Circles

Circles

Lead Security Engineer

United States of America · Staff+

Sponsorship not specifiedDetected 11 days ago
PythonJavaGoAWSGCPAzureCloud PlatformsKubernetesCI/CDDevOpsGraphQLRESTLLMsCybersecurityPenetration TestingSIEMSOARSOC OperationsIncident ResponseRecruitingCustomer SupportCommunicationCISSP

About the role

  • Jetpac was awarded Travel eSIM of the Year.

Responsibilities

  • Lead threat modeling (STRIDE, PASTA, or equivalent) for new applications, features, and major platform changes
  • Define secure design patterns and reference architectures
  • Own the Application Security program end-to-end: SAST, DAST, SCA, and API security testing - tool selection, policy tuning, and triage workflows
  • Partner with engineering leads to prioritize findings by exploitability and business impact, and drive remediation within agreed SLAs
  • Manually validate findings to separate real risk from noise before they reach engineering backlogs
  • Define secure design patterns and reference architectures; provide hands-on security guidance at every stage of the SDLC, not just at release gates
  • Own the vulnerability management lifecycle - from discovery through remediation to verified closure - and continuously tighten SLAs as maturity improves
  • Serve as a technical escalation point for security incidents; lead or support incident response - triage, containment, root cause analysis, and post-incident reviews
  • Build automation in Python (or equivalent) for security scanning, findings de-duplication, ticketing, and reporting workflows

Requirements

  • 10-12 years of hands-on experience in Application Security and Security Engineering
  • Solid working knowledge of the OWASP Top 10, OWASP API Security Top 10, secure coding practices, and cloud security fundamentals

Nice to have

  • Certifications: OSCP, OSWE, GWAPT, GPEN, CISSP, or equivalent
  • Experience securing AWS, Azure, or GCP environments, and Kubernetes/container workloads
  • Hands-on experience with SIEM/SOAR platforms (e.g., Splunk, Sentinel, XSOAR, or similar)
  • Familiarity with security maturity frameworks: OWASP SAMM, BSIMM, or NIST CSF
  • Exposure to securing AI/LLM implementations
  • Circles is committed to a diverse and inclusive workplace.
  • Data Protection and Privacy Statement
  • You also agree to the collection, use, and/or disclosure of your personal data by us solely for recruitment purposes as specified in the Policy.

Skills

  • A global provider of Communications Platform-as-a-Service (CPaaS) solutions.
  • Conduct security architecture reviews for applications, APIs, cloud infrastructure, and third-party services before go-live

Company info

  • Founded in 2014, Circles is a global technology company reimagining the telco industry with its innovative SaaS platform, empowering telco operators worldwide to effortlessly launch innovative digital brands or refresh existing ones, accelerating their transformation into techcos.
  • Today, Circles partners with leading telco operators across multiple countries and continents, including KDDI Corporation, Etisalat Group (e&), AT&T, and Telkomsel, creating blueprints for future telco and digital experiences enjoyed by millions of consumers globally.

This listing is sourced directly from Circles's careers page and normalized into a canonical job model.