[All remote jobs](https://jobicy.com/jobs.md)Open role[![Quora logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200916172339-629302.jpg)](https://jobicy.com/company/quora.md)Remote opportunity at[Quora](https://jobicy.com/company/quora.md)

# Senior Infrastructure Security Software Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/quora.md)Share29 Aug 2026Published28Listing views3Application actions28 Sep 2026Apply before  Opportunity details

## About this role.

AI SummaryQuora is hiring a Senior Infrastructure Security Software Engineer to help build protections for its Quora and Poe platforms. The role focuses on AWS and Kubernetes security, infrastructure-as-code, cloud monitoring, OS and container hardening, and security automation in CI/CD pipelines. The engineer will partner with product and infrastructure teams on architecture reviews, threat modeling, remediation roadmaps, policy enforcement, and incident triage. This is a senior individual-contributor role on a newly created security engineering team, requiring strong ownership and the ability to balance detailed technical work with pragmatic, scalable solutions. The position is remote-first and requires availability during Pacific Time coordination hours.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThe role requires deep hands-on expertise across cloud infrastructure, Linux and container security, secure software development, detection engineering, and incident response. It also demands senior-level judgment to define controls, influence engineering teams, and build scalable security automation with substantial independence.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$210,960US market range$170k–$255k0$281k

AI insightThe disclosed US base salary range is $172,279 to $249,640 USD yearly, with a midpoint of $210,959.50. This is consistent with the estimated US market range of $170,000 to $255,000 yearly for a senior infrastructure security software engineer at a remote-first technology company; equity and benefits are additional and are not included in the base-salary calculation.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[AWS security](https://jobicy.com/jobs?search_keywords=AWS%20security.md)[Kubernetes security](https://jobicy.com/jobs?search_keywords=Kubernetes%20security.md)[Infrastructure as Code](https://jobicy.com/jobs?search_keywords=Infrastructure%20as%20Code.md)[Terraform](https://jobicy.com/jobs?search_keywords=Terraform.md)[CloudFormation](https://jobicy.com/jobs?search_keywords=CloudFormation.md)[CI/CD security](https://jobicy.com/jobs?search_keywords=CICD%20security.md)[SAST and DAST](https://jobicy.com/jobs?search_keywords=SAST%20and%20DAST.md)[Linux security](https://jobicy.com/jobs?search_keywords=Linux%20security.md)[Incident response](https://jobicy.com/jobs?search_keywords=Incident%20response.md)[Threat modeling](https://jobicy.com/jobs?search_keywords=Threat%20modeling.md)

Sample interview questionsHow would you design a security baseline for a new AWS application environment?I would begin with threat modeling and data-flow mapping, then establish identity, network, logging, encryption, and monitoring controls. The baseline would use least-privilege IAM, segmented VPC design, centralized CloudTrail and audit logs, secure secrets management, policy-as-code checks, and automated remediation for high-confidence misconfigurations.

Describe how you would integrate security into an existing CI/CD pipeline without creating excessive developer friction.

I would first identify the highest-value controls, such as dependency scanning, secret detection, IaC scanning, and SAST, and tune them to prioritize exploitable, high-severity findings. I would make actionable checks visible early in pull requests, define clear exception and remediation workflows, and use metrics such as false-positive rate and time to remediate to improve adoption.

What is your approach to securing Kubernetes workloads?

I would apply defense in depth: hardened cluster configuration, RBAC least privilege, namespace isolation, network policies, image provenance and scanning, admission controls, workload security contexts, secrets management, and runtime detection. I would also ensure audit logging is centralized and that teams have paved-road deployment templates that make secure defaults easy to use.

How would you handle an alert indicating possible credential compromise in a cloud environment?

I would validate the alert and rapidly assess scope using identity, API, and network logs. If compromise is credible, I would contain it by revoking or rotating credentials, restricting suspicious sessions or permissions, preserving evidence, and coordinating incident communications; afterward, I would identify root cause and implement durable controls such as stronger credential handling, detection logic, or IAM guardrails.

How do you prioritize security remediation work when engineering capacity is limited?

I prioritize based on exploitability, business impact, asset criticality, exposure, and availability of compensating controls. I communicate the risk in practical terms, propose right-sized remediation options, and work with owners to sequence immediate containment, near-term fixes, and longer-term architectural improvements.

