Kestra Technologies logo

Kestra Technologies

Senior Security Engineer

Region Restricted

Remote work allowed only within certain countries or regions.

Europe

Employer listed it 5 days ago · Added yesterday

First listed 5 days ago and still open.

Salary

Not stated

Location

Europe

Work style

Async

Contract

Full-time

Experience

Senior

Category

Software

This employer didn't state pay. Jobs like this usually pay around $180k–$230k a year, a typical range taken from 596 senior-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Region Restricted

Remote work is allowed, but only for candidates based in Europe.

What the employer says

  • Source listing states candidate location: "Europe, India, Remote"

What Nomaders makes of it

  • Applications outside the listed area are usually rejected
  • Timezone overlap with the listed area is often expected

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About Kestra

Kestra is the universal orchestration platform : open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems.

Trusted by over 10,000 organizations worldwide , including JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole , Kestra orchestrates mission-critical workloads at scale. The open-source project has close to 30,000 GitHub stars , hundreds of contributors, and a fast-growing global community.

About the role

Kestra runs arbitrary, user-defined code at scale. Our users write workflows that execute scripts, containers, and queries against their own production systems, through hundreds of community-built plugins, on a platform whose entire source code is public. That is an unusually rich attack surface, and securing it is a genuinely hard engineering problem rather than a checklist exercise. You would be our first dedicated security hire. We're looking for a Senior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem. This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you. This is a hands-on engineering role, not a GRC or compliance one.

What you would do

Your first six months would focus on the first three points below. The rest is where the role grows.

Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments.

Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure.

Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.

Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats.

Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.

Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks.

Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies.

Own our public security posture as an open-source project: vulnerability disclosure process, CVE handling, security advisories, and the trust model of our plugin ecosystem.

Our Tech Stack

Security & Vulnerability Tools : Trivy, GitHub Security / Dependabot, Elastic Security

Infrastructure : Docker, Kubernetes, Terraform

Cloud : GCP

Programming language : Java, Typescript, Javascript

Datastore : PostgreSQL, Elasticsearch

Queuing : Redis, Kafka, AMQP

Monitoring & Logs : ELK, Prometheus, Grafana

Deployment & Repository : GitHub Actions, ArgoCD

Requirements

The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.

Benefits

  • ·Work from anywhere : We’re a remote-first company, so you can work from wherever feels like home. Plus, you’ll have access to coworking spaces worldwide if you ever need a change of scenery.
  • ·Health coverage : From medical support, dental, and vision, we've got you covered.
  • ·Home office setup on us : We’ll provide all the equipment you need to work comfortably.
  • ·Our Hiring Process
  • ·We aim to move quickly (2-3 weeks), but we can adjust the timeline if needed.

How to apply

  1. 1Check the flexibility label above, region restricted, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Kestra Technologies, mentioning your remote working experience and working hours (Async).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 1d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $180k to $230k per year · You'll be taken to the employer's careers page.