
location_onUnorganized Borough, United States
We are seeking a hands-on Senior Full Stack + DevSecOps Platform Engineer to lead the development of an internal security automation platform. This role is distinct from a traditional full-stack position; it requires a unique blend of application development, infrastructure design, and deep security expertise. You will be instrumental in building a centralized system for SBOM and CBOM inventory, orchestrating vulnerability scanning, and implementing AI-driven auto-remediation workflows.
In this position, you will design CI/CD pipelines that integrate security scanning tools directly into the development lifecycle. Your work will focus on identifying and automating safe fixes for critical issues such as weak cryptography, expired certificates, and vulnerable dependencies. You will ensure that all AI-assisted remediations are rigorously validated through comprehensive build, test, and audit workflows before any code is merged or deployed.
Your day will involve building robust applications using Java/Spring Boot while simultaneously engineering the cloud infrastructure on AWS that supports them. You will design dashboards to visualize application inventory, vulnerability posture, and remediation SLAs. A significant portion of your time will be spent collaborating with application, security, and DevOps teams to troubleshoot complex issues across the stack, from container image scanning to runtime TLS configurations.
You will also be at the forefront of integrating AI coding agents like Claude into our engineering workflows, ensuring they are used safely and effectively to accelerate remediation efforts without compromising security standards.
Interested candidates should submit their applications and inquiries directly to hirings@openkyber.com.
Work model: Hybrid
Unorganized Borough, United States
Experience building internal developer platforms or security automation platforms. Experience with vulnerability management and remediation workflows. Experience with policy engines such as OPA or custom rule engines. Knowledge of post-quantum cryptography readiness and crypto-agility. Experience with certificate lifecycle management, secrets management, and cloud security controls. Frontend experience with Angular or React for dashboards and reporting.