SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Software Engineer, Security

Super.com - Remote - Remote - posted 2026-08-26

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Super.com is seeking a Senior Software Engineer for its Security team to shape the direction of security tooling and AppSec practices across the organization. This role combines offensive and defensive security work: hardening product design and architecture, identifying vulnerabilities through advanced testing, and building tooling and AI-powered solutions that enable engineers to move fast without creating risk. You will report to the Staff Software Engineer - Security and work closely with product engineers, DevOps, and Fraud teams. The role offers high autonomy with frequent collaboration in a fast-paced environment. Key responsibilities include leading secure design across major engineering projects through threat modeling and architecture review, designing and evolving the DevSecOps architecture to embed security throughout the SDLC, building and extending in-house security tooling, identifying innovative applications of AI to automate security work, performing advanced offensive security work to demonstrate business impact, enabling developers through training and AI-powered tools, and mentoring engineers to raise security standards across the organization. Required qualifications include 5+ years of security experience (AppSec, DevSecOps, offensive security), professional offensive security experience with proven ability to find and exploit complex vulnerabilities, track record of leading security initiatives and mentoring engineers, experience with threat modeling and secure design, knowledge of embedding security in CI/CD pipelines and the SDLC, hands-on cloud infrastructure or cloud security experience (AWS, Kubernetes), comfortable writing and maintaining code (Python preferred), and strong communication skills to influence security work across teams. The technology stack includes Kubernetes-based microservices with Python FastAPI backends and TypeScript React frontends, Postgres, Redis, Kafka, Elasticsearch, and Snowflake databases, AWS infrastructure with EKS, MSK, Elasticache, and RDS, Istio service mesh, Helm, Terraform, Crossplane for IaC, Kyverno for policy enforcement, custom AI-native vulnerability management tooling, Datadog for security and application monitoring, and modern AI development workflows using Cursor, Claude, and internally built AI agents. Bonus qualifications include relevant security certifications (Burp Suite Certified Practitioner, KCSA, AWS SCS), professional software development experience, published security research or CVEs, experience applying AI/LLMs to security workflows, open-source security tool contributions, and mobile security experience.

Similar roles