Back to search
EngineeringHybrid

Senior Security Engineer

Kong · Hybrid

Apply
Last seen by MeritLog September 9, 2026Source: AshbySource version: ashby-public-job-posting-v1

MeritLog read this listing from Kong's Ashby job board and last checked it on September 9, 2026.

Source: the employer's Ashby job board. Open the original listing for current details.

Job details

Work model
Hybrid
Salary
Not listed by source
Location
Milan, Italy
Company website
konghq.com

Hiring context

How this role compares at Kong

Kong has 71 live roles in MeritLog’s catalog across 8 job families, and 37 of them are in engineering. 23 of those listings publish a pay range, a disclosure rate of 32%.

Counted across the job boards MeritLog tracks, at the time this page was served. Pay comparisons use only listings that publish a complete range in the same currency and period.

What the role asks for

What you'd do

  • Threat Defense Leadership: Architect and implement next-generation WAF, IDS, and IPS capabilities at the gateway level to protect against OWASP Top 10, zero-day exploits, and sophisticated API abuse.
  • Multi-Cloud Security: Design and implement "Zero Trust" security models that operate seamlessly across hybrid and multi-cloud environments (AWS, Azure, GCP, On-prem).
  • Strategic Roadmap: Partner with Product and Architecture leads to define the multi-year security roadmap for Kong Gateway, balancing the needs of the OSS community with Enterprise requirements.
  • Incident Resolution: Lead the response to complex, multi-faceted security challenges-from supply chain vulnerabilities in open-source dependencies to high-stakes CVE remediations.
  • Mentorship & Influence: Champion a "Security-First" culture by mentoring engineers on secure coding practices and influencing the long-term cybersecurity maturity of the entire organization.

What they're asking for

  • 5+ years’ experience in Cybersecurity Engineering, with a focus on high-traffic infrastructure or API management.Experience
  • Cloud-Native & Multi-Cloud: Expert-level knowledge of multi-cloud solution design, specifically securing traffic across disparate cloud providers and Kubernetes environments.Skill
  • Security Domain Specialist: Proven track record in designing/deploying WAF, IDS, and IPS systems at scale, with an understanding of signature-based vs. ML-based detection.Skill
  • Programming Proficiency:Python, Go or RustSkill
  • Open Source Contributor: Experience contributing to or maintaining open-source security projects is a significant asset.Skill
  • Design Excellence: Ability to produce high-quality, high-performance security designs that do not compromise the "millisecond-latency" promise of the gateway.Skill

Parsed by MeritLog from the employer’s own posting. The full description follows below.

Job description

Are you ready to unlock intelligence? If you don’t think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we’re looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others. About the Role: As a Senior Security Engineer, you will serve as the technical security lead for securing the world’s most popular API gateway. You will apply deep expertise in high-performance networking and distributed systems to shape the security posture of the Kong Cloud. You’ll spend your time architecting the evolution of our security capabilities-specifically focused on leveraging Open Source (OSS) and building state of the art network and application security solutions.. What You'll Do: - Threat Defense Leadership: Architect and implement next-generation WAF, IDS, and IPS capabilities at the gateway level to protect against OWASP Top 10, zero-day exploits, and sophisticated API abuse. - Multi-Cloud Security: Design and implement "Zero Trust" security models that operate seamlessly across hybrid and multi-cloud environments (AWS, Azure, GCP, On-prem). - Strategic Roadmap: Partner with Product and Architecture leads to define the multi-year security roadmap for Kong Gateway, balancing the needs of the OSS community with Enterprise requirements. - Incident Resolution: Lead the response to complex, multi-faceted security challenges-from supply chain vulnerabilities in open-source dependencies to high-stakes CVE remediations. - Mentorship & Influence: Champion a "Security-First" culture by mentoring engineers on secure coding practices and influencing the long-term cybersecurity maturity of the entire organization. What You'll Bring: - 5+ years’ experience in Cybersecurity Engineering, with a focus on high-traffic infrastructure or API management. - Cloud-Native & Multi-Cloud: Expert-level knowledge of multi-cloud solution design, specifically securing traffic across disparate cloud providers and Kubernetes environments. - Security Domain Specialist: Proven track record in designing/deploying WAF, IDS, and IPS systems at scale, with an understanding of signature-based vs. ML-based detection. - Programming Proficiency:Python, Go or Rust - Open Source Contributor: Experience contributing to or maintaining open-source security projects is a significant asset. - Design Excellence: Ability to produce high-quality, high-performance security designs that do not compromise the "millisecond-latency" promise of the gateway. #LI-EA1 About Kong: Kong Inc., a leading developer of API and AI connectivity technologies, is building the infrastructure that powers the agentic era. Trusted by the Fortune 500 and startups alike, Kong's unified API and AI platform, Kong Konnect, enables organizations to secure, manage, accelerate, govern, and monetize the flow of intelligence across APIs and AI models. For more information, visit www.konghq.com http://www.konghq.com.

Privacy choices

Analytics and advertising stay off unless you allow them. Private data stays out.

Read the privacy notice