Lead Security Engineer

๐Ÿข Circles ยท all Circles jobs
๐Ÿ“ United States
๐Ÿ“… Posted 2026-07-11 ยท via Himalayas
๐Ÿท Lead-Security-Engineer,Application-Security-Engineer,Security-Engineering,Cybersecurity,DevSecOps,Security-Engineering-Lead,Lead-Cybersecurity-Engineer,Lead-Information-Security-Engineer,Lead-Application-Security-Engineer,Principal-Security-Engineer,Cloud-Security-Engineer
Apply on original site โ†—

Founded in 2014, Circles is a global technology company reimagining the telco industry with its innovative SaaS platform, empowering telco operators worldwide to effortlessly launch innovative digital brands or refresh existing ones, accelerating their transformation into techcos.

Today, Circles partners with leading telco operators across multiple countries and continents, including KDDI Corporation, Etisalat Group (e&), AT&T, and Telkomsel, creating blueprints for future telco and digital experiences enjoyed by millions of consumers globally.

Besides its SaaS business, Circles operates three other distinct businesses:
-
Circles .Life: A wholly-owned digital lifestyle telco brand based in Singapore, Circles .Life is powered by Circles โ€™ SaaS platform and pioneering go-to-market strategies. It is the digital market leader in Singapore and has won numerous awards for marketing, customer service, and innovative product offerings beyond connectivity.

-
Circles Aspire: A global provider of Communications Platform-as-a-Service (CPaaS) solutions. Its cloud-based Experience Cloud platform enables enterprises, service providers and developers to deliver and scale mobile, messaging, IoT, and connectivity services worldwide.

- Jetpac: Specializing in travel tech solutions, Jetpac provides seamless eSIM roaming for over 200 destinations and innovative travel lifestyle products, redefining connectivity for digital travelers. Jetpac was awarded Travel eSIM of the Year.

Circles is backed by renowned global investors, including Peak XV Partners (formerly Sequoia), Warburg Pincus, Founders Fund, and EDBI (the investment arm of the Singapore Economic Development Board), with a track record of backing industry challengers.
Role - Lead Security Engineer

Department: Information Security

Reports To: Head of Security Engineering

Experience: - 10-12 Years

Type: Individual Contributor (IC)

Standard Job Title - Staff Engineer, Security Engineering
Role Summary

We're looking for a hands-on Lead Security Engineer to strengthen our security posture across applications, APIs, cloud infrastructure, and engineering platforms. This IC role owns secure architecture, application security, penetration testing, SOC incident response, and security automation โ€” partnering closely with Engineering, DevOps, and Product to embed security throughout the SDLC rather than bolt it on at the end.
Key Responsibilities
Secure Architecture & Threat Modeling

-
Lead threat modeling (STRIDE, PASTA, or equivalent) for new applications, features, and major platform changes

-
Conduct security architecture reviews for applications, APIs, cloud infrastructure, and third-party services before go-live

-
Define secure design patterns and reference architectures; provide hands-on security guidance at every stage of the SDLC, not just at release gates

Application & API Security

-
Own the Application Security program end-to-end: SAST, DAST, SCA, and API security testing โ€” tool selection, policy tuning, and triage workflows

-
Integrate security testing natively into CI/CD pipelines and DevSecOps workflows so findings surface before merge, not after deploy

-
Assess REST and GraphQL APIs against the OWASP API Security Top 10 (broken object/function-level authorization, excessive data exposure, rate limiting, business logic abuse)

-
Partner with engineering leads to prioritize findings by exploitability and business impact, and drive remediation within agreed SLAs

Penetration Testing & Vulnerability Management

-
Plan and execute internal penetration tests across web applications, APIs, cloud, and infrastructure; scope and oversee external pen test engagements

-
Manually validate findings to separate real risk from noise before they reach engineering backlogs

-
Own the vulnerability management lifecycle โ€” from discovery through remediation to verified closure โ€” and continuously tighten SLAs as maturity improves

โ† All remote jobs