[[Quora is a privately held, “remote-first” company](https://www.quora.com/q/quora/Remote-First-at-Quora). This position can be performed remotely from anywhere in Canada or the United States. Please visit [careers.quora.com/eligible-countries](http://careers.quora.com/eligible-countries) for details regarding employment eligibility by country.]

### About Quora:

Quora’s mission is to grow the world’s collective intelligence. To do so, we have two platforms:

*

[Quora](http://quora.com): a global knowledge sharing platform with over 300M monthly unique visitors, bringing people together to share insights on various topics and providing a unique platform to learn and connect with others.

*

[Poe](https://poe.com/): a platform providing millions of global users with one place to chat, explore and build with a wide variety of AI language models (bots), including GPT-5.6-Sol, Claude-Opus-5, Claude-Fable-5, Claude-Sonnet-5, Kimi-K3, and thousands of others. As AI capabilities rapidly advance, Poe provides a single platform to instantly integrate and utilize these new models.

Behind these products are passionate, collaborative, and high-performing global teams. We have a culture rooted in transparency, idea-sharing, and experimentation that allows us to celebrate success and grow together through meaningful work. Join us on this journey to create a positive impact and make a significant change in the world.

This role will be supporting both our Quora and Poe products.

### About the Team and Role:

You will be a key member of the newly created Security Engineering Team, with a mission to keep Quora safe from security problems by building robust protections around our products, infrastructure and people. Our small engineering team works on challenging problems every day. We have a culture that’s rooted in constantly learning and improving, and our engineers are encouraged to think big and experiment with new ideas.

### What We’re Looking For:

*

Sweat The Right Details: you thrive in understanding the details but will also know to ruthlessly prioritize the critical issues.

*

Right-Size The Solution: you recognize guidelines and framework do not always fit the problem and know how to adjust the solution for scalability not always at-scale.

*

Ownership: you are outcome focused and can deftly navigate obstacles, decompose complexities, manage your time and can communicate your vision to peers and management.

### An Ideal Candidate Would…

be a capable software engineer while also spiking in at least one of the following domain expertise:

*

Cloud Infrastructure Security: You have hands-on experience securing large-scale cloud environments, particularly with AWS. You are passionate about building secure infrastructure-as-code (IaC) pipelines using tools like Terraform or CloudFormation. You understand IAM policies, network segmentation, and VPC design and have a thorough grasp of monitoring and logging in cloud-native environments. You are skilled in identifying misconfigurations, mitigating risks, and driving remediation processes. Bonus points if you’ve implemented security in Kubernetes clusters or serverless architectures.

*

Automation and Secure Development Practices: You believe in “security as code” and are skilled at automating security processes. You can develop and integrate security tools into CI/CD pipelines to ensure secure code delivery. Tools like SAST, DAST, and dependency scanning are part of your daily toolkit, and you have experience integrating them into workflows to catch vulnerabilities early. You also advocate for secure coding practices and are skilled at mentoring teams to write resilient, secure applications.

*

Linux/System Security: You are well versed in AWS infrastructure security but also are passionate about scalability, reliability and operational rigor. Beyond that, you know that root does not mean root and are passionate about container security, POSIX Capabilities, SECCOMP and have a favorite flavor of LSM. In your spare time, you love playing around with OSQuery and eBPF.

*

Product Security (nice-to-have): Not a requirement, but a real plus: experience building secure web applications and APIs, with a working grasp of the OWASP Top 10 and common vulnerabilities such as XSS, CSRF, and SQL injection. It complements the infrastructure security focus of this role and helps when partnering with product teams.

### Responsibilities:

*

Partner with engineering teams to review cloud and compute architecture design changes

*

Establish threat models for cloud and compute paved roads to identify security risks

*

Develop or adopt open-source tools to monitor and harden our cloud Infrastructure, harden our OS, develop security logging pipelines and detect intrusions

*

Apply your expert knowledge of security best practices for AWS and Kubernetes to inform remediations and the team’s control roadmap

*

Drive the definition and implementation of security policies and monitor in conformance to the policies

*

Write code for automations that support security requirements like threat detection, incident containment, and network access management.

