Security Engineer
About Kami
Kami is a thriving organisation filled to the brim with talented, creative, and passionate people! It’s hard not to love what you do when our leading digital classroom platform offers meaningful solutions to over 70 million users worldwide, empowering students and supporting teachers!
You’ll be joining at a pretty magical time. Kami ’s user base is growing by the day. With over 170 team members across the world, we couldn’t be prouder of the accomplishments and milestones we’ve achieved to date. Now, this is your chance to join our team and become an integral member of Kami ’s growth, while shaping your own future (and having fun doing it)!
The Opportunity
As a Security Engineer at Kami , you won't just be identifying risks and writing reports—you will be the one actively fixing them. We are expanding our in-house security team and need a hands-on engineer who thrives on pure engineering remediation. In this role, you will leverage our automated security tools, scanning platforms, and risk/vulnerability processes to pinpoint faults and defects across our systems and applications.
Instead of just passing off a ticket, you will jump directly into the codebase to patch those vulnerabilities, refactor out-of-life or legacy code, upgrade outdated libraries and dependencies to ensure our environment is secure and modernized. You will act as a core technical resource for the broader engineering team, writing clear security documentation and playbooks, and actively assisting and guiding developers to successfully remediate defects within their own workflows.
You will be the ultimate bridge between automated threat detection and active engineering execution, embedding robust security guardrails directly into our software development life cycle. If you are a builder who loves deep, code-level troubleshooting, enjoys replacing stale legacy infrastructure with secure code, and wants to protect a platform supporting over 50 million global users, this is the perfect place to make a massive impact.
What You’ll Do
Vulnerability & Legacy Code Remediation
- Utilize automated scanners and internal risk processes to hunt down defects. Actively dive into code bases to update outdated libraries, rewrite out-of-life legacy components, and resolve critical technical debt.
- Ensure continuous modernization of Kami ’s codebase by wiping out vulnerabilities stemming from deprecated packages and old dependencies before they can be exploited.
Developer Support & Cross-Team Guidance
- Collaborate actively with engineering pods, reviewing their security posture and directly assisting them in troubleshooting and executing defect remediation.
- Accelerate internal security engineering cycles by clearing remediation blockers for engineering teams, turning security into a supportive peer function.
Security Documentation & Playbooks
- Draft comprehensive, easy-to-follow security playbooks, coding standards guidelines, and remediation documentation for internal distribution.
- Create a standardized knowledge base that upskills the entire engineering group on modern secure coding practices and streamlined defect fixing.
Secure SDLC Integration
- Embed automated security scanning tools, analysis processes, and proactive guardrails cleanly inside the active software development lifecycle.
- Ensure systematic and early-stage identification of technical faults across applications, moving toward a continuous 'shift-left' security model.
Infrastructure Hardening
- Implement and maintain robust cloud infrastructure protections, including customized firewalls, intrusion detection mechanisms, and advanced encryption protocols.
- Preserve the absolute structural integrity of our global digital infrastructure, securely partitioning and safeguarding core assets.
Incident Response Automation
- Manage and execute the emergency incident response lifecycle, building automated logic to spot, flag, and contain system anomalies instantly.