Kong

Senior Security Engineer – Vulnerability Management

Shanghai, China
SQL Docker Python Ruby Go Rust Kubernetes API
Description
Company Overview

Kong Inc., an industry pioneer in cloud-native solutions, empowers businesses worldwide to innovate and excel in managing their API-driven architectures. With numerous awards for innovation and security solutions, our commitment extends beyond technology to cultivating a workplace that celebrates diversity and fosters inclusion. Join us to be part of a company where your work impacts millions and where every team member is instrumental in driving success.

About the Role

As a Security Engineer specializing in Vulnerability Management and Testing, you will be critical in ensuring the security of Kong’s flagship product, the Kong Gateway. This role focuses on identifying, triaging, and closing vulnerabilities while leveraging advanced security engineering to build and update automated testing pipelines. You will bring expertise in automated security testing while remaining hands-on in manual testing and validation processes. Your contributions will directly impact the security of Kong’s products by integrating robust security measures into CI/CD pipelines, conducting in-depth testing, and working closely with development teams to remediate vulnerabilities effectively and efficiently.

What you will do:

  • This position will be responsible for Manual Testing and Validation:
  • Conduct in-depth manual testing to identify vulnerabilities not covered by automated tools.
  • Validate the accuracy of automated findings and ensure comprehensive coverage for critical systems.
  • Provide detailed remediation guidance to development teams based on manual findings.

  • This position will be responsible for performing Comprehensive Testing and Analysis:
  • Conduct both automated and manual testing to uncover vulnerabilities:
  • Static Analysis: Detect insecure coding patterns during development.
  • Tools: GitHub Advanced Security (CodeQL), SonarCloud, Checkmarx CLI.
  • Dynamic Application Security Testing (DAST): Identify runtime vulnerabilities such as XSS or SQL Injection.
  • Tools: OWASP ZAP CLI Runner, Burp Suite Enterprise Edition.
  • Fuzz Testing: Discover unknown vulnerabilities through randomized inputs.
  • Tools: ClusterFuzzLite, libFuzzer.
  • Dependency Analysis: Identify vulnerabilities in third-party libraries and components.
  • Tools: Dependabot, Snyk CLI, OWASP Dependency-Check.
  • Environment Simulation and Sandboxing: Test software in isolated environments to simulate real-world attacks.
  • Tools: Docker, Minikube, Cuckoo Sandbox.

  • Vulnerability Triage and Management:
  • Identify, prioritize, and track vulnerabilities from multiple sources, including automated tools, penetration testing, and external reports.
  • Collaborate with development teams to ensure timely remediation of findings.

  • Work with Security Engineering to develop Automated Testing Pipelines:
  • Design, implement, and maintain automated security testing pipelines using GitHub Actions.
  • Integrate security tools into CI/CD workflows to enable continuous testing.
  • Enhance pipeline efficiency by automating vulnerability identification, tracking, and validation processes.

  • Collaboration with Development Teams:
  • Act as the primary security liaison for engineering teams, guiding secure coding practices and remediation strategies.
  • Review and approve remediation actions to verify closure of identified vulnerabilities.

  • Process Development and Metrics:
  • Establish workflows for vulnerability triage, testing, and closure.
  • Develop and monitor metrics to measure the effectiveness and efficiency of vulnerability management processes.

What we look for:

  • Expertise in building and managing automated security testing pipelines in CI/CD workflows.
  • Strong knowledge of static and dynamic application security testing tools and methodologies.
  • Hands-on experience conducting manual security testing, including penetration testing and vulnerability validation.
  • Proficiency in programming or scripting languages (e.g., Python, Ruby, Go, or Rust) for building and customising testing tools.
  • Experience working with development teams to remediate vulnerabilities and ensure secure software delivery.
  • Familiarity with secure coding practices and common vulnerabilities (e.g., OWASP Top 10, CWE/SANS Top 25).
  • Knowledge of modern security frameworks such as MITRE ATT&CK and NIST CSF.

  • Preferred Qualifications:
  • Experience with Kubernetes and containerised application security.
  • Proven ability to automate complex security testing workflows.
  • Published tools or research related to security testing or vulnerability management.

