Staff Security Engineer II

Security Engineer · Staff · Full Time

IN Remote India5mo ago
Apply for this role

Opens Confluent's application page

Role

What you'll do.

Staff Application Security Engineer II at Confluent, responsible for shaping application security strategy across distributed systems and cloud platforms. The role involves defining security architecture, leading automation initiatives, and partnering with Engineering and Product teams to embed secure-by-design practices. Requires 10-12 years of application security experience with expertise in cloud-native platforms, security automation, and programming languages like Go, Python, or Java.

Responsibilities

  • Security Architecture Leadership: Partner with Engineering, Product, and Platform teams to identify security risks early and influence architectural decisions across distributed systems
  • Threat Modeling and Design Standards: Define and standardize threat modeling frameworks and security design standards for complex, distributed systems
  • Security Implementation Reviews: Serve as subject matter expert for product security implementation reviews, overseeing security code reviews and API security testing
  • Security Automation Architecture: Architect and drive roadmap for security automation, building scalable software security tooling to transform product security operations
  • Cloud-Native Security Integration: Design and lead deployment of automation frameworks that integrate security into cloud-native deployment pipelines
  • Vulnerability Research and Prevention: Proactively identify new vulnerability classes, lead research initiatives and orchestrate table-top exercises
  • Advanced Security Controls: Strategically identify and deploy advanced technology controls to maximize observability and harden attack surfaces
  • Cross-Functional Security Leadership: Build and sustain strong security culture across Engineering, Product, and broader organization through technical guidance and mentorship

Qualifications

What we look for.

Technical

  • Application Security Expertise

    10-12 years of hands-on Application Security experience with measurable security improvements across large-scale distributed systems

  • Modern Web Application Security

    Comprehensive knowledge of security fundamentals for modern web applications and cloud-native platforms

  • Secure Software Development

    Proven experience evolving SDLC to embed security by default, including CI/CD pipeline security and automated guardrails

  • Programming Proficiency

    Experience in Go, Python, or Java with ability to design and build scalable security automation frameworks

  • AI/ML Security Integration

    Passion for applying AI and LLMs to automate complex security workflows and improve security outcomes

  • Incident Response Leadership

    Ability to lead technical investigation and response to application security incidents while driving preventive improvements

Education

  • Bachelor's Degree

    Computer Science, Information Security, or related technical field preferred

  • Security Certifications

    CISSP, CSSLP, CEH, or equivalent security certifications preferred

Experience

  • Leadership Experience

    Experience leading cross-functional initiatives in distributed environments and translating security requirements into technical roadmaps

  • Architecture Partnership

    Ability to partner as trusted peer with Engineering and Product leadership to embed security into core architecture

  • Data-Driven Decision Making

    Experience balancing security requirements with business velocity and engineering trade-offs to deliver measurable outcomes

  • Technical Mentorship

    Proven ability to raise organizational security standards through architectural reviews and development of engineers across all levels

Skills

Required

  • Application Security

    10-12 years of hands-on experience in application security for large-scale distributed systems

  • Security Architecture

    Expertise in secure software design, architecture, and common vulnerability classes

  • Programming Languages

    Proficiency in Go, Python, or Java for security automation framework development

  • Cloud-Native Security

    Experience securing CI/CD pipelines, build systems, and cloud-native deployment workflows

  • Threat Modeling

    Advanced skills in threat modeling frameworks and security design standards

  • Security Automation

    Ability to architect and build scalable security automation and orchestration frameworks

Preferred

  • AI/ML Integration

    Nice to have

    Experience applying AI and LLMs to automate security workflows and reduce manual processes

  • Incident Response

    Nice to have

    Leadership experience in technical investigation and response to application security incidents

  • Cross-Functional Leadership

    Nice to have

    Proven ability to lead initiatives across distributed engineering organizations

  • Security Certifications

    Nice to have

    CISSP, CSSLP, CEH, or equivalent industry security certifications

  • Vulnerability Research

    Nice to have

    Experience in proactive vulnerability research and emerging threat landscape analysis

Tech stack

Languages

GoPythonJava

Frameworks

Apache KafkaCloud-native frameworksCI/CD Pipeline frameworks

Databases

Distributed databasesNoSQL databases

Tools

Security automation toolsThreat modeling toolsVulnerability management platformsAPI security testing tools

Other

Cloud platformsAI/ML platformsObservability platforms

Compensation

Pay and benefits.

Benefits

  • Equal Opportunity Workplace

    Employment decisions based on job-related criteria without regard to protected classifications

  • Inclusive Culture

    Belonging-focused environment that values diverse perspectives and backgrounds

  • Global Remote Work

    Work across time zones with flexible remote arrangements

  • Professional Growth

    Opportunities to lead, grow, and challenge what's possible in data streaming technology

Process

Interview steps.

