Senior Infrastructure Security Software Engineer (Remote)

Security Engineer · Senior · Full Time · Remote

Remote - Multiple Locations · RemoteUSD 172k – 256k1mo ago
Apply for this role

Opens Quora's application page

Role

What you'll do.

Senior Infrastructure Security Software Engineer at Quora is a critical role supporting the company's Quora and Poe platforms, focusing on building robust cloud and infrastructure security protections for over 300 million monthly users. This position requires a capable software engineer with deep expertise in cloud infrastructure security (AWS/Kubernetes), automation and secure development practices, or Linux/system security, working collaboratively to architect threat models, harden cloud environments, and develop security automation tools. The role offers the opportunity to shape security at scale across globally distributed systems while working with a passionate, newly-formed Security Engineering Team in a remote-first, culture-driven organization.

Responsibilities

  • Cloud Architecture Security Reviews: Partner with engineering teams to conduct comprehensive reviews of cloud and compute architecture design changes, identifying security vulnerabilities and ensuring alignment with security best practices and organizational standards.
  • Threat Modeling and Risk Assessment: Establish comprehensive threat models for cloud and compute infrastructure paved roads to systematically identify security risks, potential attack vectors, and compliance gaps before they impact production systems.
  • Infrastructure Hardening and Tool Development: Develop, adopt, and maintain open-source and proprietary tools to monitor and harden cloud infrastructure, operating systems, and security logging pipelines, including intrusion detection capabilities and real-time threat visibility.
  • Security Best Practices Implementation: Apply expert knowledge of security best practices for AWS and Kubernetes environments to inform remediation strategies, control roadmaps, and architectural decisions that protect the company's infrastructure at scale.
  • Security Policy Development and Enforcement: Drive the definition, documentation, and implementation of comprehensive security policies while establishing monitoring mechanisms and compliance frameworks to ensure consistent adherence across all infrastructure and teams.
  • Security Automation and Infrastructure-as-Code: Write and maintain code for security automation solutions supporting threat detection, incident containment, network access management, and infrastructure provisioning using infrastructure-as-code principles and CI/CD integration.
  • Incident Response and Triage: Conduct initial incident triage for security events, determine scope and urgency, assess potential business impact, and actively participate in incident response processes to minimize damage and prevent recurrence.

Qualifications

What we look for.

Technical

  • Cloud Infrastructure Security (AWS)

    Hands-on expertise securing large-scale AWS cloud environments with deep knowledge of IAM policies, network segmentation, VPC design, and cloud-native monitoring and logging solutions. Experience with infrastructure-as-code tools like Terraform or CloudFormation is required.

  • Container and Kubernetes Security

    Demonstrated experience implementing security controls in Kubernetes clusters, including pod security policies, network policies, RBAC configurations, and container runtime security. Understanding of container image scanning and registry security is essential.

  • Linux and System-Level Security

    Strong proficiency with Linux operating systems, including kernel security features, POSIX capabilities, SELinux/AppArmor, seccomp profiles, and system hardening. Experience with container security and eBPF-based security tooling is highly valued.

  • CI/CD Security Integration

    Expertise developing and integrating security tools into continuous integration and continuous deployment pipelines, including SAST, DAST, dependency scanning, and vulnerability management solutions to detect and prevent security issues early in development.

  • Secure Development Practices

    Proficiency implementing 'security as code' methodologies, automating security processes, and advocating for secure coding practices. Ability to mentor development teams on building resilient, secure applications and APIs.

  • Security Monitoring and Logging

    Advanced capability in designing and implementing comprehensive security logging pipelines, threat detection systems, and intrusion detection/prevention mechanisms. Experience with SIEM platforms, log aggregation, and real-time alerting systems is essential.

  • Software Engineering Fundamentals

    Strong software development background with the ability to write production-quality code, design scalable systems, and contribute meaningfully to architectural decisions. Ability to balance security requirements with operational and business needs.

