About The Position

This role focuses on designing, implementing, and maintaining enterprise security controls across cloud, infrastructure, and application environments. The Senior Lead Engineer will evaluate emerging threats and technologies, develop security standards, and lead security engineering efforts for internally developed applications and APIs. A key aspect of the role involves designing and developing security automation solutions, integrating security into CI/CD pipelines, and managing Web Application Firewall (WAF) capabilities. The position also includes conducting offensive security assessments and collaborating with various teams to enhance the overall security posture.

Requirements

  • Experience in designing, implementing, and maintaining enterprise security controls across cloud, infrastructure, and application environments.
  • Experience evaluating emerging threats and technologies and recommending improvements to security architecture.
  • Experience developing security standards, engineering patterns, and technical guidance.
  • Experience designing and developing security automation solutions.
  • Experience integrating security controls and validation activities into CI/CD pipelines and software delivery workflows.
  • Experience building and maintaining GitHub Actions and related automation.
  • Experience automating vulnerability management, policy enforcement, reporting, and remediation tracking activities.
  • Experience leading security engineering efforts for internally developed applications and APIs.
  • Experience with threat modeling, secure design and architecture reviews, secure code reviews, SAST, DAST, SCA, open-source dependency and supply chain security reviews, secret and credential exposure detection, API security testing and assessments, CI/CD pipeline security reviews, and security validation of application deployments.
  • Experience partnering with development teams to identify, prioritize, and remediate security risks.
  • Experience designing, implementing, and maintaining Web Application Firewall (WAF) capabilities.
  • Experience developing and tuning WAF security rules, attack detection logic, bot mitigation, rate limiting, and application-layer protections.
  • Experience conducting application red team exercises and adversarial security assessments.
  • Experience performing manual and automated penetration testing of web applications, APIs, and supporting services.
  • Experience documenting findings, providing remediation guidance, and validating corrective actions.
  • Experience partnering with engineering, infrastructure, and cloud teams to implement secure solutions.
  • Experience supporting incident response investigations.
  • Experience providing technical leadership and mentorship on security engineering practices and security tool adoption.

Responsibilities

  • Design, implement, and maintain enterprise security controls across cloud, infrastructure, and application environments.
  • Evaluate emerging threats and technologies and recommend improvements to the organization's security architecture.
  • Develop security standards, engineering patterns, and technical guidance to improve the overall security posture.
  • Design and develop security automation solutions that improve operational efficiency and reduce manual effort.
  • Integrate security controls and validation activities into CI/CD pipelines and software delivery workflows.
  • Build and maintain GitHub Actions and related automation to support secure development practices.
  • Automate vulnerability management, policy enforcement, reporting, and remediation tracking activities.
  • Lead security engineering efforts focused on protecting internally developed applications and APIs.
  • Perform and coordinate: Threat modeling, Secure design and architecture reviews, Secure code reviews, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Open-source dependency and supply chain security reviews, Secret and credential exposure detection, API security testing and assessments, CI/CD pipeline security reviews, Security validation of application deployments.
  • Partner with development teams to identify, prioritize, and remediate security risks.
  • Design, implement, and maintain Web Application Firewall (WAF) capabilities.
  • Develop and tune security rules, attack detection logic, bot mitigation, rate limiting, and application-layer protections.
  • Continuously monitor and improve protections against OWASP Top 10 and emerging web application threats.
  • Conduct application red team exercises and adversarial security assessments.
  • Perform manual and automated penetration testing of web applications, APIs, and supporting services.
  • Simulate real-world attack techniques to identify weaknesses in application design, authentication, authorization, and deployment architectures.
  • Document findings, provide remediation guidance, and validate corrective actions.
  • Partner with engineering, infrastructure, and cloud teams to implement secure solutions.
  • Support incident response investigations involving applications, cloud services, and development platforms.
  • Provide technical leadership and mentorship on security engineering practices and security tool adoption.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service