Kairos
Back to jobs

Security Engineer

On-site
ArmadaBellevue, WA, US / Sunset Corporate Campus1 month agoWebsite
Aging
R&D - Engineering

Compensation

$130,824-$163,530/yr
Apply
Share

Description

About the Role

You will own security engineering across our Azure cloud, hybrid infrastructure, and edge computing platform. The work is hands-on: building detections, testing our own applications, hardening Kubernetes, and putting controls into CI/CD. You will also help define how we secure AI/ML workloads running at the edge. 

 

Location. This role is office-based at our Bellevue, Washington office. 

 

What You'll Do (Key Responsibilities)

Cloud and Infrastructure Security 

  • Design and implement security architecture across Azure, hybrid infrastructure, and edge deployments 
  • Manage SIEM (Microsoft Sentinel), EDR/XDR, WAF, email security, and CSPM/CNAPP tooling 
  • Write and tune detection rules, correlation logic, and automated response playbooks 
  • Lead incident response from triage through containment and remediation 

Offensive Security and Assessment 

  • Perform security assessments, vulnerability scanning, and penetration testing across cloud, infrastructure, and application layers 
  • Test web applications and APIs for authentication and authorization flaws, business logic abuse, and OWASP Top 10 issues 
  • Threat model new services and architectures before they ship 
  • Own the vulnerability lifecycle: risk-based prioritization, SLA tracking, and remediation follow-through with owning teams 
  • Maintain SAST, DAST, SCA, secrets scanning, IaC scanning, and container image scanning into CI/CD as automated gates 
  • Harden the software supply chain: build provenance, artifact signing, SBOM generation, dependency governance 
  • Enforce guardrails as policy-as-code using Azure Policy, OPA/Gatekeeper, or Kyverno 
  • Review designs and code with engineering teams and support secure deployments  

AI/ML Security 

  • Secure AI/ML development and deployment, including model and data supply chain integrity, inference endpoint exposure, prompt injection and agentic tool abuse, and training data governance 

Governance 

  • Maintain security policies, standards, and procedures aligned to NIST, ISO 27001, and SOC 2 
  • Produce audit evidence and support customer security assessments 
  • Track emerging threats and turn them into roadmap work 

 

Required Qualifications:

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience 
  • 5+ years in information security, including 3+ years focused on cloud security 
  • Strong hands-on experience with Azure security services including Defender for Cloud, Sentinel, Entra ID, Key Vault, Azure Policy, and network security 
  • Production experience with several of: SIEM, EDR/XDR, WAF, email security, CSPM/CNAPP, vulnerability management 
  • Experience securing Kubernetes and containerized workloads in production 
  • Experience embedding security testing into CI/CD pipelines using SAST, DAST, SCA, secrets scanning, and IaC scanning 
  • Hands-on application security testing experience covering web and API penetration testing and secure code review 
  • Proficiency with vulnerability management platforms such as Nessus, Nexpose, Qualys, or Defender Vulnerability Management 
  • Python and SQL/KQL for automation, tooling, and log analysis 
  • Working knowledge of NIST, ISO 27001, and SOC 2 
  • Incident response experience as a lead or primary responder 
  • U.S. Citizenship required 

 

Preferred Qualifications:

  • Experience securing edge, disconnected, or intermittently connected environments 
  • Experience securing AI/ML or LLM-based systems, including OWASP Top 10 for LLM Applications and MITRE ATLAS 
  • Detection engineering experience: writing and tuning KQL, detection-as-code, purple team exercises 
  • Infrastructure-as-code fluency with Terraform or Bicep 
  • Familiarity with MITRE ATT&CK for threat modeling and detection coverage mapping 
  • Experience supporting SOC 2 Type II or FedRAMP audit cycles 

Certifications 

At least one from either group is preferred. 

  • Defensive and architecture: CISSP, CCSP, Azure Security Engineer Associate (AZ-500), GCIH, GCIA 
  • Offensive: OSCP, OSWE, OSWP, OSEE, GPEN, GWAPT, CEH 

 

Citizenship Requirements 

For select roles, due to the nature of our clientele and the technologies involved, there may be specific nationality or citizenship indicated in the required qualifications section. These roles may involve access to sensitive information that is subject to export control regulations or other legal restrictions. In such cases, employment offers will be contingent upon your ability to comply with these requirements. 

 

Compensation

For U.S. Based candidates: To ensure fairness and transparency, the starting base salary range for this role for candidates in the U.S. are listed below, varying based on location experience, skills, and qualifications.

In addition to base salary, this role will also be offered equity and subsidized benefits (details available upon request).

 

Benefits

  • Competitive base salary and equity
  • Medical, dental, and vision (subsidized cost)
  • Health savings accounts (HSA), flexible spending accounts (FSA), and dependent care FSAs (DCFSA)
  • Retirement plan options, including 401(k) and Roth 401(k)
  • Unlimited paid time off (PTO)
  • 14 paid company holidays per year

#LI-ST1

#LI-Onsite

#770

Stack

LLMsPythonEmbeddingsAzureTerraformCI/CDSQLAgentic AIMachine LearningKubernetes
Posted
Jul 28, 2026
Last seen
Jul 29, 2026
First seen
Jul 29, 2026

Similar roles

Browse more AI jobs