Job Overview
Job description
- Location:
- United States
- Work arrangement:
- On-site
Role Summary
This is a remote position.
Strengthen cloud, application, and AI security by embedding practical controls across infrastructure, delivery pipelines, and incident workflows.
- Organization: A confidential client; further details will be shared with shortlisted candidates, subject to client confidentiality requirements
- Location: Remote - open to candidates in Egypt, Jordan, and other countries nearshore to the client's operating region
- Role Type: Full-time | Consultant/contractor | Fixed-term project (6-8 months)
- Reports to: To be confirmed
Our client is looking for a Middle+ Security Engineer to assess and reduce security risk across AWS infrastructure, application delivery, containers, and LLM/AI integrations. In this role, you will combine hands-on security engineering with automation, vulnerability remediation, and cross-functional technical review.
About the organization
Our client is a UAE-based HRTech scale-up transforming workplace operations across HR, Payroll, Finance, and Insurance in the MENA region. It helps employers and employees manage the full workplace lifecycle through a unified platform.
Responsibilities
- Conduct threat modeling and security reviews for cloud infrastructure and LLM/AI integrations.
- Integrate SAST, DAST, and SCA tools directly into CI/CD pipelines.
- Harden AWS environments, Infrastructure as Code scripts, and Kubernetes workloads and containers.
- Automate repetitive security tasks, alerting, and incident-response workflows using custom scripts.
- Triage, investigate, and remediate vulnerabilities identified through automated scans and Bug Bounty programs.
Requirements
- At least 3 years of professional experience in Security Engineering, DevSecOps, or a related role.
- Scripting proficiency in Python, Go, or Ruby.
- Deep hands-on experience with AWS cloud security services (IAM, VPC, GuardDuty, WAF, Inspector).
- Practical experience with AppSec tooling (Burp Suite, OWASP ZAP, Snyk, or SonarQube).
- Experience with container and orchestration security controls (Docker, Kubernetes).
- Knowledge of Infrastructure as Code (IaC) security reviews (Terraform or CloudFormation).
- Familiarity with AI/LLM security risks (OWASP Top 10 for LLMs, RAG architectures, API security).
How the engagement works
- Contracting party: You will contract directly with Apricot, which will manage contracting, invoicing/payroll, payments, and administrative support. Day to day, you will work closely with the client team and follow the agreed scope, deliverables, and security requirements.
- You are expected to provide your own laptop and basic equipment, maintain reliable connectivity and a secure working environment, and follow required security controls, including two-factor authentication.
- Planned check-ins are at month 1 to see how the engagement is working and help address issues, given the shorter 6–8 month duration.
About Apricot
Apricot is a nonprofit sourcing firm connecting displaced and underserved professionals from Palestine and the wider MENA region with global employment opportunities. We combine a clear social-impact mission with fast, high-quality recruitment delivery for international clients.
- Role:
- Security Engineer
- Job Type:
- Contractor