Education

  • Bachelor's Degree in Computer Science, Security, or Related Field

    Formal education in computer science, information security, software engineering, or equivalent technical discipline that provides foundational knowledge for infrastructure and application security work.

Experience

  • 5+ Years Infrastructure or Security Engineering Experience

    Minimum five years of professional experience in infrastructure engineering, cloud security, system administration, or security engineering roles, demonstrating progressive responsibility and impact in building secure systems at scale.

  • 3+ Years Cloud Platform Experience

    At least three years of hands-on experience working with cloud platforms, preferably AWS, including designing, deploying, and securing cloud infrastructure and understanding cloud-native architecture patterns.

  • 2+ Years Security Engineering or Application Security

    Minimum two years of dedicated experience in security engineering, application security, or related security-focused roles where you've implemented or championed security controls, policies, or best practices.

  • Incident Response Experience

    Demonstrated participation in security incident response activities, including initial triage, scope determination, containment, and post-incident analysis to prevent recurrence.

Skills

Required

  • AWS Cloud Infrastructure

    Production-level expertise with AWS services including EC2, VPC, IAM, S3, CloudTrail, and other core infrastructure components with demonstrated ability to architect secure cloud environments.

  • Infrastructure-as-Code (Terraform/CloudFormation)

    Proficiency writing and maintaining infrastructure-as-code using Terraform, CloudFormation, or similar tools with deep understanding of idempotency, state management, and secure secret handling.

  • Kubernetes Administration and Security

    Advanced Kubernetes knowledge including deployment, configuration, troubleshooting, and implementation of security controls such as RBAC, network policies, and pod security standards.

  • Linux Systems Administration

    Expert-level Linux administration including kernel hardening, package management, service configuration, performance tuning, and security implementation using native Linux security features.

  • Python or Go Programming

    Strong proficiency in at least one systems programming language such as Python or Go, enabling development of security automation tools, scripts, and integrations with security platforms.

  • Security Automation and Scripting

    Ability to develop automation solutions for security processes including threat detection, incident response, compliance checking, and remediation using scripting languages and security APIs.

  • Vulnerability Assessment and Remediation

    Hands-on experience identifying security misconfigurations and vulnerabilities in cloud environments, systems, and applications, with demonstrated ability to drive remediation and implement preventive controls.

  • Monitoring and Alerting Systems

    Experience designing and implementing comprehensive monitoring, logging, and alerting solutions for security events, infrastructure health, and compliance using tools like Datadog, Prometheus, ELK, or similar platforms.

Preferred

  • eBPF and Advanced Linux Security Tools

    Nice to have

    Experience with eBPF-based security tools, OSQuery, or other advanced system introspection and monitoring solutions for deep visibility into system and container behavior.

  • Product Security and Application Security

    Nice to have

    Working knowledge of OWASP Top 10, common web vulnerabilities such as XSS, CSRF, SQL injection, and experience securing web applications and APIs alongside infrastructure security.

  • Serverless Architecture Security

    Nice to have

    Experience implementing security controls and best practices for serverless computing platforms and function-as-a-service environments including Lambda and similar services.

  • Security Compliance Frameworks

    Nice to have

    Familiarity with security compliance standards such as SOC 2, ISO 27001, CIS Benchmarks, or similar frameworks, with experience implementing controls and maintaining compliance posture.

  • Incident Response and Forensics

    Nice to have

    Experience participating in security incident response activities, forensic analysis, and contributing to post-incident reports and preventive measures to enhance security posture.

  • Container Image Scanning and Registry Security

    Nice to have

    Experience implementing and maintaining container image scanning, vulnerability management in container registries, and secure supply chain practices for containerized applications.

  • SAST, DAST, and Dependency Scanning Tools

    Nice to have

    Hands-on experience integrating and managing static analysis, dynamic analysis, and dependency scanning tools within CI/CD pipelines to detect and remediate vulnerabilities early in development.

