Apricot International Logo

Apricot International

Security Engineer

Posted 2 Days Ago
Remote
Hiring Remotely in USA
Mid level
Remote
Hiring Remotely in USA
Mid level
Assess and reduce security risks across AWS infrastructure, applications, CI/CD pipelines, containers, and AI/LLM integrations. Responsibilities include threat modeling, security reviews, integrating SAST/DAST/SCA tools, hardening cloud and Kubernetes environments, automating security and incident-response workflows, and remediating vulnerabilities from scans and bug bounty programs.
The summary above was generated by AI

This is a remote position.

Strengthen cloud, application, and AI security by embedding practical controls across infrastructure, delivery pipelines, and incident workflows.

Organization: A confidential client; further details will be shared with shortlisted candidates, subject to client confidentiality requirements
Location: Remote - open to candidates in Egypt, Jordan, and other countries nearshore to the client's operating region
Role Type: Full-time | Consultant/contractor | Fixed-term project (6-8 months)
Reports to: To be confirmed

The opportunity
Our client is looking for a Middle+ Security Engineer to assess and reduce security risk across AWS infrastructure, application delivery, containers, and LLM/AI integrations. In this role, you will combine hands-on security engineering with automation, vulnerability remediation, and cross-functional technical review.

About the organization
Our client is a UAE-based HRTech scale-up transforming workplace operations across HR, Payroll, Finance, and Insurance in the MENA region. It helps employers and employees manage the full workplace lifecycle through a unified platform.

What you will do

  • Conduct threat modeling and security reviews for cloud infrastructure and LLM/AI integrations.
  • Integrate SAST, DAST, and SCA tools directly into CI/CD pipelines.
  • Harden AWS environments, Infrastructure as Code scripts, and Kubernetes workloads and containers.
  • Automate repetitive security tasks, alerting, and incident-response workflows using custom scripts.
  • Triage, investigate, and remediate vulnerabilities identified through automated scans and Bug Bounty programs.

What you bring

  • At least 3 years of professional experience in Security Engineering, DevSecOps, or a related role.
  • Scripting proficiency in Python, Go, or Ruby.
  • Deep hands-on experience with AWS cloud security services (IAM, VPC, GuardDuty, WAF, Inspector).
  • Practical experience with AppSec tooling (Burp Suite, OWASP ZAP, Snyk, or SonarQube).
  • Experience with container and orchestration security controls (Docker, Kubernetes).
  • Knowledge of Infrastructure as Code (IaC) security reviews (Terraform or CloudFormation).
  • Familiarity with AI/LLM security risks (OWASP Top 10 for LLMs, RAG architectures, API security).

How the engagement works

Contracting party: You will contract directly with Apricot, which will manage contracting, invoicing/payroll, payments, and administrative support. Day to day, you will work closely with the client team and follow the agreed scope, deliverables, and security requirements.

You are expected to provide your own laptop and basic equipment, maintain reliable connectivity and a secure working environment, and follow required security controls, including two-factor authentication.

Planned check-ins are at month 1 to see how the engagement is working and help address issues, given the shorter 6–8 month duration.

About Apricot
Apricot is a nonprofit sourcing firm connecting displaced and underserved professionals from Palestine and the wider MENA region with global employment opportunities. We combine a clear social-impact mission with fast, high-quality recruitment delivery for international clients.


Similar Jobs

3 Hours Ago
Easy Apply
Remote or Hybrid
Easy Apply
110K-150K Annually
Senior level
110K-150K Annually
Senior level
Automotive • Greentech • HR Tech • Sales • Software
Own and improve enterprise security platforms, cloud and infrastructure security, identity governance, endpoint protection, vulnerability management, incident response, network controls, and DevSecOps practices. Lead complex security initiatives, compliance controls, vendor assessments, security architecture reviews, and AI security governance. Build automation with PowerShell and Python, partner with IT Operations and DevOps, reduce manual work, and serve as the senior escalation point for technical security incidents.
Top Skills: Amazon SesAuth0AWSAws Identity CenterAzureChatgpt EnterpriseCi/CdCisco DuoCisco MerakiCisco UmbrellaClaudeConditional AccessContainersCrowdstrikeDastDkimDmarcInfrastructure As CodeKnowbe4KubernetesMcpMicrosoft 365Microsoft Entra IdMicrosoft GraphNist CsfPimPowershellPythonRapid7 InsightappsecRapid7 InsightidrRapid7 InsightvmRapid7 MdrRest ApisSastScimSendgridSnykSoc 2SpfSsoVpn
2 Days Ago
Remote or Hybrid
TX, USA
70K-95K Annually
Entry level
70K-95K Annually
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Develops and strengthens threat detection, response, and remediation capabilities for CrowdStrike infrastructure. Responsibilities include researching attacker techniques, creating network and host-based detections, implementing security analytics and automation, investigating and remediating threats, supporting cloud security across major providers, tracking operational metrics, and collaborating on complex cross-functional programs. The role requires expertise in SIEM/SOAR technologies, cloud-native systems, programming, operating systems, networking, web security, and security engineering principles.
Top Skills: APIsDockerGoIaasKibanaKubernetesLinuxLogscalemacOSOauthOwaspPaasPythonSaaSSAMLSIEMSoarSplunkSsl/TlsTerraformWindowsXss
2 Days Ago
Remote or Hybrid
United States
80K-120K Annually
Mid level
80K-120K Annually
Mid level
Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Secure LLMs, generative AI systems, ML infrastructure, training pipelines, and AI applications. Responsibilities include threat modeling, architecture reviews, security controls, hardening, vulnerability remediation, data privacy, incident response runbooks, vendor reviews, governance, policy development, and AI security training. The role also supports proof-of-concept security solutions and monitors emerging AI threats.
Top Skills: AnsibleBashETLGdprGenerative AiGoInfrastructure As CodeKubernetesLarge Language ModelsPythonPyTorchScikit-LearnSoc 2TensorFlowTerraform

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account