EU remote
Senior Security Engineer
About this role
About Kestra Kestra is the universal orchestration platform : open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems. Trusted by over 10,000 organizations worldwide , including JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole , Kestra orchestrates mission-critical workloads at scale. The open-source project has close to 30,000 GitHub stars , hundreds of contributors, and a fast-growing global community.
About the role Kestra runs arbitrary, user-defined code at scale. Our users write workflows that execute scripts, containers, and queries against their own production systems, through hundreds of community-built plugins, on a platform whose entire source code is public. That is an unusually rich attack surface, and securing it is a genuinely hard engineering problem rather than a checklist exercise. You would be our first dedicated security hire.
We're looking for a Senior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem. This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.
This is a hands-on engineering role, not a GRC or compliance one. What you would do Your first six months would focus on the first three points below. The rest is where the role grows. Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments. Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure.
Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation. Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats. Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production. Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks.