About

XBOW

Jobs at

XBOW

XBOW company logo
Security Engineer
18 Sep
XBOW
18 Sep
Engineering
All U.S.
Fully Remote
<h2>Your Role: Security Engineer</h2><p>We're looking for an experienced, hands-on Security Engineer to secure XBOW's product, cloud, and platform as we scale. This is a technical individual contributor role focused on building security into how we design, ship, and operate systems.</p><p>You'll work closely with engineering and platform teams across application security, cloud security, vulnerability management, and incident response. The core of this role is security engineering ownership: improving preventive controls, detection quality, and response readiness, while driving remediation of real risks in production.</p><h2>What You'll Do:</h2><ul><li><p>Design and implement security controls across cloud, infrastructure, and internal platforms</p></li><li><p>Partner with engineering to harden cloud architecture, IAM, and infrastructure</p></li><li><p>Own product security reviews for new features, services, and major architecture changes</p></li><li><p>Drive threat modeling and secure design decisions early in the SDLC</p></li><li><p>Operate and improve AppSec workflows (SAST, SCA, secrets scanning, IaC scanning)</p></li><li><p>Triage vulnerabilities across application, container, and cloud findings, and drive remediation with risk-based SLAs</p></li><li><p>Define and run the vulnerability management lifecycle: intake, prioritization, exception handling, validation, and reporting</p></li><li><p>Improve CNAPP coverage and finding quality across cloud accounts and workloads</p></li><li><p>Improve Kubernetes and container security posture</p></li><li><p>Monitor, investigate, and respond to security events and incidents</p></li><li><p>Build automation to improve security operations, access workflows, and incident response</p></li><li><p>Support the wider teams by providing timezone coverage for our fully remote organization.</p></li></ul><h2>Who You Are:</h2><h2>Essential-</h2><ul><li><p>5+ years of experience in security engineering, product security, cloud/platform security, or closely related roles</p></li><li><p>Strong hands-on experience securing cloud environments (AWS, Azure and GCP)</p></li><li><p>Comfortable owning technical security problems end-to-end in fast-moving environments</p></li><li><p>Hands-on experience with product/application security in engineering environments (secure design reviews, threat modeling, code-level risk discussions)</p></li><li><p>Experience operating AppSec tooling and processes at scale (SAST, SCA, secrets, IaC scanning)</p></li><li><p>Strong vulnerability triage and remediation management experience, including risk-based prioritization and SLAs</p></li><li><p>Experience with CNAPP (or equivalent cloud security platforms) and tuning findings for engineering actionability</p></li><li><p>Working knowledge of Kubernetes/container security in production systems</p></li><li><p>Ability to partner with developers and platform teams to ship secure defaults without blocking delivery</p></li><li><p>Comfortable writing scripts and automations to improve security reliability and scale</p></li><li><p>Experience in incident response, investigation, and post-incident hardening in cloud-native environments</p></li><li><p>Security-minded, detail-oriented, and a proactive communicator in remote-first teams</p></li></ul><h2>Advantageous-</h2><ul><li><p>Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI)</p></li><li><p>Offensive security/pentesting background and ability to convert findings into durable engineering fixes</p></li><li><p>Experience scaling security at a startup from early stage to audit-ready maturity</p></li><li><p>Relevant security certifications (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certs)</p></li></ul><h2>What We Offer:</h2><ul><li><p><strong>Compensation & Equity:</strong> Competitive salary, meaningful stock options, comprehensive benefits and 401k plan</p></li><li><p><strong>Growth:</strong> Opportunity to learn from and collaborate with top security and AI experts</p></li><li><p><strong>Impact</strong>: Work on complex technical challenges that support the foundation of our company</p></li><li><p><strong>Remote-First</strong>:Work from anywhere, with regular opportunities to meet in person</p></li></ul><p><strong>What Else You Should Know:</strong></p><p>• <strong>Location:</strong> Remote: US, Canada, Argentina. All team members are remote but we meet regularly and you're supported to travel to collaborate with colleagues in person</p><p>• <strong>Contract:</strong> Full-time.</p><h2>Hiring Process:</h2><p>30-min introductory chat with your Talent Partner</p><p>30 minutes with the Hiring Manager.</p><p>1 hour technical deep dive.</p><p>30 minutes with the Deputy CISO</p><p>30-min final meeting with our CISO</p><p>We're a security company that builds with AI at the core — so you'll be protecting a team that moves fast, iterates aggressively, and lives in the command line. If that sounds like your kind of environment, let's talk.</p>
AL, AK, AZ, AR, CA, CO, CT, DE, FL, GA, HI, ID, IL, IN, IA, KS, KY, LA, ME, MD, MA, MI, MN, MS, MO, MT, NE, NV, NH, NJ, NM, NY, NC, ND, OH, OK, OR, PA, RI, SC, SD, TN, TX, UT, VT, VA, WA, DC, WV, WI, WY
Engineering