Senior Security Engineer II
CareemKarachi6d ago
SecurityEngineeringremotecurated-jd
Job description
Senior Security Engineer II at Careem.
About the role
Careem is seeking a hands-on Senior Security Engineer II to manage infrastructure, cloud, and agentic AI security. You will operate within a large-scale, multi-vertical environment, taking ownership of security initiatives from design to implementation.
Key facts
What you'll do
- Manage AWS security posture including IAM, GuardDuty, Bottlerocket, and Beanstalk, while enforcing encryption and golden AMI pipelines.
- Oversee KSPM and CSPM controls, lead infrastructure-level incident response, and report on patching and hardening KPIs.
- Configure Cloudflare settings, including WAF, TLS enforcement, and bot traffic analysis, while managing HackerOne-reported issues.
- Operate DDoS simulation tools like Kratos and integrate them into developer portals.
- Perform security reviews for agentic AI systems, n8n workflows, and MCP servers, focusing on OAuth, JWT, and injection risks.
- Conduct threat modeling and security architecture assessments for product verticals such as Pay, Food, Groceries, and Remittance.
- Develop IaC-based security baselines and use automation to identify and remediate infrastructure gaps.
Requirements
- 8-10 years of hands-on security engineering experience in cloud-native environments.
- Deep technical knowledge of AWS security, including Secrets Manager, EC2, and EBS encryption.
- Proficiency in Kubernetes security, specifically runtime detection and container escape risks.
- Practical experience with Cloudflare traffic analytics, custom rules, and bot management.
- Demonstrated ability to manage vulnerability programs, patching SLAs, and KPI reporting.
- Experience coordinating DDoS resilience testing with SRE and QA teams.
- Understanding of agentic AI security, including SSRF, prompt injection, and tool permission scoping.
- Experience reviewing n8n or similar workflow automation tools.
- Strong written and verbal communication skills for presenting to Architecture Review Boards.
- Ability to drive complex, independent projects with a high-ownership mindset.
Nice to have
- Experience with Infrastructure as Code using Terraform or CDK.
- Familiarity with CrowdStrike for endpoint security.
- Background in HackerOne bug bounty triage.
- Proficiency with application security tools like Snyk or SonarQube.
Skills & tools
- AWS (IAM, GuardDuty, EC2, EBS, Beanstalk, Bottlerocket, Secrets Manager)
- Cloudflare (WAF, Bot Management, SSL/TLS)
- Kubernetes (KSPM)
- Agentic AI / MCP Servers
- n8n
- DDoS Simulation (Kratos)
- Threat Modeling
- Infrastructure as Code (Terraform/CDK)
Practical notes
- Work schedule: 2 days in the office and 3 days from home for tech individual contributors.
- Flexibility: 30 days of remote work per year from any country.
- Leave: Unlimited vacation days.
- Benefits: Healthcare coverage and fitness reimbursements for gym or training classes.