  • By joining Kong Inc., you will combine your expertise in vulnerability management, security engineering, and hands-on testing to ensure the security and reliability of our leading cloud-native API management platform. If you’re ready to take ownership of testing and remediation processes while driving innovation in secure software development, we’d love to hear from you!
About Kong: 

Kong is THE cloud native API platform with the fastest, most adopted API gateway in the world (over 300m downloads!). As the innovation leader of cloud API technologies, Kong is on a mission to enable companies around the world to become "API-first" and securely accelerate AI adoption.  Kong helps organizations globally - from startups to Fortune 500 enterprises - unleash developer productivity, build securely and accelerate to market.

83% of web traffic today is API calls!  APIs are the connective tissue of the cloud and the underlying technology that allows software to talk and interact with one another.  Therefore, we believe that APIs act as the nervous system of the cloud.  Our audacious mission is to build the nervous system that will safely and reliably connect all of humankind!  

For more information about Kong, please visit konghq.com or follow @thekonginc on Twitter.

We are an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.

#LI-CL1
Kong
Kong
Cloud Computing Cloud Data Services Developer APIs Enterprise Software Open Source

0 applies

9 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say

Sid avatar
Sid
Very nice portal for searching jobs in this rough market.
Mar 6, 2025
Michael Duran avatar
Michael Duran
Software Engineer
I've been using this job search site for a while now, and it’s honestly one of the best out there! The clean and easy-to-navigate UI makes the whole job-hunting process so much smoother. Plus, the job postings are always up-to-date, so I never feel like I’m wasting time. The cherry on top is the owner—super kind and always quick to respond. Definitely recommend checking it out if you're on the job hunt!
Aug 21, 2024
Sai avatar
Sai
It’s really great website for finding jobs based on skills it’s really helpful give a go
Aug 21, 2024
Adinadh avatar
Adinadh
What I like most about Echo Jobs is how easy it is to use. The platform helps me quickly find jobs that match my skills and interests, thanks to its great recommendations and filters. Yes, I would definitely recommend Echo Jobs to a friend. It makes job searching simple and efficient, making it a great tool for anyone looking for a new job.
Jul 23, 2024
As a student navigating the job market, I've found LinkedIn increasingly frustrating due to numerous fake postings by consultancies. In contrast, this job posting website has been a game-changer for me. It offers genuine opportunities and a straightforward application process, making it much easier to find and apply for real jobs. Highly recommend it to fellow students seeking reliable job listings!
Jul 16, 2024
Cliff Gor avatar
Echo Jobs has been exceptional in my job hunt where it provides one platform to job hunt and I don't have to open 10 websites just to look for a job. It has also helped me focus much on the job skill and the location filtering out the onsite jobs and remote ones. The only feature that I would request is to display fully remote jobs that are not restricted to a country since the one available shows ie, Remote, US yet. But if it could show remote only, that would be helpful not only to me but to other people applying for full remote and not tied to only US candidates
Apr 22, 2024
I found EchoJobs in 2022, and I love it. It has a lot of remote jobs. It's exclusive to software and technology jobs (helpful for devs like me). What I like the most are its filters and its API. If you're a tech professional seeking remote work, I highly recommend giving it a try to EchoJobs.
Mar 4, 2024
Would definitely recommend it! Excellent product, dedicated founder, Jobs are easier to find. Congrats 🎉 to the entire team!
Mar 3, 2024
Brandon Banks avatar
Brandon Banks
Echo Jobs is really impressive. It provides a great user experience with an ability to quickly search through the many job postings. There is an impressive amount of jobs here and it is quickly updated. The details in the each job posting is helpful when determining if it is worth pursuing. I would highly recommend using Echo Jobs to find the next step in your career.
Mar 2, 2024
Tyler Young avatar
Tyler Young
tylerayoung.com
Best wishes with EchoJobs—it's become my favorite job board overnight!
Dec 16, 2023
Simply put, it's the most up to date tech jobs aggregator I’ve found. I'm like... "I don't have to check 10+ jobs boards daily just to see if there's a new job listing? sign me up!" The filters are also quite helpful! The UI is very clean and straightforward. Love it!
Oct 5, 2023