Security Engineer
Job description
About the role
Security is treated as a foundational requirement rather than a final checkpoint across all product initiatives at Delight.ai. The role owner partners with engineering groups to design and deliver security controls that remove friction instead of adding burden to the development lifecycle. You will own day-to-day security collaboration, translating business risk into technical requirements for distributed teams. This position requires the ability to manage complexity across multiple time zones, technology stacks, and concurrent security incidents. The ideal candidate will connect security projects and policies directly to business objectives while maintaining accountability for the systems under oversight. Effective project management and the ability to influence without direct authority are essential in this role.
Key facts
What you'll do
- Work with Engineering teams to help build secure products and infrastructure at scale while maintaining delivery velocity.
- Be the day-to-day security partner to teams across the company to conduct architecture reviews and threat models for systems being developed.
- Secure multi-account and multi-cloud infrastructure for Sendbird using standardized controls and automation.
- Own product security and cloud security tooling and build automations to reduce manual overhead and improve coverage.
- Embed security tools into the CI-CD system for SCA, SAST, Container, and IAC scanning to shift security left.
- Identify security gaps through proactive analysis and come up with practical, risk-based solutions.
- Research and identify new attack vectors and adversarial techniques targeting Sendbird's products and infrastructure.
- Collaborate with cross-functional teams to align security requirements with product roadmaps and delivery schedules.
- Communicate security concepts clearly to engineers who know more about their code than about security theory.
- Mentor other security practitioners and contribute to the development of security playbooks and standards.
- Lead complex cross-functional security projects from conception through implementation and validation.
- Ensure that security tooling integrates smoothly into developer workflows without creating unnecessary bottlenecks.
- Track security metrics and provide insights that help improve the overall security posture over time.
- Support incident response efforts by providing technical context and remediation guidance when needed.
Requirements
- Can manage complexity across time zones, technology stacks, and security issues on a daily basis.
- Collaborate effectively with cross-functional teams that include product, engineering, and operations.
- Can connect the dots between security projects and policies with concrete business objectives.
- Accountable for taking responsibility of the systems and infrastructure under your direct oversight.
- Effective project manager with the ability to influence without authority in matrixed organizations.
- English proficiency at a conversational level required, business level preferred for written and verbal communication.
- Demonstrated experience working with cloud providers such as AWS and GCP in globally distributed software environments.
- Hands-on experience with Infrastructure as Code practices and tooling for provisioning and securing cloud resources.
- Familiarity with Kubernetes environments and container security concepts across the lifecycle.
- Practical experience with automation scripting, preferably in Python, to streamline security operations.
- Knowledge of security tools and platforms used to enhance an organization's security posture and detect advanced threats.
- Proven capability in making sound security decisions that allow an agile business to move quickly while maintaining acceptable risk levels.
- Experience leading complex security initiatives that span multiple teams and require coordination over extended timelines.
Nice to have
- Experience developing security tools and contributing to open source security projects.
- Familiarity with AI system security, prompt injection defenses, and secure ML workflows.
- Background in privacy frameworks and regulatory compliance relevant to customer data.
- Active participation in the security community through talks, write-ups, or conference involvement.
Practical notes
This role is based in Seoul, South Korea. Only candidates located in or willing to relocate to Seoul should apply. No visa sponsorship is mentioned in the source material, and candidates must ensure they have the right to work in South Korea under the expected engagement type. No specific working hours or travel requirements are outlined in the source material.