Search by job, company or skills

Recro

Security Engineer

new job description bg glownew job description bg glownew job description bg svg
  • Posted 4 hours ago
  • Be among the first 10 applicants
Early Applicant

Job Description

As part of our world-class engineering team at Recro, we are expanding our Product Security Engineering function. Our dev teams work across a variety of cutting-edge tech stacks in a fast-moving environment, which makes security both a challenge and an opportunity to innovate. We prioritise guardrails over roadblocks in our security culture, empowering developers to move fast while ensuring that security is built-in, scalable, and resilient.

The Product Security team is responsible for integrating security into all phases of the SDLC from design through deployment including infrastructure and application security, secure development practices, threat modelling, and DevSecOps automation.

Our mission includes:

Driving secure-by-design principles across web, mobile, cloud, and IoT systems.

  • Building and maintaining security automation tools for CI/CD pipelines.
  • Enhancing our cloud infrastructure security posture at scale.
  • Developing secure coding patterns, libraries, and guardrails for developers.
  • Partnering with dev teams to identify and remediate security risks early (shift-left mindset).
  • Conducting architectural reviews and risk assessments for new features or products.
  • Assist engineering teams in performing threat modelling and working with them for effective mitigation techniques.

What we're looking for:

We value diverse security backgrounds and want to work with professionals who are passionate about engineering secure systems at scale.

Required Skills:

Strong understanding of information security fundamentals and the ability to communicate them clearly to engineering and product teams.

  • 3-5 years of hands-on experience with secure coding, DevSecOps, and security automation.
  • Familiarity with application architecture, threat modelling, CI/CD pipelines, infrastructure-as-code (IAC), serverless, IAM, and cloud-native security.
  • Experience integrating security controls into developer workflows.
  • Penetration testing is optional and good to have. However, the ability to interpret results is a must.
  • Comfortable collaborating across teams and challenging assumptions constructively.
  • Solution-oriented, pragmatic, and focused on scalable risk mitigation.
  • Proficiency in at least one programming language (Python, Bash, Java, etc.) for tool development and automation.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 145097573

Similar Jobs