United States
1 month ago

Job Overview

Job Type
Contractor
Pay
Not disclosed

Job description

Location:
United States
Work arrangement:
On-site

Role Summary

This is a remote position.

Strengthen cloud, application, and AI security by embedding practical controls across infrastructure, delivery pipelines, and incident workflows.

  • Organization: A confidential client; further details will be shared with shortlisted candidates, subject to client confidentiality requirements
  • Location: Remote - open to candidates in Egypt, Jordan, and other countries nearshore to the client's operating region
  • Role Type: Full-time | Consultant/contractor | Fixed-term project (6-8 months)
  • Reports to: To be confirmed

Our client is looking for a Middle+ Security Engineer to assess and reduce security risk across AWS infrastructure, application delivery, containers, and LLM/AI integrations. In this role, you will combine hands-on security engineering with automation, vulnerability remediation, and cross-functional technical review.

About the organization

Our client is a UAE-based HRTech scale-up transforming workplace operations across HR, Payroll, Finance, and Insurance in the MENA region. It helps employers and employees manage the full workplace lifecycle through a unified platform.

Responsibilities

  • Conduct threat modeling and security reviews for cloud infrastructure and LLM/AI integrations.
  • Integrate SAST, DAST, and SCA tools directly into CI/CD pipelines.
  • Harden AWS environments, Infrastructure as Code scripts, and Kubernetes workloads and containers.
  • Automate repetitive security tasks, alerting, and incident-response workflows using custom scripts.
  • Triage, investigate, and remediate vulnerabilities identified through automated scans and Bug Bounty programs.

Requirements

  • At least 3 years of professional experience in Security Engineering, DevSecOps, or a related role.
  • Scripting proficiency in Python, Go, or Ruby.
  • Deep hands-on experience with AWS cloud security services (IAM, VPC, GuardDuty, WAF, Inspector).
  • Practical experience with AppSec tooling (Burp Suite, OWASP ZAP, Snyk, or SonarQube).
  • Experience with container and orchestration security controls (Docker, Kubernetes).
  • Knowledge of Infrastructure as Code (IaC) security reviews (Terraform or CloudFormation).
  • Familiarity with AI/LLM security risks (OWASP Top 10 for LLMs, RAG architectures, API security).

How the engagement works

  • Contracting party: You will contract directly with Apricot, which will manage contracting, invoicing/payroll, payments, and administrative support. Day to day, you will work closely with the client team and follow the agreed scope, deliverables, and security requirements.
  • You are expected to provide your own laptop and basic equipment, maintain reliable connectivity and a secure working environment, and follow required security controls, including two-factor authentication.
  • Planned check-ins are at month 1 to see how the engagement is working and help address issues, given the shorter 6–8 month duration.

About Apricot

Apricot is a nonprofit sourcing firm connecting displaced and underserved professionals from Palestine and the wider MENA region with global employment opportunities. We combine a clear social-impact mission with fast, high-quality recruitment delivery for international clients.

Role:
Security Engineer
Job Type:
Contractor

More jobs at apricot

Similar Security Engineer jobs at other companies