HighLevel

HighLevel

HighLevel provides an all-in-one sales and marketing platform that agencies can white label and resell, offering tools and resources designed to help businesses consolidate their marketing efforts and achieve their growth objectives.

Internet Software & Services
251-1K
Founded 2018
$60M raised

Description

  • Perform and lead manual and automated penetration testing across applications, APIs, and cloud services.
  • Drive threat modeling and secure architecture reviews across application and infrastructure layers.
  • Collaborate with Infra/DevOps on cloud network architecture, including VPC design, security groups, routing, and segmentation.
  • Design and advise on cloud-native security controls such as IAM hardening, role boundaries, secrets management, and least privilege.
  • Evaluate and improve Kubernetes and container security posture across runtime, image, and network layers.
  • Implement secure-by-default patterns across the SDLC, CI/CD, and Infrastructure-as-Code.
  • Monitor emerging threats, CVEs, and vulnerabilities relevant to the web, cloud, and infrastructure stack.
  • Influence internal security tooling, automation pipelines, and security review processes.
  • Serve as a security advisor to engineering, SRE, and product teams on key projects.

Requirements

  • 8+ years of total experience in Application Security, Security Engineering, or Penetration Testing roles.
  • Strong hands-on experience with threat modeling, secure architecture reviews, and penetration testing.
  • Familiarity with OWASP Top 10, STRIDE, and modern security frameworks.
  • Experience with tools such as Burp Suite, ZAP, Snyk, Metasploit, and Semgrep.
  • Ability to read and analyze code in JavaScript, Go, PHP, or Node.js.
  • Working knowledge of cloud security principles, preferably AWS.
  • Experience with multi-tenant SaaS platforms or white-labeled architectures is preferred.
  • Familiarity with network-level security concepts such as VPC design, IAM, and zero-trust networks is preferred.
  • Exposure to container security, including Docker and Kubernetes, is preferred.
  • Hands-on experience with IaC security and CI/CD pipelines such as GitHub Actions and Terraform is preferred.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Security Engineer II (Engineering & Tooling), Remote

Aledade 1K-5K Health Care Providers & Services

Aledade is hiring a Senior Security Engineer II to design and operate security tooling and infrastructure protections for a remote, cloud-focused environment supporting its healthcare platform.

Ansible Argo CD AWS Azure Bash Buildkite Chef CrowdStrike Cybersecurity Datadog DevSecOps Docker GCP Helm HIPAA Jenkins Kubernetes Network Security PowerShell Python SIEM Splunk Terraform
2 hours, 33 minutes ago

Blockchain Security Engineer (Smart Contract Auditing)

Binance 5K-10K Capital Markets

Binance is hiring a Blockchain Security Engineer to perform smart contract auditing and on-chain security analysis across wallets, blockchains, and related blockchain products in a remote role based in Taipei/Asia.

Blockchain Encryption Git Go Python Rust VS Code
2 hours, 48 minutes ago

Staff Threat Research Engineer

Sysdig 251-1K IT Services

Sysdig is hiring a Staff Threat Research Engineer to research cloud-based attacks and drive threat detection and security solutions for containers, Kubernetes, and cloud environments.

Cybersecurity Kubernetes Linux Penetration Testing
3 hours, 3 minutes ago

Senior Technical Lead for Systems Security

Pingwind 51-250 Internet Software & Services

PingWind is hiring a remote Senior Technical Lead for Systems Security to assess and strengthen security compliance for federal systems, with the main objective of ensuring required controls are met and risks are identified and mitigated.

Cybersecurity
3 hours, 3 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers