About Us:
As an AI Red Team Staff Software Engineer at Kenility, you’ll join a tight-knit family of creative developers, engineers, and designers who strive to develop and deliver the highest quality products into the market.
Technical Requirements:
- Bachelor’s degree in Computer Science, Software Engineering, or a related field.
- 8+ years of professional software engineering experience, including at least 2 years in a Staff Engineer position or a comparable technical leadership capacity.
- Demonstrated experience assessing, confirming, and supporting the remediation of security vulnerabilities across production applications, services, APIs, infrastructure, or software supply chain components.
- Strong proficiency in analyzing and reasoning about complex codebases, ideally involving Java, Kotlin, or other JVM-based backend technologies.
- Practical knowledge of application security testing approaches and tools, including SAST, DAST, SCA, secret detection, threat modeling, secure code reviews, and vulnerability validation.
- Experience applying AI-assisted engineering, security analysis, or automation techniques to strengthen software quality and security outcomes.
- Ability to convert security findings into actionable remediation recommendations, implementation-ready technical solutions, and risk-based priorities.
- Strong cross-functional collaboration and communication capabilities, particularly when partnering with Application Security, Engineering, Product, and Security Research teams.
- Solid understanding of cloud-native architectures, CI/CD processes, build pipelines, containerized environments, and modern DevOps practices.
- Commitment to improving security standards through technical leadership, mentoring, secure engineering practices, and continuous improvement initiatives.
- Relevant security certifications such as GSEC, GCIH, GCLD, GCID, GMON, CISSP, CC, SSCP, CCSP, CAP, or CSSLP are considered valuable.
- Minimum Upper Intermediate English (B2) or Proficient (C1).
Tasks and Responsibilities:
- Identify and prioritize significant security risks affecting proprietary code, services, infrastructure, build environments, and software supply chain dependencies.
- Assess security findings to determine exploitability, severity, impacted products, potential business consequences, and appropriate remediation priority.
- Partner with Security Research and Product teams to transform emerging vulnerabilities, malicious component discoveries, and evolving attack techniques into research deliverables, product enhancements, detection capabilities, and actionable customer intelligence.
- Collaborate with Application Security and Engineering teams to drive validated vulnerabilities through remediation while helping prevent recurring security weaknesses.
- Promote modern AI-SDLC practices by converting recurring vulnerability categories, insecure development patterns, and successful remediation techniques into reusable guidance, detection mechanisms, secure coding standards, and remediation playbooks.
- Develop concise remediation instructions, implementation-ready fix recommendations, and pull requests when appropriate.
Soft Skills:
- Responsibility
- Proactivity
- Flexibility
- Great communication skills