Are you a talented developer looking for a remote job that lets you show your skills and get decent compensation? Join Upstaff.com, a platform that connects you with hand-picked startups and scale-ups in the US and Europe.
The role
This is a senior security engineering position with a strong emphasis on penetration testing and threat modeling. You'll work across the full security lifecycle: designing secure architectures, modeling threats, researching emerging attack vectors, and validating defenses through hands-on testing.
The focus is on long-term security improvements — identifying and addressing risks before they become incidents. You'll need both the attacker's mindset to find vulnerabilities and the engineering skills to help fix them properly.
What you'll work on
- Penetration testing and security assessments against web applications and internal systems
- Leading security design reviews and threat modeling for new products and infrastructure changes
- Researching emerging threats and attack techniques, then translating findings into practical defense strategies
- Building security automations and tools, and prototypes to support testing and detection
- Collaborating with engineering teams to remediate vulnerabilities and improve secure development practices
- Contributing to security architecture decisions and standards
What we're looking for
- 7+ years in security engineering with substantial experience in both offensive and defensive work
- Proven, hands-on web applications penetration testing experience
- Strong programming skills, preferably Python, with experience building security tools or automation
- Deep expertise in at least one core security domain: cryptography, authentication/authorisation, secure architecture, or network security
- Clear understanding of attack vectors and methods and how to anticipate them
- Good communication skills in English
Useful additions
- Experience securing serverless architectures or AI/ML platforms
- Background in cloud-native security (AWS, GCP, Kubernetes)
- DevSecOps experience- integrating security into CI/CD pipelines
- Relevant certifications (OSCP, OSCE, CISSP, or similar)
Not your tech stack?
Join the Upstaff community and we are looking for the best project for you. Be ready for the next steps:
- Create your profile on our website (import from LinkedIn)
- 20-30-minute screening call
- Technical interview
- Feedback
- Project Selection (we are looking for the best project for you).
We work with developers from 50+ countries in different regions: Europe, LATAM, the U.S. (W-9 form owners), Canada, Asia (Philippines, Indonesia), Oceania (Australia, New Zealand, Papua New Guinea), and the the UK.
- We don’t have a legal and ethical basis to accept applicants from the following countries: Russia, Belarus, Iran, North Korea
- We do not provide visa assistance, and our cooperation model does not include the benefits typically offered with direct hire.