
At Okala, we are looking for a Security Engineer to help build secure, scalable, and resilient products. In this role, you will work closely with Engineering, DevOps, and QA teams to integrate security throughout the software development lifecycle, proactively identify and mitigate security risks, and strengthen the security of our applications and infrastructure.
Monitor, investigate, and respond to security incidents, including conducting post-incident analysis to identify root causes and improve security controls.
Conduct security assessments of applications, APIs, and cloud infrastructure.
Identify, prioritize, and remediate security vulnerabilities.
Perform threat modeling and secure design reviews.
Integrate and maintain security controls within CI/CD pipelines (DevSecOps).
Collaborate with engineering teams to promote secure development practices.
Develop and maintain security standards, guidelines, and security best practices.
Proficiency in at least one programming language.
Solid knowledge of Web Security, API Security, and the OWASP Top 10.
Experience with Linux, Docker, Kubernetes, and CI/CD pipelines.
Familiarity with authentication and authorization mechanisms.
Experience with security testing and vulnerability assessment tools.
Strong analytical and problem-solving skills.
Excellent communication and collaboration skills with cross-functional engineering teams.
Have experience securing microservices and cloud-native applications.
Have hands-on experience with Kubernetes, Docker, and cloud-native security practices.
Are familiar with securing platforms such as Kafka, Redis, SQL Server, and Elasticsearch.
Have experience with security tools such as Burp Suite, OWASP ZAP, Trivy, Semgrep, SonarQube, Snyk, Checkov, or similar solutions.
Understand Web Application Firewalls (WAF), API security, and bot protection strategies.
Have experience with SIEM platforms, log analysis, and incident response processes.
Are familiar with security standards and frameworks such as OWASP ASVS, ISO 27001, PCI DSS, or CIS Benchmarks.
Think like both an engineer and a security advocate.
Enjoy solving complex security challenges before they become production issues.
Are passionate about DevSecOps, automation, and secure-by-design principles.
Collaborate effectively across Engineering, DevOps, QA, and Product teams.
Continuously explore emerging security threats, tools, and best practices.
ثبت مشکل و تخلف آگهی
ارسال رزومه برای اُکالا