About the job
Join Us in Empowering Global Connections!
At Kong, we value diverse experiences and encourage you to apply even if you don’t meet every single requirement. We're searching for candidates who are particularly strong in certain areas while displaying interest and capabilities in others.
Role Overview:
As a vital member of our Runtime Organization, you will contribute to the development of our Data Plane products, which serve as the cornerstone of our API platform: Kong Gateway, Kong AI Gateway, Kong Mesh, and Kong Event Gateway. We are seeking a proactive Staff Engineer specializing in security to enhance the security across our Data Plane offerings, collaborating with various engineering teams to fortify our code and infrastructure. This hands-on technical leadership position requires a unique combination of deep technical knowledge and outstanding communication skills.
Key Responsibilities:
Serve as a bridge between the Kong Runtime engineering teams and the security organization to define innovative requirements for the security roadmap.
Promote security best practices throughout the Kong Runtime engineering organization.
Research, design, implement, and maintain security-oriented frameworks and features aimed at hardening Kong’s Data Plane and safeguarding our customers.
Provide routine security engineering designs and conduct code reviews for sensitive pathways.
Dismantle complex challenges into manageable tasks while swiftly prototyping and contributing to security initiatives through agile methodologies.
Mentor and coach Kong Runtime engineers on security best practices.
.
Qualifications:
8+ years of experience in leading teams to develop, deliver, and maintain sophisticated software solutions, with a strong emphasis on security.
Proficiency in Golang or Rust.
In-depth knowledge of security across all levels of the TCP/IP stack.
Solid grasp of concepts such as Test-Driven Development, Secure SDLC, and Secure Code Reviews, along with the ability to identify and mitigate threats and vulnerabilities in code and infrastructure.
Familiarity with cloud service providers like AWS and GCP.