*

Conduct initial incident triage; determine scope, urgency, and potential impact of security incidents; participate in the incident response process

At Quora, we value diversity and inclusivity and welcome individuals from all backgrounds, including marginalized or underrepresented groups in tech, to apply for our job openings. We encourage all candidates who share a passion for growing the world’s knowledge, even those who may not strictly meet all the preferred requirements, to apply, as we know that a diverse range of perspectives can have a significant impact on our products and our culture.

### Additional Information:

Successful candidates must have availability for meetings and impromptu communication during Quora’s “[coordination hours](https://quora.com/coordination_hours)” (Mon-Fri: 9am-3pm Pacific Time).

We are accepting applications on an ongoing basis.

Quora offers a wide range of benefits including medical/dental/vision coverage, equity refreshers, remote work reimbursement, paid time off, employee assistance programs, and more. Benefits are country-specific and may vary.

There are many factors that will determine the starting pay, including but not limited to experience, location, education, and business needs.

*

US candidates only: For US based applicants, the salary range is $172,279 – $249,640 USD + equity + benefits.

*

Canada candidates only: For Toronto and Vancouver based applicants, the salary range is $221,209 – $256,433 CAD + equity + benefits. For all other locations in Canada, the salary range is $206,461 – $239,337 CAD + equity + benefits.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

AI technology may assist in sorting applications and recording interview notes, but all decisions are made by a member of our team.

To ensure a secure hiring process, all final candidates will undergo identity verification and a comprehensive background check prior to onboarding.

Job Applicant Privacy Notice: [https://www.careers.quora.com/pages/quora-global-job-applicant-privacy-notice](https://www.careers.quora.com/pages/quora-global-job-applicant-privacy-notice)

#LI-JC1
#LI-REMOTE

Show more

[Apply now >](https://jobicy.com/jobs/151970-senior-infrastructure-security-software-engineer.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Quora logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200916172339-629302.jpg)
Quora  Aug 29

### [Detection & CorpSec Engineer](https://jobicy.com/jobs/151966-detection-corpsec-engineer.md)

[Quora is a privately held, “remote-first” company. This position can be performed remotely from anywhere in Canada or the United States. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by…

*
![Veeam Software logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/f7716b71-221.jpg)
Veeam Software  Aug 28

### [Cyber-Security Operations Analyst III, Product AppSec](https://jobicy.com/jobs/151951-cyber-security-operations-analyst-iii-product-appsec.md)

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI…

*
![Cision logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/e9661342-221.jpeg)
Cision  Aug 27

### [Security Engineer I, Information Technology](https://jobicy.com/jobs/151867-security-engineer-i-information-technology.md)

At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As…

*
![Cision logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/e9661342-221.jpeg)
Cision  Aug 27

### [Security Analyst I, Information Technology](https://jobicy.com/jobs/151862-security-analyst-i-information-technology.md)

At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As…

*
![LastPass logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13842160-221.png)
LastPass  Aug 27

### [Principal Cloud Security Engineer](https://jobicy.com/jobs/151831-principal-cloud-security-engineer.md)

About LastPassLastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and…

*
![Pleo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b27fbed2-221.jpg)
Pleo  Aug 27

### [Lead Security Operations Engineer](https://jobicy.com/jobs/151792-lead-security-operations-engineer.md)

About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we’re changing that. We build spend solutions…

*
![Ada logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/666ef11e-221.png)
Ada  Aug 27

### [Compliance and Security Lead](https://jobicy.com/jobs/151791-compliance-and-security-lead.md)

About Us Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service…

*
![Pleo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b27fbed2-221.jpg)
Pleo  Aug 27

### [Senior Application Security Manager](https://jobicy.com/jobs/151788-senior-application-security-manager.md)

About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we’re changing that. We build spend solutions…

*
![GitLab logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/12/WRILS-201207055737-109952.jpg)
GitLab  Aug 27

### [Senior Security Engineer, Security Incident Response Team (SIRT) – EMEA](https://jobicy.com/jobs/149309-senior-security-engineer-security-incident-response-team-sirt-emea.md)

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50…

*
![Vercel logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/a6aded72-221.png)
Vercel  Aug 27

### [Security Software Engineer, IAM](https://jobicy.com/jobs/147750-security-software-engineer-iam.md)

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built….