Remote
Security Engineer | Mid - Senior
About this role
As a Security Engineer at nexos.ai you will own the security of the cloud and Kubernetes platform behind a live AI product - an environment where AI is both the product and the primary risk surface, and where AI-specific attack paths are part of the threat model, not an afterthought. You will bring an attacker's mindset to defense, work closely with the SOC and DevOps teams, and act as the internal technical anchor that bridges cloud security, detection, and engineering, with the Information Security Lead as your strategic counterpart.
Main Responsibilities: - Own the security of nexos.ai cloud and Kubernetes infrastructure - triage findings, set priorities, assess the impact of changes, drive remediation to completion within reasonable timeframes, and develop policies for an environment where AI is both the product and the attack surface. - Harden Kubernetes and cloud infrastructure end-to-end - covering container security, network policies, identity, and secrets management.
- Own the resolution of SOC-escalated alerts - investigating findings, making sound judgments on what requires action, and coordinating remediation with DevOps and engineering teams. - Continuously identify security gaps across the environment - drive remediation, propose improvements, and engage the right teams and stakeholders based on the scope and impact of each issue. - Conduct cloud and AI-focused threat modeling and proactive threat hunting - identifying realistic attack paths and closing them before they can be exploited.
- Embed security into CI/CD pipelines, infrastructure-as-code, and GitOps delivery - automated scanning, pipeline gates, and shift-left practices. - Build scripts and automation to eliminate repetitive security tasks and improve operational efficiency. Core Requirements: - A solid foundation in security engineering - cloud, application, or infrastructure - with a demonstrated appetite for learning new domains and a track record of mastering them.
- Solid working knowledge of cloud environments, container security, or infrastructure-as-code - AWS experience is a strong plus. - Experience in alert triage, incident investigation, or security operations; comfortable making judgment calls and driving findings to resolution. - Threat modeling experience or a strong intuition for how attackers think - able to identify realistic attack paths and translate them into defensive action.