Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
https://bayt.page.link/mYpS81AP8e5uazqe8
Back to the job results

Security Lead

3 days ago 2026/08/29
Other Business Support Services
Create a job alert for similar positions
Job alert turned off. You won’t receive updates for this search anymore.

Job description

About PetroApp

PetroApp is building a modern technology platform, helping customers and partners move faster with confident, reliable systems. As we scale our engineering organization, we’re investing in both world-class reliability and pragmatic, high-impact security.


The Role

We’re hiring a Security Lead with a strong DevOps/SRE background to build and lead our security practice while remaining hands-on across cloud infrastructure, CI/CD, and production reliability.


You’ll own the security strategy across the SDLC and production environment, embed security into developer workflows, lead vulnerability management and penetration testing with external vendors, and work closely with our Platform/DevOps/SRE team to ensure PetroApp’s systems are both secure and reliable.


What You’ll DoSecurity Leadership & Strategy
  • Own the overall security roadmap and strategy for PetroApp, aligning it with business and product priorities.
  • Act as the primary security point of contact for engineering and leadership.
  • Define, document, and maintain security policies, standards, and guidelines for engineering teams.
  • Lead risk assessments, threat modeling, and security design reviews for major initiatives.
  • Define and track key security KPIs and report status, risks, and progress to leadership.
DevSecOps & SDLC Security
  • Embed security into the SDLC by integrating SAST, DAST, dependency and container scanning, and IaC scanning into CI/CD pipelines.
  • Establish secure coding practices and patterns; provide guidance and reviews for high-risk changes.
  • Set up and maintain secrets management and secrets detection across repos and environments.
  • Drive vulnerability management: triage findings, prioritize remediation, track SLAs, and verify fixes.
  • Partner with engineers to ensure security controls are automated and developer-friendly.
Cloud & Platform Security (with SRE Mindset)
  • Own and continuously improve the cloud and platform security posture (IAM, networking, encryption, key management, hardening).
  • Design and enforce least privilege access models and secure-by-default infrastructure baselines.
  • Ensure security is built into core platform components such as Kubernetes, service-to-service communication, and data stores.
  • Collaborate with SRE/DevOps on secure, resilient architectures, covering scalability, failover, and disaster recovery.
Reliability & Incident Collaboration
  • Collaborate with SRE/DevOps to maintain high availability and reliability of production systems.
  • Contribute to observability and monitoring with a security lens: actionable alerts, meaningful logging, and traceability.
  • Participate in incident response for security-related events, including root cause analysis and long-term fixes.
  • Help improve on-call and incident processes where security and reliability intersect.
External Security Engagements & Enablement
  • Own relationships with external security vendors, including penetration testing and security assessments.
  • Scope, coordinate, and manage penetration tests; track findings through to remediation and retesting.
  • Coordinate security-related input for audits, certifications, and customer security questionnaires as needed.
  • Run security awareness and training initiatives tailored to engineers and operational teams.
This job post has been translated by AI and may contain minor differences or errors.

You’ve reached the maximum limit of 15 job alerts. To create a new alert, please delete an existing one first.
Job alert created for this search. You’ll receive updates when new jobs match.
Are you sure you want to unapply?

You'll no longer be considered for this role and your application will be removed from the employer's inbox.