Senior Security Engineer - Cloud-Native Application Security

Jobgether • Switzerland
Remote
Apply
AI Summary

Lead application security practices across the software development lifecycle, securing cloud-native environments on AWS and Kubernetes/EKS. Design and implement service mesh security controls, automate security guardrails, and ensure compliance with frameworks like SOC 2 and ISO 27001. Collaborate with engineering teams to embed security into product development and protect sensitive user data.

Key Highlights
Strengthen security across modern cloud-native applications and infrastructure
Implement service mesh security controls including authentication and encryption
Develop security guardrails and automation through policy-as-code frameworks
Improve software supply chain security with secure build and release processes
Work with regulated frameworks such as HIPAA, SOC 2, and ISO 27001
Key Responsibilities
Lead and continuously improve application security practices across the software development lifecycle
Strengthen cloud and containerized environments by implementing and maintaining security controls
Design, implement, and enhance service mesh security controls
Develop security guardrails and automation through policy-as-code frameworks
Improve software supply chain security by establishing secure build and release processes
Drive vulnerability management initiatives including risk assessment and remediation coordination
Implement and maintain technical security controls supporting compliance frameworks
Partner with engineering, platform, and operations teams to design and deploy security services
Technical Skills Required
Application security Threat modeling Secure code review API security AWS security Kubernetes/EKS security Istio service mesh Go programming Python programming Terraform CI/CD pipeline security Kyverno OPA Cilium Vulnerability management Compliance frameworks Data protection requirements
Benefits & Perks
Competitive compensation package
Equity or stock option opportunities
Full equipment and technology setup provided
21 days of annual leave in addition to public holidays
Fully remote work option for eligible candidates
Flexible and collaborative international work environment
Exposure to large-scale products used by millions of users worldwide
Career growth opportunities within a high-performing engineering organization
Nice to Have
Supply chain security tools
Penetration testing
Offensive security practices
Bug bounty programs

Job Description


This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer based in Switzerland.

As a Senior Security Engineer, you will play a key role in strengthening security across modern cloud-native applications and infrastructure in a fast-paced, product-driven environment. Working across application security, cloud platforms, Kubernetes ecosystems, and secure software delivery practices, you will help embed security into every stage of the development lifecycle. This position offers the opportunity to influence architecture, implement scalable security controls, and collaborate closely with engineering and platform teams. You will contribute to protecting sensitive user data while supporting innovation and operational excellence. The role combines hands-on technical work with strategic security initiatives, making a direct impact on product reliability, compliance, and customer trust. It is an ideal opportunity for an experienced security professional who thrives in highly collaborative and engineering-focused environments.

Accountabilities

  • Lead and continuously improve application security practices across the software development lifecycle, including secure design reviews, threat modeling, code reviews, and integration of automated security testing tools.
  • Strengthen cloud and containerized environments by implementing and maintaining security controls across AWS, Kubernetes/EKS, identity and access management, network segmentation, workload security, and secrets management.
  • Design, implement, and enhance service mesh security controls, including authentication, authorization, encryption, and secure service-to-service communication.
  • Develop security guardrails and automation through policy-as-code frameworks, reusable templates, and developer-friendly self-service security tooling.
  • Improve software supply chain security by establishing secure build and release processes, artifact validation, dependency visibility, image signing, and provenance controls.
  • Drive vulnerability management initiatives, including risk assessment, prioritization, remediation coordination, and validation of security improvements.
  • Implement and maintain technical security controls supporting compliance frameworks and data protection requirements, including access control, encryption, logging, monitoring, and audit readiness.
  • Partner with engineering, platform, and operations teams to design, deploy, operate, and continuously improve security services and processes.

Requirements

  • Minimum 5 years of experience in security engineering, application security, cloud security, or software engineering with a strong focus on security.
  • Strong expertise in application security, including threat modeling, secure code review, API security, and mitigation of common application and API vulnerabilities.
  • Hands-on experience securing production environments running on AWS and Kubernetes/EKS.
  • Practical experience implementing and managing security controls within service mesh environments such as Istio.
  • Strong programming skills in Go or Python, with the ability to develop automation, tooling, and integrations.
  • Experience securing CI/CD pipelines and working with Infrastructure as Code technologies, including Terraform, GitOps workflows, or similar platforms.
  • Knowledge of Kubernetes security, networking, and policy enforcement tools such as Kyverno, OPA, or Cilium.
  • Ability to translate security, privacy, and compliance requirements into effective technical solutions.
  • Experience working within regulated environments governed by frameworks such as HIPAA, SOC 2, ISO 27001, or similar standards.
  • Strong ownership mindset with the ability to independently drive projects from concept through operational maturity.
  • Excellent written and verbal communication skills in English.
  • Additional experience with supply chain security tools, penetration testing, offensive security practices, or bug bounty programs is considered an advantage.

Benefits

  • Competitive compensation package aligned with experience and expertise.
  • Equity or stock option opportunities.
  • Full equipment and technology setup provided.
  • 21 days of annual leave in addition to public holidays.
  • Fully remote work option for eligible candidates.
  • Flexible and collaborative international work environment.
  • Opportunity to work with modern cloud-native technologies and security tooling.
  • Exposure to large-scale products used by millions of users worldwide.
  • Career growth opportunities within a high-performing engineering organization.

How Jobgether Works

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.


Similar Jobs

Explore other opportunities that match your interests

Security and Compliance Lead

Cyber Security
•
3w ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

blp

Switzerland
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

nava software solutions

United State

Senior Security Researcher

Cyber Security
•
3h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

CrowdStrike

Germany

Subscribe our newsletter

New Things Will Always Update Regularly