5 months ago
Milan, ItalySenior
Responsibilities
- Architect and implement gateway-level WAF, IDS, and IPS capabilities to defend against OWASP Top 10 threats, zero-day exploits, and API abuse.
- Design and implement zero-trust security models across hybrid, multi-cloud, and Kubernetes environments.
- Partner with Product and Architecture leads to define Kong Gateway’s multi-year security roadmap for open-source and enterprise needs.
- Lead responses to complex security incidents, supply-chain vulnerabilities, and CVE remediation efforts.
- Mentor engineers on secure coding and influence the organization’s cybersecurity maturity.
- Design high-performance security solutions that preserve the gateway’s millisecond-latency requirements.
Requirements
- 5+ years of experience in cybersecurity engineering focused on high-traffic infrastructure or API management.
- Expert-level knowledge of multi-cloud solution design and securing traffic across AWS, Azure, GCP, on-premises, and Kubernetes environments.
- Proven experience designing and deploying WAF, IDS, and IPS systems at scale, including signature-based and ML-based detection.
- Proficiency in Python, Go, or Rust.
- Experience contributing to or maintaining open-source security projects is a significant asset.
- Ability to produce high-quality, high-performance security designs.
