SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
XBOW is seeking an experienced Security Engineer to secure the company's product, cloud, and platform as it scales. This is a hands-on technical individual contributor role focused on embedding security into design, shipping, and operations.
You will work closely with engineering and platform teams across application security, cloud security, vulnerability management, and incident response. Core responsibilities include:
- Design and implement security controls across cloud, infrastructure, and internal platforms
- Partner with engineering to harden cloud architecture, IAM, and infrastructure
- Own product security reviews for new features, services, and major architecture changes
- Drive threat modeling and secure design decisions early in the software development lifecycle
- Operate and improve AppSec workflows (SAST, SCA, secrets scanning, IaC scanning)
- Triage vulnerabilities across application, container, and cloud findings, and drive remediation with risk-based SLAs
- Define and run the vulnerability management lifecycle: intake, prioritization, exception handling, validation, and reporting
- Improve CNAPP coverage and finding quality across cloud accounts and workloads
- Improve Kubernetes and container security posture
- Monitor, investigate, and respond to security events and incidents
- Build automation to improve security operations, access workflows, and incident response
- Support the wider team by providing timezone coverage for the fully remote organization
XBOW is a security company that builds with AI at its core. The environment moves fast, iterates aggressively, and operates in command-line-heavy workflows. The team is fully remote but meets regularly in person.
REQUIREMENTS:
Essential:
- 5+ years of experience in security engineering, product security, cloud/platform security, or closely related roles
- Strong hands-on experience securing cloud environments (AWS, Azure, GCP)
- Comfortable owning technical security problems end-to-end in fast-moving environments
- Hands-on experience with product/application security in engineering environments (secure design reviews, threat modeling, code-level risk discussions)
- Experience operating AppSec tooling and processes at scale (SAST, SCA, secrets, IaC scanning)
- Strong vulnerability triage and remediation management experience, including risk-based prioritization and SLAs
- Experience with CNAPP (or equivalent cloud security platforms) and tuning findings for engineering actionability
- Working knowledge of Kubernetes/container security in production systems
- Ability to partner with developers and platform teams to ship secure defaults without blocking delivery
- Comfortable writing scripts and automations to improve security reliability and scale
- Experience in incident response, investigation, and post-incident hardening in cloud-native environments
- Security-minded, detail-oriented, and a proactive communicator in remote-first teams
Advantageous:
- Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI)
- Offensive security/pentesting background and ability to convert findings into durable engineering fixes
- Experience scaling security at a startup from early stage to audit-ready maturity
- Relevant security certifications (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certs)