Aptible logo

Senior Security Engineer

Aptible
Remote
Remote$162k–$184k· about 1 hour ago

Straight from Aptible’s careers page. Apply on the company site — no recruiter, no middleman.

Explore more remote Security Engineer jobs — salaries, top companies, and the latest openings.See all →

Senior Security Engineer

Department: Research & Development

Location: North America (PT-ET Time Zones)

Compensation: $162K – $184K

Employment Type: FullTime

About Aptible

 

Large language models are transforming software engineering — developers can now go from idea to code faster than ever. But that just shifts complexity downstream: deployment, observability, cost, security, reliability — all of that has to scale too, and LLMs dont yet solve the problem.

Thats where Aptible comes in. Since 2014, our cloud delivery platform has been automating security, compliance and reliability for engineering teams whose apps handle the most sensitive data, in the most highly regulated industries.

The need for a platform like Aptible has never been greater. If youre passionate about cloud infrastructure and ensuring DevOps evolves to meet the pressure of AI-assisted development — and youre excited to join a small and highly talented team — we’d love to hear from you.

NEW! Aptible is part of Opti9 Technologies, a cloud solutions provider specializing in managed cloud, security, disaster recovery, and compliance. Joining forces with Opti9 gives Aptible the resources to invest more aggressively in the platform — expanding what we can deliver to the engineering teams who depend on it.

 

Our Commitment to Diversity and Inclusion

We see great value in bringing together a team with different perspectives, educational backgrounds, and life experiences, and we prioritize diversity within our team. We encourage people from underrepresented backgrounds to apply.

About This Role

Overview

In this role, youll be a hands-on security engineer defending and hardening a platform that regulated companies build their businesses on. This is an engineering role first; youll design security-by-default infrastructure, run our vulnerability management program, drive our pentesting program (including working with tools like XBOW) from finding to fix, and lead incident response when things go wrong. Youll also bring the organizational rigor to run a compliance recertification when the underlying technical controls are already sound, but this is not a policy-writing or audit-management role, and its not the core of the job.

This role reports to the Chief Information Security Officer (CISO), but works day-to-day in close collaboration with the Engineering team — not as a siloed security function reviewing work from a distance, but as an embedded partner co-owning the fixes, the infrastructure, and the outcomes.

What Youll Do

Engineering

  • Design and build security-by-default infrastructure across our AWS-based PaaS, which spans Ruby on Rails backend systems, a web app (React-TypeScript), a Terraform client (Go), a CLI client (Go), and several other distributed components (Python, Go, Ruby)

  • Own and mature our vulnerability management program — triaging findings and working findings from scanning tools and the AWS Security Agent in collaboration with the Engineering team, prioritizing by real-world exploitability and risk

  • Own our pentesting program end to end — running automated assessments with XBOW, coordinating manual and third-party testing, and driving remediation to closure in our codebase (Ruby, Go, TypeScript) and infrastructure alongside Engineering, rather than just filing tickets and waiting

  • Lead incident response operations: detection, containment, eradication, and post-incident review, with a bias toward fixing root causes in the code and infrastructure, not just symptoms

  • Build and maintain detection tooling, alerting, and runbooks — including tuning and extending the AWS Security Agent — to reduce time-to-response

  • Participate in on-call rotation for security-relevant incidents and help drive follow-ups that prevent repeats

Compliance

  • Run point on compliance recertifications and maintaining current standards (e.g., renewing SOC 2 or HITRUST) when the technical controls are already in place, this means being organized, coordinating evidence collection, and working with auditors, not authoring new policy from scratch

  • Use AI tools to improve your development and investigation workflow

What Were Looking For

General Experience

  • 5+ years of experience in security engineering, with a track record of owning security-critical systems in production

  • You have experience as a hands-on security engineer, not just a security reviewer or policy writer — you can read and write code, operate infrastructure, and get into the weeds of a system under attack

  • You communicate extremely well — clear, effective, and proactive, both in writing and live during an incident

  • Developer tools or platform engineering experience is a plus

Technical Expertise

  • Strong engineering fundamentals and coding ability, with comfort working across a fullstack codebase — our stack includes Ruby on Rails, React/TypeScript, Go (Terraform client), and Ruby (CLI)

  • Youre a prolific and thoughtful developer in at least one mainstream language, and can pick up new languages/frameworks quickly

  • Deep, hands-on experience with cloud infrastructure security (AWS strongly preferred), including AWS-native security tooling (e.g., AWS Security Agent, GuardDuty, Security Hub), and distributed systems

  • Real pentesting experience, including with automated/AI-assisted tools like XBOW, and a track record of driving remediation rather than just reporting findings

  • Experience running or significantly contributing to a vulnerability management program, from scanning and triage through verified remediation

  • Experience leading or heavily participating in incident response — you stay calm and methodical under pressure

  • Comfort working across identity management, network security, and detection tooling

Organizational Strength

  • Youre organized enough to run a compliance recertification as a project — tracking evidence, coordinating stakeholders, and hitting deadlines — without that becoming your whole job

  • You know the difference between operating existing controls well and designing net-new policy, and youre energized by the former

Startup Compatibility

  • You want to be part of a small, highly collaborative team, and you work closely with Engineering rather than operating at arms length

  • You dont let ambiguity or bumps in the road stop you: you identify whats blocking you, take ownership, and drive to get unblocked

You Should Apply If

  • You appreciate working in a highly autonomous, trusted role, where the day to day priorities may shift.