  • Open Source Security Tools Development

    Nice to have

    Experience developing, maintaining, or significantly contributing to open source security tools, demonstrating ability to write security-focused software and contribute to the broader security community.

Tech stack

Languages

PythonGoBash/Shell Scripting

Frameworks

TerraformCloudFormationKubernetes

Databases

Time-Series Databases (Prometheus, InfluxDB)Log Aggregation (ELK, Splunk)

Tools

AWS Security Tools (IAM, Security Hub, GuardDuty)Container Security (Docker, container registries, image scanning)SAST/DAST Tools (SonarQube, Burp Suite, OWASP ZAP)Vulnerability Scanning and ManagementMonitoring and Observability (Datadog, Prometheus, Grafana)CI/CD Platforms (GitHub, GitLab, Jenkins)OSQuery and eBPF Tools

Other

AWS Ecosystem and ServicesSecurity Best Practices and FrameworksLinux Kernel Security FeaturesNetwork Security ConceptsThreat Modeling and Risk Assessment

Compensation

Pay and benefits.

Base·USD 172,279 – 256,433

Equity·Stock options

Benefits

  • Comprehensive Health Coverage

    Medical, dental, and vision insurance coverage with company contributions to ensure employee health and wellness.

  • Equity Compensation and Refreshers

    Stock options and regular equity refreshers for senior-level employees, aligning individual success with company growth and providing long-term wealth building opportunities.

  • Remote Work Support

    Dedicated remote work reimbursement to support home office setup, technology equipment, and internet services for productive remote work.

  • Generous Paid Time Off

    Comprehensive paid time off policy including vacation days, sick leave, and personal time for work-life balance and employee wellbeing.

  • Employee Assistance Program

    Access to confidential counseling, mental health support, and personal resources to support employee and family wellbeing.

  • Flexible Work Environment

    Remote-first company culture with flexible coordination hours (Monday-Friday, 9am-3pm Pacific Time) allowing for geographic flexibility and work-life integration.

  • Professional Development

    Culture rooted in continuous learning and experimentation with opportunities to think big, explore new ideas, and develop expertise in cutting-edge security practices.

  • Inclusive Company Culture

    Transparent, collaborative environment celebrating success with high-performing global teams and meaningful work toward growing the world's collective intelligence.

Full posting

Original listing.

[Quora is a privately held, "remote-first" company. This position can be performed remotely from anywhere in Canada or the United States. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by country.]

About Quora:

Quora’s mission is to grow the world's collective intelligence. To do so, we have two platforms:

  • Quora: a global knowledge sharing platform with over 300M monthly unique visitors, bringing people together to share insights on various topics and providing a unique platform to learn and connect with others.

  • Poe: a platform providing millions of global users with one place to chat, explore and build with a wide variety of AI language models (bots), including Claude-Opus-4.7, Nano-Banana-2, GPT-Image-2, GPT-5.5, GPT-5.5-Pro, and more. As AI capabilities rapidly advance, Poe provides a single platform to instantly integrate and utilize these new models.

Behind these products are passionate, collaborative, and high-performing global teams. We have a culture rooted in transparency, idea-sharing, and experimentation that allows us to celebrate success and grow together through meaningful work. Join us on this journey to create a positive impact and make a significant change in the world.

This role will be supporting both our Quora and Poe products.

About the Team and Role:

You will be a key member of the newly created Security Engineering Team, with a mission to keep Quora safe from security problems by building robust protections around our products, infrastructure and people. Our small engineering team works on challenging problems every day. We have a culture that's rooted in constantly learning and improving, and our engineers are encouraged to think big and experiment with new ideas.

What We're Looking For:

  • Sweat The Right Details: you thrive in understanding the details but will also know to ruthlessly prioritize the critical issues.

  • Right-Size The Solution: you recognize guidelines and framework do not always fit the problem and know how to adjust the solution for scalability not always at-scale.