  1. 01

    Initial Screening

    Phone or video call with HR/Recruiting to discuss background, experience, and role alignment

  2. 02

    Technical Security Assessment

    Deep dive into application security experience, threat modeling, and security architecture design

  3. 03

    System Design and Architecture

    Security-focused system design interview covering distributed systems and cloud-native security

  4. 04

    Leadership and Collaboration

    Behavioral interview assessing cross-functional leadership and ability to influence engineering teams

  5. 05

    Security Automation and Tools

    Technical discussion on security automation, tooling development, and DevSecOps practices

  6. 06

    Final Panel Interview

    Meeting with security leadership and engineering stakeholders to assess cultural fit and strategic thinking

Full posting

Original listing.

We’re not just building better tech. We’re rewriting how data moves and what the world can do with it. With Confluent, data doesn’t sit still. Our platform puts information in motion, streaming in near real-time so companies can react faster, build smarter, and deliver experiences as dynamic as the world around them.

It takes a certain kind of person to join this team. Those who ask hard questions, give honest feedback, and show up for each other. No egos, no solo acts. Just smart, curious humans pushing toward something bigger, together.

One Confluent. One Team. One Data Streaming Platform.

About the Role:

As a Staff Application Security Engineer at Confluent, you will join a team of security architects and engineers responsible for shaping and advancing the application security strategy across our on-premises products and cloud services. In this role, you will go beyond implementation to define the long-term security posture of our ecosystem, spanning high-scale distributed systems, on-prem deployments, and globally operated cloud platforms.

You will lead the design and evolution of application security architecture, ensuring security is embedded throughout the product lifecycle—from early design decisions to cloud deployment and ongoing operations. Acting as a strategic partner to Engineering and Product leadership, you will influence architectural direction and proactively mitigate systemic and emerging security risks.

This role plays a key part in building and sustaining a strong security culture across Engineering, Product, and the broader organization. You will architect and oversee security automation and tooling that scales security operations and enables consistent, high-quality outcomes. The ideal candidate brings deep technical expertise and sound security judgment, with a proven ability to eliminate entire classes of vulnerabilities through architecture, automation, and cross-functional leadership.

What You Will Do:

  • Partner closely with Engineering, Product, and Platform teams to identify security risks early, influence architectural decisions, and drive adoption of secure-by-design practices across the organization.

  • Define and standardize threat modeling frameworks and security design standards, and lead security design reviews for complex, distributed systems, providing actionable architectural guidance to engineers and product managers.

  • Serve as the subject matter expert (SME) for product security implementation reviews, overseeing security code reviews and API security testing while providing definitive remediation guidance.

  • Architect and drive the roadmap for security automation, building scalable software security tooling to transform product security operations and vulnerability management practices.

  • Design and lead the deployment of automation and orchestration frameworks that integrate security seamlessly into the cloud-native deployment pipeline.

  • Proactively identify new vulnerability classes, lead research initiatives and orchestrate complex table-top exercises to keep the organization ahead of the evolving threat landscape.

  • Strategically identify and deploy advanced technology controls to maximize observability and harden key attack surfaces across the ecosystem.

What You Will Bring:

  • 10–12 years of hands-on Application Security experience, who can drive measurable security improvements across large-scale, distributed systems and global engineering organizations.

  • Comprehensive knowledge of security fundamentals as applied to modern web applications and cloud-native platforms including secure software design and architecture, secure coding practices, common vulnerability classes.

  • Ability to partner as a trusted peer with Engineering and Product leadership to embed security into the core architecture of the organization.

  • Ability to lead technical investigation and response to application security incidents while driving preventive improvements through architecture and automation.

  • Proven experience evolving the software development lifecycle to embed security by default, from securing CI/CD pipelines and build systems to implementing automated security guardrails in cloud-native deployment workflows. Passionate about applying AI and LLMs to automate complex security workflows, reduce manual toil, and drive measurable improvements in security outcomes.

  • Experience in Go, Python, or Java, with the ability to design and build scalable security automation frameworks.

  • Experience in leading cross-functional initiatives in distributed environments, translating security requirements into clear, executable technical roadmaps.

  • A data-driven decision-maker who can balance security requirements with business velocity and engineering trade-offs to deliver outcomes.

  • Ability to raise the organization’s security bar through architectural reviews, advanced technical guidance, and the development of engineers across all levels.

Ready to build what's next? Let’s get in motion.

Come As You Are

Belonging isn’t a perk here. It’s the baseline. We work across time zones and backgrounds, knowing the best ideas come from different perspectives. And we make space for everyone to lead, grow, and challenge what’s possible.

We’re proud to be an equal opportunity workplace. Employment decisions are based on job-related criteria, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by law.

Redirects to Confluent's application page.

Other roles

More at Confluent.

View all 23 roles