Security Engineer

KamiOhio (anywhere within EST or CST), OH

About The Position

Kami is a thriving organisation filled to the brim with talented, creative, and passionate people! It’s hard not to love what you do when our leading digital classroom platform offers meaningful solutions to over 70 million users worldwide, empowering students and supporting teachers! You’ll be joining at a pretty magical time. Kami’s user base is growing by the day. With over 170 team members across the world, we couldn’t be prouder of the accomplishments and milestones we’ve achieved to date. Now, this is your chance to join our team and become an integral member of Kami’s growth, while shaping your own future (and having fun doing it)! As a Security Engineer at Kami, you won't just be identifying risks and writing reports—you will be the one actively fixing them. We are expanding our in-house security team and need a hands-on engineer who thrives on pure engineering remediation. In this role, you will leverage our automated security tools, scanning platforms, and risk/vulnerability processes to pinpoint faults and defects across our systems and applications. Instead of just passing off a ticket, you will jump directly into the codebase to patch those vulnerabilities, refactor out-of-life or legacy code, upgrade outdated libraries and dependencies to ensure our environment is secure and modernized. You will act as a core technical resource for the broader engineering team, writing clear security documentation and playbooks, and actively assisting and guiding developers to successfully remediate defects within their own workflows. You will be the ultimate bridge between automated threat detection and active engineering execution, embedding robust security guardrails directly into our software development life cycle. If you are a builder who loves deep, code-level troubleshooting, enjoys replacing stale legacy infrastructure with secure code, and wants to protect a platform supporting over 50 million global users, this is the perfect place to make a massive impact.

Requirements

  • 5-8+ years of experience in an Application Security or Security Engineering role.
  • Ability to read code, identify architectural flaws, and write the necessary fixes or scripts to resolve them.
  • Proven experience managing technical debt, identifying out-of-life or legacy code paths, and safely updating third-party libraries/dependencies without breaking production features.
  • Excellent written skills with a knack for building clean security playbooks.
  • Enjoy working side-by-side with developers, pairing to debug technical issues, and assisting teams in pushing code fixes over the finish line.
  • Familiarity with cloud-native architectures, containerized applications, CI/CD integrations, and configuring automated security testing systems (SAST/DAST/SCA).
  • Strong builder mindset; enjoys digging into the architecture to implement lasting infrastructure or code-level safeguards when a security weakness is exposed.
  • Exposure to application security fundamentals, specifically with OWASP, is required or preferred.

Nice To Haves

  • Network & Deployment: Experience with network configuration and application deployment is preferred.

Responsibilities

  • Utilize automated scanners and internal risk processes to hunt down defects.
  • Actively dive into code bases to update outdated libraries, rewrite out-of-life legacy components, and resolve critical technical debt.
  • Ensure continuous modernization of Kami’s codebase by wiping out vulnerabilities stemming from deprecated packages and old dependencies before they can be exploited.
  • Collaborate actively with engineering pods, reviewing their security posture and directly assisting them in troubleshooting and executing defect remediation.
  • Accelerate internal security engineering cycles by clearing remediation blockers for engineering teams, turning security into a supportive peer function.
  • Draft comprehensive, easy-to-follow security playbooks, coding standards guidelines, and remediation documentation for internal distribution.
  • Create a standardized knowledge base that upskills the entire engineering group on modern secure coding practices and streamlined defect fixing.
  • Embed automated security scanning tools, analysis processes, and proactive guardrails cleanly inside the active software development lifecycle.
  • Ensure systematic and early-stage identification of technical faults across applications, moving toward a continuous 'shift-left' security model.
  • Implement and maintain robust cloud infrastructure protections, including customized firewalls, intrusion detection mechanisms, and advanced encryption protocols.
  • Preserve the absolute structural integrity of our global digital infrastructure, securely partitioning and safeguarding core assets.
  • Manage and execute the emergency incident response lifecycle, building automated logic to spot, flag, and contain system anomalies instantly.
  • Deliver rapid technical resolution timelines during active security incidents, significantly minimizing structural exposure or system downtime.

Benefits

  • Continuous learning and development opportunities, including subsidised course fees, certifications, conferences, and free access to Udemy and more.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service