hirly

Aptible

Senior Security Engineer

North America (PT-ET Time Zones)

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Aptible first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Role family
Engineering
Seniority
Senior
Stated salary
$162,000 – $184,000 per year
Country
US
Work mode
Remote-friendly
First seen by hirly
28 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

About Aptible

Large language models are transforming software engineering — developers can now go from idea to code faster than ever. But that just shifts complexity downstream: deployment, observability, cost, security, reliability — all of that has to scale too, and LLMs don't yet solve the problem.

That's where Aptible comes in. Since 2014, our cloud delivery platform has been automating security, compliance and reliability for engineering teams whose apps handle the most sensitive data, in the most highly regulated industries.

The need for a platform like Aptible has never been greater. If you're passionate about cloud infrastructure and ensuring DevOps evolves to meet the pressure of AI-assisted development — and you're excited to join a small and highly talented team — we’d love to hear from you.

NEW! Aptible is part of Opti9 Technologies, a cloud solutions provider specializing in managed cloud, security, disaster recovery, and compliance. Joining forces with Opti9 gives Aptible the resources to invest more aggressively in the platform — expanding what we can deliver to the engineering teams who depend on it.

Our Commitment to Diversity and Inclusion

We see great value in bringing together a team with different perspectives, educational backgrounds, and life experiences, and we prioritize diversity within our team. We encourage people from underrepresented backgrounds to apply.

About This Role

Overview

In this role, you'll be a hands-on security engineer defending and hardening a platform that regulated companies build their businesses on. This is an engineering role first; you'll design security-by-default infrastructure, run our vulnerability management program, drive our pentesting program (including working with tools like XBOW) from finding to fix, and lead incident response when things go wrong. You'll also bring the organizational rigor to run a compliance recertification when the underlying technical controls are already sound, but this is not a policy-writing or audit-management role, and it's not the core of the job.

This role reports to the Chief Information Security Officer (CISO), but works day-to-day in close collaboration with the Engineering team — not as a siloed security function reviewing work from a distance, but as an embedded partner co-owning the fixes, the infrastructure, and the outcomes.

What You'll Do

Engineering

Design and build security-by-default infrastructure across our AWS-based PaaS, which spans Ruby on Rails backend systems, a web app (React-TypeScript), a Terraform client (Go), a CLI client (Go), and several other distributed components (Python, Go, Ruby)

Own and mature our vulnerability management program — triaging findings and working findings from scanning tools and the AWS Security Agent in collaboration with the Engineering team, prioritizing by real-world exploitability and risk

Own our pentesting program end to end — running automated assessments with XBOW, coordinating manual and third-party testing, and driving remediation to closure in our codebase (Ruby, Go, TypeScript) and infrastructure alongside Engineering, rather than just filing tickets and waiting

Lead incident response operations: detection, containment, eradication, and post-incident review, with a bias toward fixing root causes in the code and infrastructure, not just symptoms

Build and maintain detection tooling, alerting, and runbooks — including tuning and extending the AWS Security Agent — to reduce time-to-response

Participate in on-call rotation for security-relevant incidents and help drive follow-ups that prevent repeats

Compliance

Run point on compliance recertifications and maintaining current standards (e.g., renewing SOC 2 or HITRUST) when the technical controls are already in place, this means being organized, coordinating evidence collection, and working with auditors, not authoring new policy from scratch

Use AI tools to improve your development and investigation workflow

What We're Looking For

General Experience

5+ years of experience in security engineering, with a track record of owning security-critical systems in production

You have experience as a hands-on security engineer, not just a security reviewer or policy writer — you can read and write code, operate infrastructure, and get into the weeds of a system under attack

You communicate extremely well — clear, effective, and proactive, both in writing and live during an incident

Developer tools or platform engineering experience is a plus

Technical Expertise

Strong engineering fundamentals and coding ability, with comfort working across a fullstack codebase — our stack includes Ruby on Rails, React/TypeScript, Go (Terraform client), and Ruby (CLI)

You're a prolific and thoughtful developer in at least one mainstream language, and can pick up new languages/frameworks quickly

Deep, hands-on experience with cloud infrastructure security (AWS strongly preferred), including AWS-native security tooling (e.g., AWS Security Agent, GuardDuty, Security Hub), and distributed systems

Real pentesting experience, including with automated/AI-assisted tools like XBOW, and a track record of driving remediation rather than just reporting findings

Experience running or significantly contributing to a vulnerability management program, from scanning and triage through verified remediation

Experience leading or heavily participating in incident response — you stay calm and methodical under pressure

Comfort working across identity management, network security, and detection tooling

Organizational Strength

You're organized enough to run a compliance recertification as a project — tracking evidence, coordinating stakeholders, and hitting deadlines — without that becoming your whole job

You know the difference between operating existing controls well and designing net-new policy, and you're energized by the former

Startup Compatibility

You want to be part of a small, highly collaborative team, and you work closely with Engineering rather than operating at arm's length

You don't let ambiguity or bumps in the road stop you: you identify what's blocking you, take ownership, and drive to get unblocked

You Should Apply If

You appreciate working in a highly autonomous, trusted role, where the day to day priorities may shift.

You want to do hands-on security engineering, designing, building, breaking, and fixing in real code — not just governance and paperwork

You're a deeply curious problem solver, and you're not tied to a specific language or technology

You're energized by incident response, vulnerability management, and pentesting, and see compliance as something you keep running smoothly, not something you build from scratch

You're invested in team ownership — you care about what your teammates are building, not just your own corner

Aptible's Employee Benefits

Aptible's Values & Principles

----

Why Aptible

Aptible has been around for over a decade. We have a real product, real customers who depend on it, and a profitable business. We're not a rocketship chasing hypergrowth — we're a small, tight-knit team doing meaningful work in a complex system. Together, we wield genuine ownership to drive lasting impact: the kind where our work shapes the whole product, not just a corner of it.

We'll be honest: this isn't an “everything is figured out” moment. We're navigating real change, with more on the way — and we're doing it together. We're not looking for someone who thinks they have all the answers already. We're looking for someone who wants to find them with us.

What keeps us here is each other. We're a team that genuinely cares — about the work, the customers (and the cool things they're building), and each other. If you want to do hard things alongside people you actually like and respect, and leave a lasting mark on a system that matters, this is that place.

Interview Process

We wan

Original posting on Aptible's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job
Senior Security Engineer – Aptible | hirly.me