Kong Inc.

Technology

StaffSecurityEngineer

€85–125k ~AI est. Milan, Italy FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Staff Security Engineer at Kong Inc.. Skills: API gateway security, Network security, Multi-cloud security. Serve as technical security lead. Architect security capabilities”

Industry & Context.

Technology
Problems you'll solve

Incident resolution; Complex security challenges

What They're Looking For.

Must Have

8+ years experience in Cybersecurity Engineering, Focus on high-traffic infrastructure or API management, Extensive experience with Kong Gateway, Nginx, eBPF, or similar technologies, Expert-level knowledge of multi-cloud solution design, Proven track record in designing/deploying WAF, IDS, and IPS systems at scale, Understanding of signature-based vs. ML-based detection, Programming Proficiency: Python, Go or Rust

Nice to Have

Experience contributing to or maintaining open-source security projects

What You'll Do.

Serve as technical security lead

Architect security capabilities

Leverage Open Source (OSS)

Build network security solutions

Build application security solutions

Act as subject matter expert

Architect WAF capabilities

Implement WAF capabilities

Architect IDS capabilities

Implement IDS capabilities

Architect IPS capabilities

Implement IPS capabilities

Design Zero Trust security models

Implement Zero Trust security models

Define security roadmap

Lead incident response

Respond to supply chain vulnerabilities

Remediate high-stakes CVEs

Champion Security-First culture

Mentor engineers on secure coding

Influence cybersecurity maturity

How You'll Work.

Team & Collaboration

Partner with Product; Partner with Architecture leads

Process & Methodology

Strategic roadmap

Full Job Description

Are you ready to unlock intelligence? If you don’t think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we’re looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others. About the Role: As a Staff Security Engineer, you will serve as the technical security lead for securing the world’s most popular API gateway. You will apply deep expertise in high-performance networking and distributed systems to shape the security posture of the Kong Cloud. You’ll spend your time architecting the evolution of our security capabilities—specifically focused on leveraging Open Source (OSS) and building state of the art network and application security solutions.. What you'll do: - Domain Expertise: Act as the lead subject matter expert for the Kong Cloud Security Operations. - Threat Defense Leadership: Architect and implement next-generation WAF, IDS, and IPS capabilities at the gateway level to protect against OWASP Top 10, zero-day exploits, and sophisticated API abuse. - Multi-Cloud Security: Design and implement "Zero Trust" security models that operate seamlessly across hybrid and multi-cloud environments (AWS, Azure, GCP, On-prem). - Strategic Roadmap: Partner with Product and Architecture leads to define the multi-year security roadmap for Kong Gateway, balancing the needs of the OSS community with Enterprise requirements. - Incident Resolution: Lead the response to complex, multi-faceted security challenges—from supply chain vulnerabilities in open-source dependencies to high-stakes CVE remediations. - Mentorship & Influence: Champion a "Security-First" culture by mentoring engineers on secure coding practices and influencing the long-term cybersecurity maturity of the entire organization. What you'll bring: - 8+ years’ experience in Cybersecurity Engineering, with a focus on high-traffic infrastructure or API management. - Extensive experience with Kon

Free ATS check

Applying for this Staff Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Kong Inc.?

Real rants from real employees. Read before you apply.

Read Company Rants →