HighLevel logo
HighLevel

Lead Security Engineer

🕐 7 dias atrás📍 India🌍 Remoto

What You’ll Be Doing:

  • Lead Application Security initiatives across HighLevel’s products and engineering teams.
  • Proliferate security standards recommended by central security team as best practices within Dev teams.
  • Conduct architecture reviews, secure design assessments, and threat modeling for new features and platforms.
  • Perform security assessments for Web, Mobile, and API-based applications.
  • Define and drive secure SDLC practices across engineering teams.
  • Partner with developers to identify, prioritize, and remediate security vulnerabilities.
  • Lead security reviews for AI/LLM-powered applications, agents, and AI integrations.
  • Develop security guardrails for AI systems, including protections against prompt injection, data leakage, insecure tool usage, model abuse, and emerging AI attack techniques.
  • Improve security tooling and automate security testing within CI/CD pipelines.
  • Champion secure coding practices through developer enablement, documentation, and training.
  • Drive vulnerability management efforts and improve remediation workflows.
  • Mentor engineers and foster a strong security-first engineering culture.
  • Drive cross-functional collaboration by communicating complex security risks to technical and non-technical stakeholders, influencing product roadmaps, and ensuring alignment between security priorities and engineering objectives.
  • Stay current with emerging threats, application security trends, and advancements in AI security.

What You’ll Bring:

  • 8+ years of experience in Cybersecurity, with deep expertise in Application Security and leading engineering-focused security initiatives.
  • Comprehensive technical knowledge in securing Web, Mobile (Android/iOS), and API (REST/GraphQL) environments, including OWASP standards and authentication protocols (OAuth 2.0, OIDC, JWT, SAML).
  • Proven experience performing security assessments including threat modeling, secure design/code reviews, penetration testing, and architecture reviews.
  • Hands-on DevSecOps proficiency: automating security in CI/CD pipelines, container security (Kubernetes/Docker), and managing security tooling (SAST, DAST, SCA, Secret Scanning).
  • Specialized expertise in AI/LLM security, including mitigation of prompt injection, data leakage, model misuse, and insecure agent/tool integration.
  • Proficiency in programming/scripting (Python, Go, JavaScript, or Bash) and strong communication skills to influence technical stakeholders across product and engineering teams.

Preferred Qualifications:

  • Experience securing workloads on Google Cloud Platform (GCP).
  • Experience with Infrastructure as Code security (Terraform).
  • Familiarity with CSPM/CNAPP solutions.
  • Experience leading or participating in Red Teaming, adversary simulation, or purple team exercises.
  • Experience with DevSecOps and security automation.
  • Security certifications such as CEH, OSCP, GWAPT, CISSP, GCP Professional Cloud Security Engineer, or similar.
  • Contributions to open-source security projects, bug bounty programs, or security research.

🇧🇷 Essa vaga exige inglês. Você está pronto?

A DevSpeak Academy prepara desenvolvedores brasileiros para conquistar vagas internacionais. Domine o inglês técnico com professores que entendem o mundo dev.

Conheça a DevSpeak Academy