Himalayas logo
KongKO

Senior Security Engineer, Insomnia

Speed up time to market by unleashing developer productivity, automating security, and streamlining API management.

Kong

Employee count: 201-500

Salary: 145k-203k CAD

Canada only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Are you ready to power the World's connections?

If you don’t think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we’re looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.

About the role:

As a Security Engineer specializing in Vulnerability Management and Testing, you will be critical in ensuring the security of Kong Insomnia. This role focuses on identifying, triaging, and closing vulnerabilities while leveraging advanced security engineering to build and update automated testing pipelines. You will bring expertise in automated security testing while remaining hands-on in manual testing and validation processes.

A key aspect of this role will involve researching and understanding all components of the Kong Insomnia platform, including the underlying technologies and dependencies. Binary analysis is a critical skill, and you will be expected to analyze and reverse-engineer parts of the Kong Insomnia to uncover vulnerabilities and security weaknesses.

Your contributions will directly impact the security of Kong’s products by integrating robust security measures into CI/CD pipelines, conducting in-depth testing, and working closely with development teams to remediate vulnerabilities effectively and efficiently.

What you'll do:

  • This position will be responsible for performing Comprehensive Security Testing and Analysis:

  • Conduct both automated and manual testing to uncover vulnerabilities:

  • 1.Static Analysis: Detect insecure coding patterns during development.

  • Tools: GitHub Advanced Security (CodeQL), SonarCloud, Checkmarx CLI.

  • 2. Dynamic Application Security Testing (DAST): Identify runtime vulnerabilities such as XSS or SQL Injection.

  • Tools: OWASP ZAP CLI Runner, Burp Suite.

  • 3. Fuzz Testing: Discover unknown vulnerabilities through randomized inputs.

  • Tools: ClusterFuzzLite, libFuzzer.

  • 4. Dependency Analysis: Identify vulnerabilities in third-party libraries and components.

  • Tools: Dependabot, Snyk CLI, OWASP Dependency-Check.

  • 5. Environment Simulation and Sandboxing: Test software in isolated environments to simulate real-world attacks.

  • Tools: Docker, Minikube, Cuckoo Sandbox.

  • Responsibilities

  • Vulnerability Triage and Management: Identify, prioritize, and track vulnerabilities from multiple sources, including automated tools, penetration testing, and external reports. Collaborate with development teams to ensure timely remediation of findings.

  • This position will be responsible for Manual Testing and Validation: Conduct in-depth manual testing to identify vulnerabilities not covered by automated tools. Validate the accuracy of automated findings and ensure comprehensive coverage for critical systems. Provide detailed remediation guidance to development teams based on manual findings.

  • Work with Security Engineering to develop Automated Testing Pipelines: Design, implement, and maintain automated security testing pipelines using GitHub Actions. Integrate security tools into CI/CD workflows to enable continuous testing. Enhance pipeline efficiency by automating vulnerability identification, tracking, and validation processes.

  • Collaboration with Development Teams: Act as the primary security liaison for engineering teams, guiding secure coding practices and remediation strategies. Review and approve remediation actions to verify closure of identified vulnerabilities.

  • Process Development and Metrics: Establish workflows for vulnerability triage, testing, and closure. Develop and monitor metrics to measure the effectiveness and efficiency of vulnerability management processes.

What you'll bring:

  • To be effective in this role, you should possess most of the following skills and be eager to grow in the others:

  • Hands-on experience performing binary analysis to identify vulnerabilities and security weaknesses.

  • Direct experience using debuggers (e.g., GDB, WinDbg) to analyze binaries and investigate potential security flaws.

  • Expertise in building and managing automated security testing pipelines in CI/CD workflows.

  • Strong knowledge of static and dynamic application security testing tools and methodologies.

  • Hands-on experience conducting manual security testing, including penetration testing and vulnerability validation.

  • Proficiency in typescript/javascript

  • Experience working with development teams to remediate vulnerabilities and ensure secure software delivery.

  • Familiarity with secure coding practices and common vulnerabilities (e.g., OWASP Top 10, CWE/SANS Top 25).

  • Knowledge of modern security frameworks such as MITRE ATT&CK and NIST CSF.

Preferred Qualifications:

  • Experience with desktop applications.

  • Proven ability to automate complex security testing workflows.

  • Published tools or research related to security testing or vulnerability management.

