Senior Security Engineer (Edge & Cloud)

Derq

$120K — $150K *
US-AnywhereRemote in Vancouver, BC
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6 to 8+ years in security engineering, application security, or cloud security.
  • Hands-on experience securing production systems; not limited to compliance or audit.
  • Strong knowledge of Linux security practices and hardening techniques.
  • Familiarity with web application security, including OWASP Top 10 vulnerabilities.
  • Experience securing cloud environments, particularly AWS, focusing on IAM and encryption.
  • Proficient in CI/CD security, vulnerability scanning, and monitoring.
  • Ability to conduct threat modeling for edge-to-cloud systems.

Responsibilities

  • Secure the end-to-end platform, encompassing edge devices to cloud infrastructure.
  • Identify, assess, and remediate security vulnerabilities in applications and hosted services.
  • Conduct threat modeling for various data flows, focusing on real-time video and sensor data.
  • Harden and secure edge devices, paying attention to OS security and patching.
  • Ensure the security of cloud environments, with particular emphasis on IAM and network security.
  • Participate in secure design and architecture reviews for new systems and features.
  • Monitor security incidents and lead post-incident reviews.

Benefits

  • Work in a cutting-edge tech environment focused on practical security engineering.
  • Opportunity to influence security practices from design to deployment.
  • Engagement with cross-functional teams to integrate security seamlessly into the workflow.
  • Chance to contribute to security compliance efforts like ISO 27001 and SOC 2.
  • Possibility for relocation to UAE following a probation period.
Full Job Description
Role Overview

We are looking for a hands-on Senior Security Engineer to help secure our end-to-end platform, from Linux-based edge devices deployed in the field to our cloud infrastructure, APIs, and data pipelines.

This is not a pure compliance role. The focus is practical security engineering: identifying risks, fixing vulnerabilities, and working closely with Engineering, Product, and Infrastructure teams to build security into how we design, deploy, and operate.

Our platform includes edge units deployed in roadside cabinets, processing real-time video and sensor data locally, then syncing insights and metadata to the cloud. This means the role requires someone who can think through real-world risks such as physical access, SSH exposure, device hardening, secure data transfer, cloud security, and incident response.
Key Responsibilities
  • Secure the end-to-end platform, from Linux-based edge devices to cloud infrastructure, APIs, and data pipelines.
  • Identify, assess, and remediate security risks across applications, backend services, and deployed devices.
  • Conduct threat modeling across edge-to-cloud data flows, including video, sensor data, and metadata pipelines.
  • Harden edge devices, including OS security, SSH access, credential management, and patching practices, especially in physically accessible environments.
  • Secure cloud environments (AWS preferred), including IAM, network security, encryption, secrets management, and logging.
  • Support secure design and architecture reviews for new features and deployments.
  • Implement and improve CI/CD security, vulnerability scanning, and monitoring practices.
  • Monitor and respond to security incidents, including compromised devices or unauthorized access, and lead post-incident reviews.
  • Define and improve security policies, standards, and controls aligned with practical engineering needs.
  • Support compliance efforts such as ISO 27001, SOC 2, and customer security reviews.
  • Work closely with Engineering and Product to embed security into development without slowing delivery.
  • Contribute to internal security awareness, documentation, and best practices.

Requirements
  • 6 to 8+ years in security engineering, application security, cloud security, or infrastructure security.
  • Hands-on experience securing production systems, not only compliance or audit.
  • Strong knowledge of Linux security, hardening, access controls, and patching.
  • Strong understanding of web application security, including OWASP Top 10.
  • Experience securing cloud platforms, preferably AWS, including IAM, networking, encryption, logging, and secrets management.
  • Experience with CI/CD security, vulnerability scanning, monitoring, and incident response.
  • Ability to threat model edge-to-cloud systems, APIs, data pipelines, and deployed devices.
  • Comfortable working closely with Product and Engineering to explain risks and drive fixes.
  • Scripting or automation skills, such as Python or Bash.
  • Experience with SOC 2, ISO 27001, or similar frameworks.
  • Experience in IoT, ITS, smart mobility, embedded systems, or data-heavy platforms is a strong plus.
  • Open to relocation to UAE after probation, subject to UAE immigration approval.

Similar Jobs

More Jobs at Derq

More Information Technology Jobs

Find similar Senior Security Engineer (Edge & Cloud) jobs: