Your Role: Security EngineerWe're looking for an experienced, hands-on Security Engineer to secure XBOW's product, cloud, and platform as we scale. This is a technical individual contributor role focused on building security into how we design, ship, and operate systems.You'll work closely with engineering and platform teams across application security, cloud security, vulnerability management, and incident response. The core of this role is security engineering ownership: improving preventive controls, detection quality, and response readiness, while driving remediation of real risks in production.What You'll Do:Design and implement security controls across cloud, infrastructure, and internal platformsPartner with engineering to harden cloud architecture, IAM, and infrastructureOwn product security reviews for new features, services, and major architecture changesDrive threat modeling and secure design decisions early in the SDLCOperate and improve AppSec workflows (SAST, SCA, secrets scanning, IaC scanning)Triage vulnerabilities across application, container, and cloud findings, and drive remediation with risk-based SLAsDefine and run the vulnerability management lifecycle: intake, prioritization, exception handling, validation, and reportingImprove CNAPP coverage and finding quality across cloud accounts and workloadsImprove Kubernetes and container security postureMonitor, investigate, and respond to security events and incidentsBuild automation to improve security operations, access workflows, and incident responseSupport the wider teams by providing timezone coverage for our fully remote organization.Who You Are:Essential-5+ years of experience in security engineering, product security, cloud/platform security, or closely related rolesStrong hands-on experience securing cloud environments (AWS, Azure and GCP)Comfortable owning technical security problems end-to-end in fast-moving environmentsHands-on experience with product/application security in engineering environments (secure design reviews, threat modeling, code-level risk discussions)Experience operating AppSec tooling and processes at scale (SAST, SCA, secrets, IaC scanning)Strong vulnerability triage and remediation management experience, including risk-based prioritization and SLAsExperience with CNAPP (or equivalent cloud security platforms) and tuning findings for engineering actionabilityWorking knowledge of Kubernetes/container security in production systemsAbility to partner with developers and platform teams to ship secure defaults without blocking deliveryComfortable writing scripts and automations to improve security reliability and scaleExperience in incident response, investigation, and post-incident hardening in cloud-native environmentsSecurity-minded, detail-oriented, and a proactive communicator in remote-first teamsAdvantageous-Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI)Offensive security/pentesting background and ability to convert findings into durable engineering fixesExperience scaling security at a startup from early stage to audit-ready maturityRelevant security certifications (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certs)What We Offer:Compensation & Equity: Competitive salary, meaningful stock options, comprehensive benefits and 401k planGrowth: Opportunity to learn from and collaborate with top security and AI expertsImpact: Work on complex technical challenges that support the foundation of our companyRemote-First:Work from anywhere, with regular opportunities to meet in personWhat Else You Should Know:• Location: Remote: US, Canada, Argentina. All team members are remote but we meet regularly and you're supported to travel to collaborate with colleagues in person• Contract: Full-time.Hiring Process:30-min introductory chat with your Talent Partner30 minutes with the Hiring Manager.1 hour technical deep dive.30 minutes with the Deputy CISO30-min final meeting with our CISOWe're a security company that builds with AI at the core — so you'll be protecting a team that moves fast, iterates aggressively, and lives in the command line. If that sounds like your kind of environment, let's talk.