  • You want to do hands-on security engineering, designing, building, breaking, and fixing in real code — not just governance and paperwork

  • Youre a deeply curious problem solver, and youre not tied to a specific language or technology

  • Youre energized by incident response, vulnerability management, and pentesting, and see compliance as something you keep running smoothly, not something you build from scratch

  • Youre invested in team ownership — you care about what your teammates are building, not just your own corner

 

Aptibles Employee Benefits

 

Aptibles Values & Principles

----

Why Aptible

Aptible has been around for over a decade. We have a real product, real customers who depend on it, and a profitable business. Were not a rocketship chasing hypergrowth — were a small, tight-knit team doing meaningful work in a complex system. Together, we wield genuine ownership to drive lasting impact: the kind where our work shapes the whole product, not just a corner of it.

Well be honest: this isnt an “everything is figured out” moment. Were navigating real change, with more on the way — and were doing it together. Were not looking for someone who thinks they have all the answers already. Were looking for someone who wants to find them with us.

What keeps us here is each other. Were a team that genuinely cares — about the work, the customers (and the cool things theyre building), and each other. If you want to do hard things alongside people you actually like and respect, and leave a lasting mark on a system that matters, this is that place.

Interview Process

We want to make the experience of interviewing with us as delightful, efficient, fair, respectful, and transparent as possible. A typical process at Aptible might include the following steps. Please note that this may vary by role, and details will be provided to you early on in the process.

  • Introduction to Aptible with the Hiring Manager

  • 2-3 Skills-Based Interviews with Aptible Team Members

  • Take-Home Project (You will be compensated for completing this)

  • References

  • Final in-person onsite

If you have a disability or special need that requires accommodation, please let your Recruiter and/or Hiring Manager know.

AI at Aptible

👉 tl;dr — Aptible is a good fit for pragmatic AI skeptics and for AI enthusiasts who are clear-eyed about its limitations and risks.

We are a security and compliance company, and our primary goal is to make it easy for our customers to stay secure and compliant in the cloud. To do that these days, we simply have to have our hands in AI. Theres no avoiding it.

We dont believe that AI is the answer to everything. In fact, we carry healthy skepticism about it and have clear eyes about its negative impacts on society, the environment, engineering culture, and more.

But we engage with it for two reasons:

  • Because our customers do. And to best serve them, we need expertise in AI use, AI risk, AI development, and more.

  • Because sometimes AI is the right tool for the job, and sometimes it accelerates our work. And at heart, we are pragmatists.

Aptible is a good fit if youre someone who can hold multiple ideas at once about AI — the utility and the risk, the potential and the cost, enthusiasm and skepticism. If youre categorically opposed to working with it in any form or an unbridled enthusiast, this probably isnt the right fit.

AI Usage in the Interview Process

At Aptible, AI is part of how we work every day. We treat it like any other development tool — powerful, expected, and entirely the responsibility of the person using it. Use it with discernment, knowing that you still own the results.

Heres what we expect from you:

  • Your resume — Dont submit AI-generated resumes. They will be discarded. Concise and real wins with us. (Why? We review a high volume of applications and arent using AI for application review. Our human reviewers cant parse through templated, bloated submissions, and resumes highly tailored to the keywords of our JDs dont hold weight for our reviewers)

  • Live conversations — Dont use real-time AI to generate answers that you read off to us. Its obvious, and well end the interview. Honest and real wins with us. (Why? These are human interactions. Were evaluating you — how you think, how you communicate, how you engage)

  • Technical topics/work — Use any tools you normally would, including AI agents. But be honest about what you used, be discerning about what AI outputs, and be ready to explain your thinking. AI output refined by human judgment wins with us. (Why? We want to see what real work looks like. And real work includes shaping what comes from AI, not just accepting it as-is)

Bjak logo

Bjak

Security Architect

Remote
✓ From careers page· 34 minutes ago
DaCodes logo

DaCodes

Senior Solutions Tech Lead (Remote)

Remote
Mexico City, Mexico
✓ From careers page· 35 minutes ago
Blue Cross Blue Shield of Michigan logo

Blue Cross Blue Shield of Michigan

Lead Software Engineer, Guidewire (ClaimCenter)

Remote
$83k–$217k
✓ From careers page· 42 minutes ago
Blue Cross Blue Shield of Michigan logo

Blue Cross Blue Shield of Michigan

Lead Software Engineer

Remote
$83k–$217k
✓ From careers page· 42 minutes ago

Discover More than 100,000 Hidden Remote Jobs Before Everyone Else

Unlock All Remote Jobs Today

Simple pricing. Big savings on Quarterly and Yearly.

Monthly Access

$19/month
  • Instant access to fresh remote jobs from 500+ companies
  • New opportunities added hourly, often 3-7 days before anywhere else
  • Advanced filtering by role type, stack, pay, and location
  • Priority customer support
Start 7-day trial — $2.95
Most Popular

Yearly Access

$59/year
  • Everything in Monthly
  • Save $169 (~74%) vs paying monthly
  • Average job search takes ~6 months - get covered for the whole journey
  • Less than the cost of one lunch per month for competitive advantage
  • Equivalent to just ~$4.92/month
Start 7-day trial — $2.95