Security Engineer, Kong

Security Operations/Incident Response

CA$153-188.2k

Salary dependent on specific candidate location, role, skill set, and level of experience

AWS
GCP
Python
Linux
Go
Ruby
Rust
Senior and Expert level
Remote in Canada, US

More information about location

Kong

Microservice API gateway

Open for applications

Kong

Microservice API gateway

501-1000 employees

B2BEnterpriseAPICloud Computing

Open for applications

CA$153-188.2k

Salary dependent on specific candidate location, role, skill set, and level of experience

AWS
GCP
Python
Linux
Go
Ruby
Rust
Senior and Expert level
Remote in Canada, US

More information about location

501-1000 employees

B2BEnterpriseAPICloud Computing

Company mission

To build the nervous system that will safely and reliably connect all of humankind!

Role

Who you are

  • At Kong Inc., we value a diversity of voices. The following is not a laundry list, but to be effective in this role, you should possess most of the following and an interest in learning more about the rest
  • Expertise in building and operating security information/event management systems (SIEM), including investigating threats, developing metrics and dashboards, normalizing data feeds, and integrating with other tools
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs) and experience with “Detection as Code.”
  • Proven expertise in managing and operating SIEM systems; familiarity with CrowdStrike and LimaCharlie SecOps Cloud Platform preferred
  • Demonstrated ability to use Tines, the smart, secure workflow builder, to automate processes that detect, contain, and eliminate active malicious agents. This includes designing and implementing automation workflows that enhance our security response capabilities and operational efficiency
  • Experience in securing, developing detections, and responding to incidents in one major public cloud infrastructure, such as Amazon Web Services (AWS) or Google Cloud Platform (GCP)
  • Experience in effectively leading large and complex security incidents from detection to remediation
  • Familiarity with modern security frameworks and best practices, such as the MITRE ATT&CK framework and NIST CSF
  • Proficiency in one or more general-purpose programming languages such as Python, Ruby, Go, or Rust
  • Experience with Linux administration at scale, associated intrusion/manipulation techniques, and standard methodologies for system hardening and process isolation

Desirable

  • Experience in building a Detection Engineering Pipeline and leading threat hunts
  • Published research in detection engineering or threat intelligence
  • Developed automation to enhance security operations

What the job involves

  • As a Security Engineer specializing in detection and response, you will play a pivotal role in safeguarding Kong’s platforms against sophisticated cybersecurity threats
  • This dynamic position involves directing our Security Incident Response Team (SIRT), enhancing our incident response strategies, and providing mentorship to develop team expertise
  • Your efforts in evolving our Detection and Response program will be crucial—through pioneering advanced frameworks, integrating cutting-edge automation, and crafting essential performance metrics; you will lead initiatives that significantly boost our defenses and operational efficiencies
  • Direct our Security Incident Response Team (SIRT), leveraging strategic frameworks, state-of-the-art technologies, and rigorous processes to swiftly identify, manage, and mitigate security incidents. Focus on minimizing the impact of these incidents through effective response and recovery strategies
  • Engineer sophisticated detection systems and analytics to proactively identify and neutralize threats across diverse environments, including cloud, corporate, and edge infrastructures
  • Foster strong partnerships with Engineering, Risk Management, Compliance, and other critical departments to ensure security measures are perfectly integrated with the broader business goals and objectives
  • To strengthen our security infrastructure, we continuously assess, select, and optimize a blend of custom and commercial security tools, including EDR, anti-phishing technologies, and SIEM systems
  • Craft and refine advanced strategies, create resilient frameworks, and implement process automation to elevate the maturity of our Detection and Response programs. Develop critical metrics to measure effectiveness and drive continuous improvement
  • Design and maintain comprehensive incident response playbooks and detailed documentation to guide the security team's actions during incidents and ensure consistency in response strategies
  • Lead proactive threat-hunting initiatives to uncover hidden risks and vulnerabilities. Manage and enhance our security simulation program, including conducting rigorous tabletop exercises to test and improve incident response tactics
  • Engage actively in on-call rotations, providing expert support and rapid responses to emergent security issues, ensuring 24/7 protection for our operations
  • Developing the security event simulation program and conducting security event tabletop exercises
  • Oversee and cultivate strategic partnerships with external vendors and Managed Detection and Response (MDR) services, ensuring they align with our security objectives and deliver exceptional support and technology

Our take

Kong provides a cutting-edge API and service lifecycle management platform tailored for modern architectures, such as microservices, containers, cloud, and serverless environments. With a focus on flexibility, scalability, speed, and performance, Kong allows developers and Global 5000 enterprises to securely connect and orchestrate microservice APIs for today's sophisticated applications.

The core products offered by Kong include Kong, an open-source API and Microservices management solution Galileo, a platform for API analytics and debugging; Gelato, a platform for creating developed portals for PIs and Microservices; and API Marketplace, a hub for discovering and publishing cloud APIs. Additionally, the recent introduction of a new collection of AI plug-ins in Kong Gateway 3.6 enhances the platform's capabilities further, reinforcing its commitment to innovation and advancement.

In pursuit of growth, the company is prioritizing expanding its marketing efforts, bolstering its customer service team, and accelerating product development. By focusing on these key areas, Kong aims to continue providing unparalleled solutions and support to its ever-expanding user base in the rapidly evolving landscape of modern application development.

Kirsty headshot

Kirsty

Company Specialist

Insights

Led by a woman
Top investors

Some candidates hear
back within 2 weeks

23% female employees

2% employee growth in 12 months

Company

Funding (last 2 of 6 rounds)

Feb 2021

$100m

SERIES D

Mar 2019

$43m

SERIES C

Total funding: $169.1m

Company benefits

  • Flexible time off: Take time to take care of yourself and the things that matter most
  • Stock options: We want you to share in our success. That's why stock options are offered to most Kongers
  • U-First Fridays: Get 4 hours a month for continuous learning with a book, podcast, or course of your choice
  • Virtual events: Stay connected with Donut chats, trivia, fitness challenges, guided meditations, and more
  • Dedicated unplug days: Silence those notifications. Enjoy some well-deserved long weekend where the entire team unplugs
  • Home office stipend: Build a home office environment tailored to support your productivity

Company values

  • Global: Be inclusive. We work together from anywhere to achieve our common goals. Our differences make us stronger
  • Real: Be authentic. We are genuine, principled and confident without arrogance. Show respect and kindness, especially in tough moments
  • Unstoppable: Be relentlessly resourceful. We work with purpose, obsession and grit. It takes muscle to do hard things and doing hard things build muscle
  • Champions: Be customer obsessed. We care. Customers are everything, we put them at the center of everything you do. We are all empowered to make an impact
  • Explorers: Be curious. We value ideas over hierarchy. Never accept the status quo. We make bold bets, fail, and learn everyday. There is always a way
  • Own it: Be an owner. We are drivers not passengers and own the quality and outcomes of our work

Company HQ

The East Cut, San Francisco, CA

Founders

Previously founded Mashape API Marketplace. Before Mashape, Augusto was an SF homeless immigrant from Italy.

Janet Phillips

(Vice President of People)

Previously Director at SonicWALL for 5 years and Senior Director at Symantec for 7 years.

Previously co-founded MemboxX, an online service for storing documents and small pieces of personal data.

Share this job

View 21 more jobs at Kong