Personal Characteristics:

  • Proactive and detail-oriented, with a strong drive for delivering secure solutions.

  • Effective communicator who can articulate security issues and remediation strategies to technical and non-technical audiences.

  • Collaborative and adaptable, thriving in fast-paced and cross-functional environments.

Upcoming Projects:

  • This role will lead and contribute to key initiatives to enhance Kong’s vulnerability management and testing processes, including:

  • Automated Testing Pipeline Development: Design and implement automated security testing workflows in GitHub Actions to ensure continuous vulnerability scanning.

  • Vulnerability Lifecycle Management: Establish comprehensive frameworks for tracking and closing vulnerabilities across Kong Gateway.

  • Hands-On Security Testing: Conduct manual penetration tests and validate automated findings to ensure thorough vulnerability coverage.

  • Collaboration with Development Teams: Partner with engineering teams to remediate vulnerabilities and improve secure development practices.

  • Continuous Improvement of Testing Tools: Regularly evaluate and integrate cutting-edge tools and methodologies into testing pipelines.

  • By joining Kong Inc., you will combine your expertise in vulnerability management, security engineering, and hands-on testing to ensure the security and reliability of our leading cloud-native API management platform. If you’re ready to take ownership of testing and remediation processes while driving innovation in secure software development, we’d love to hear from you!

About Kong:

Kong Inc., a leading developer of cloud API technologies, is on a mission to enable companies around the world to become “API-first” and securely accelerate AI adoption. Kong helps organizations globally — from startups to Fortune 500 enterprises — unleash developer productivity, build securely, and accelerate time to market. For more information about Kong, please visit www.konghq.com or follow us on X @thekonginc.

Compensation Range: CA$144.8K - CA$202.8K

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Salary

Salary: 145k-203k CAD

Location requirements

Hiring timezones

Canada +/- 0 hours

About Kong

Learn more about Kong and their company culture.

View company profile

Speed up time to market by unleashing developer productivity, automating security, and streamlining API management.

Kong powers the API world

Kong provides the foundation that enables any company to become an API-first company — speeding up time to market, creating new business opportunities, and delivering superior products and services.

Built on the world’s most adopted API gateway, Kong’s unified cloud API platform delivers fast, reliable, secure digital experiences. With Kong, organizations can increase developer productivity, security, and performance at scale with a single easy-to-use platform for API management, service mesh, and ingress controller.

We put customers at the heart of everything we do. That’s why everyone from e-commerce startups to the world’s leading biotech companies trust Kong to run mission-critical applications.

We embody open source and everything it stands for. We foster a culture of individualism — encouraging our people to bring new ideas and innovations, regardless of level and function.

How we do it

We’re passionate about solving the challenges that will fundamentally shape the future of tech. If you believe in taking ownership of your work, making an impact, and having fun along the way, come join us!

Global: Be Inclusive. We work together from anywhere to achieve our common goals. Our differences make us stronger.

Real: Be Authentic. We are genuine, pricipled and confident without arrogance. Show respect and kindness, especially in tough moments.

Unstoppable: Be Relentlessly Resourceful. We work with purpose, obsession and grit. It takes muscle to do hard things and doing hard things builds muscle.

Champions: Be Customer Obsessed. We care. Customers are everything, we put them at the center of everything you do. We are all empowered to make an impact.

Explorers: Be Curious. We value ideas over hierarchy. Never accept the status quo. We make bold bets, fail, and learn everyday. There is always a way.

Own It: Be an owner. We are drivers not passengers and own the quality and outcomes of our work.

Employee benefits

Learn about the employee benefits and perks provided at Kong.

View benefits

Unplug Days

Kong encourages taking well-deserved long weekends where the entire team unplugs to rest and recharge.

Equity Participation

Kongers are offered stock options to share in the success of the company, aligning employee and company growth.

Virtual Team Events

Kong hosts virtual events, donut chats, trivia, and fitness challenges to keep team members connected and engaged.

Office Stipend

Kong offers an office stipend to help employees build a home office environment tailored to support their productivity.

View Kong's employee benefits
Claim this profileKong logoKO

Kong

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

50 remote jobs at Kong

Explore the variety of open remote roles at Kong, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Kong

Remote companies like Kong

Find your next opportunity by exploring profiles of companies that are similar to Kong. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan