deep, hands-on experience with cloud infrastructure security (AWS strongly preferred), including AWS-native security tooling (GuardDuty, Security Hub) and distributed systems.
  • Real pentesting experience, including automated/AI-assisted tools like XBOW, and a track record of driving remediation.
  • Experience running or significantly contributing to a vulnerability management program.
  • Experience leading or heavily participating in incident response under pressure.
  • Comfort working across identity management, network security, and detection tooling.
  • Excellent communication skills, both in writing and live during an incident.

Interview Process

  • Introduction to Aptible with the Hiring Manager
  • 2-3 Skills-Based Interviews with Aptible Team Members
  • Take-Home Project (compensated)
  • References
  • Final onsite

Timezone overlap

UTC-8–-4

Open to

NA

Sign in to track applications and earn points.

More roles at Aptible

Similar remote roles