Senior Security Engineer

Kestra Technologies
•Remote

About The Position

About Kestra Kestra is the universal orchestration platform : open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems. Trusted by over 10,000 organizations worldwide , including JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole , Kestra orchestrates mission-critical workloads at scale. The open-source project has close to 30,000 GitHub stars , hundreds of contributors, and a fast-growing global community. About the role We’re looking for a Senior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem. This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.

Requirements

  • 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.
  • Strong hands-on penetration testing background , with proven ability to discover application, API, and network-level vulnerabilities.
  • A builder/fixer mindset : You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers.
  • Deep familiarity with cloud security (AWS or GCP) and containerized environments ( Kubernetes , Docker).
  • Experience with dependency and supply-chain security (CVE management, open-source licensing, SCA tools).
  • Fluent in English and comfortable working autonomously in a fully remote environment.
  • Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.

Responsibilities

  • Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments.
  • Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure.
  • Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.
  • Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats.
  • Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.
  • Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks.
  • Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies.

Benefits

  • Work from anywhere : We’re a remote-first company, so you can work from wherever feels like home. Plus, you’ll have access to coworking spaces worldwide if you ever need a change of scenery.
  • Health coverage : From medical support, dental, and vision, we've got you covered.
  • Home office setup on us : We’ll provide all the equipment you need to work comfortably.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service