SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Aptible is a cloud delivery platform that automates security, compliance, and reliability for engineering teams building applications in highly regulated industries. Since 2014, the company has served customers handling sensitive data across healthcare, fintech, and other regulated sectors. Aptible recently joined Opti9 Technologies, gaining resources to accelerate platform development.
In this Senior Security Engineer role, you'll be a hands-on security engineer embedded within the engineering team, not a siloed security function. You'll design security-by-default infrastructure, own vulnerability management and pentesting programs, lead incident response, and maintain compliance certifications (SOC 2, HITRUST). The role reports to the VP of Security but works day-to-day alongside the Engineering team as a co-owner of fixes and outcomes.
Key responsibilities include:
- Designing and building security-by-default infrastructure across an AWS-based PaaS platform spanning Ruby on Rails, React-TypeScript, Go (Terraform and CLI clients), Python, and other distributed components
- Owning the vulnerability management program end-to-end: triaging findings from scanning tools and AWS Security Agent, prioritizing by exploitability and risk
- Running the pentesting program: executing automated assessments with XBOW, coordinating manual and third-party testing, and driving remediation in codebases and infrastructure alongside Engineering
- Leading incident response operations (detection, containment, eradication, post-incident review) with focus on fixing root causes in code and infrastructure
- Building and maintaining detection tooling, alerting, and runbooks; tuning AWS Security Agent
- Participating in on-call rotation for security incidents
- Running compliance recertifications and maintaining current standards when technical controls are in place—coordinating evidence collection and working with auditors, not authoring new policy
- Using AI tools to improve development and investigation workflows
Aptible values pragmatic, hands-on security engineers who can read and write code, operate infrastructure, and get into the weeds of systems under attack. The team is small, tight-knit, and collaborative. The company is profitable with real customers and a decade-long track record, not a hypergrowth startup. You'll have genuine ownership and the ability to shape the whole product.
REQUIREMENTS:
- 5+ years of security engineering experience with a track record of owning security-critical systems in production
- Hands-on security engineering background (not just security review or policy writing); ability to read and write code, operate infrastructure, and respond to attacks
- Excellent communication skills—clear, effective, and proactive in writing and during incidents
- Strong engineering fundamentals and coding ability across fullstack codebases (Ruby on Rails, React/TypeScript, Go, Ruby)
- Proficiency in at least one mainstream language; ability to pick up new languages/frameworks quickly
- Deep, hands-on experience with cloud infrastructure security, strongly preferring AWS, including AWS-native security tooling (AWS Security Agent, GuardDuty, Security Hub) and distributed systems
- Real pentesting experience, including with automated/AI-assisted tools like XBOW, and a track record of driving remediation
- Experience running or significantly contributing to a vulnerability management program from scanning and triage through verified remediation
- Experience leading or heavily participating in incident response; ability to stay calm and methodical under pressure
- Comfort working across identity management, network security, and detection tooling
- Organizational capability to run compliance recertifications as a project (tracking evidence, coordinating stakeholders, hitting deadlines) without it becoming your whole job
- Understanding of the difference between operating existing controls well and designing net-new policy; energized by the former
- Desire to work in a small, highly collaborative team, embedded with Engineering rather than at arm's length
- Comfort with ambiguity and ownership mentality; ability to identify blockers and drive to resolution
- Developer tools or platform engineering experience is a plus