  • Ownership: you are outcome focused and can deftly navigate obstacles, decompose complexities, manage your time and can communicate your vision to peers and management.

An Ideal Candidate Would...

be a capable software engineer while also spiking in at least one of the following domain expertise:

  • Cloud Infrastructure Security: You have hands-on experience securing large-scale cloud environments, particularly with AWS. You are passionate about building secure infrastructure-as-code (IaC) pipelines using tools like Terraform or CloudFormation. You understand IAM policies, network segmentation, and VPC design and have a thorough grasp of monitoring and logging in cloud-native environments. You are skilled in identifying misconfigurations, mitigating risks, and driving remediation processes. Bonus points if you've implemented security in Kubernetes clusters or serverless architectures.

  • Automation and Secure Development Practices: You believe in "security as code" and are skilled at automating security processes. You can develop and integrate security tools into CI/CD pipelines to ensure secure code delivery. Tools like SAST, DAST, and dependency scanning are part of your daily toolkit, and you have experience integrating them into workflows to catch vulnerabilities early. You also advocate for secure coding practices and are skilled at mentoring teams to write resilient, secure applications.

  • Linux/System Security: You are well versed in AWS infrastructure security but also are passionate about scalability, reliability and operational rigor. Beyond that, you know that root does not mean root and are passionate about container security, POSIX Capabilities, SECCOMP and have a favorite flavor of LSM. In your spare time, you love playing around with OSQuery and eBPF.

  • Product Security (nice-to-have): Not a requirement, but a real plus: experience building secure web applications and APIs, with a working grasp of the OWASP Top 10 and common vulnerabilities such as XSS, CSRF, and SQL injection. It complements the infrastructure security focus of this role and helps when partnering with product teams.

Responsibilities:

  • Partner with engineering teams to review cloud and compute architecture design changes

  • Establish threat models for cloud and compute paved roads to identify security risks

  • Develop or adopt open-source tools to monitor and harden our cloud Infrastructure, harden our OS, develop security logging pipelines and detect intrusions

  • Apply your expert knowledge of security best practices for AWS and Kubernetes to inform remediations and the team's control roadmap

  • Drive the definition and implementation of security policies and monitor in conformance to the policies

  • Write code for automations that support security requirements like threat detection, incident containment, and network access management.

  • Conduct initial incident triage; determine scope, urgency, and potential impact of security incidents; participate in the incident response process

At Quora, we value diversity and inclusivity and welcome individuals from all backgrounds, including marginalized or underrepresented groups in tech, to apply for our job openings. We encourage all candidates who share a passion for growing the world’s knowledge, even those who may not strictly meet all the preferred requirements, to apply, as we know that a diverse range of perspectives can have a significant impact on our products and our culture.

Additional Information:

Successful candidates must have availability for meetings and impromptu communication during Quora's “coordination hours" (Mon-Fri: 9am-3pm Pacific Time).

We are accepting applications on an ongoing basis.

Quora offers a wide range of benefits including medical/dental/vision coverage, equity refreshers, remote work reimbursement, paid time off, employee assistance programs, and more. Benefits are country-specific and may vary.

There are many factors that will determine the starting pay, including but not limited to experience, location, education, and business needs.

  • US candidates only: For US based applicants, the salary range is $172,279 - $249,640 USD + equity + benefits.

  • Canada candidates only: For Toronto and Vancouver based applicants, the salary range is $221,209 - $256,433 CAD + equity + benefits. For all other locations in Canada, the salary range is $206,461 - $239,337 CAD + equity + benefits.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

AI technology may assist in sorting applications and recording interview notes, but all decisions are made by a member of our team.

To ensure a secure hiring process, all final candidates will undergo identity verification and a comprehensive background check prior to onboarding.

Job Applicant Privacy Notice: https://www.careers.quora.com/pages/quora-global-job-applicant-privacy-notice

#LI-JC1
#LI-REMOTE

Redirects to Quora's application page.

Other roles

More at Quora.