Logo for Kong Inc

Senior Security Engineer

Role overview

Qualifications

  • 5+ years of experience in Cybersecurity Engineering with a focus on high-traffic infrastructure or API management.
  • Expert-level knowledge of multi-cloud security design, capable of securing traffic across AWS, Azure, GCP, and on-premises Kubernetes environments.
  • Proven experience designing and deploying WAF, IDS, and IPS systems at scale, with understanding of signature-based vs ML-based detection.
  • Programming proficiency in Python, Go, or Rust; open-source security contributions are a significant asset.

Responsibilities

  • Architect and implement next-generation WAF, IDS, and IPS at the gateway level to protect against OWASP Top 10, zero-day exploits, and API abuse.
  • Design and implement Zero Trust security models across multi-cloud and hybrid environments (AWS, Azure, GCP, on-prem).
  • Define and drive the multi-year security roadmap for Kong Gateway in collaboration with Product and Architecture, balancing OSS community needs with Enterprise requirements.
  • Lead incident response for complex security challenges (e.g., supply chain vulnerabilities in open-source dependencies and CVE remediation) while mentoring engineers on secure coding practices to raise the organization's cybersecurity maturity.

About the company

Kong Inc logo

Kong Inc

API & Integration Platforms (iPaaS)

Powering the API World. Kong enables any company to become an API-first company. Kong’s unified cloud native API platform is easy to use and works in any environment — unleashing developer productivity, automating security, and boosting performance of APIs and microservices at scale.

Company details

Company typeSME
IndustryAPI & Integration Platforms (iPaaS)
Company size501 - 1000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Are you ready to power the World's connections?

If you don’t think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we’re looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.

About the Role:

As a Senior Security Engineer, you will serve as the technical security lead for securing the world’s most popular API gateway. You will apply deep expertise in high-performance networking and distributed systems to shape the security posture of the Kong Cloud. You’ll spend your time architecting the evolution of our security capabilities—specifically focused on leveraging Open Source (OSS) and building state of the art network and application security solutions..

What you'll do:

  • Threat Defense Leadership: Architect and implement next-generation WAF, IDS, and IPS capabilities at the gateway level to protect against OWASP Top 10, zero-day exploits, and sophisticated API abuse.

  • Multi-Cloud Security: Design and implement "Zero Trust" security models that operate seamlessly across hybrid and multi-cloud environments (AWS, Azure, GCP, On-prem).

  • Strategic Roadmap: Partner with Product and Architecture leads to define the multi-year security roadmap for Kong Gateway, balancing the needs of the OSS community with Enterprise requirements.

  • Incident Resolution: Lead the response to complex, multi-faceted security challenges—from supply chain vulnerabilities in open-source dependencies to high-stakes CVE remediations.

  • Mentorship & Influence: Champion a "Security-First" culture by mentoring engineers on secure coding practices and influencing the long-term cybersecurity maturity of the entire organization.

What you'll bring:

  • 5+ years’ experience in Cybersecurity Engineering, with a focus on high-traffic infrastructure or API management.

  • Cloud-Native & Multi-Cloud: Expert-level knowledge of multi-cloud solution design, specifically securing traffic across disparate cloud providers and Kubernetes environments.

  • Security Domain Specialist: Proven track record in designing/deploying WAF, IDS, and IPS systems at scale, with an understanding of signature-based vs. ML-based detection.

  • Programming Proficiency:Python, Go or Rust

  • Open Source Contributor: Experience contributing to or maintaining open-source security projects is a significant asset.

  • Design Excellence: Ability to produce high-quality, high-performance security designs that do not compromise the "millisecond-latency" promise of the gateway.

#LI-BR2

About Kong:

Kong Inc., a leading developer of API and AI connectivity technologies, is building the infrastructure that powers the agentic era. Trusted by the Fortune 500 and startups alike, Kong's unified API and AI platform, Kong Konnect, enables organizations to secure, manage, accelerate, govern, and monetize the flow of intelligence across APIs and AI models. For more information, visit www.konghq.com.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Kong Inc

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.