All remote jobs

Senior Software Engineer – Infrastructure Security

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Remote from
USA, Canada
Salary
USD 172,279–249,640 / yr
Department
Cybersecurity
Employment
Full Time
Experience
Senior
Published
Apply before
29 Oct 2026
Listing views
25
Application actions
1
Application toolkit

Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

The role, at a glance.

This senior infrastructure security role builds and operates security controls across Quora and Poe cloud environments. The engineer will review AWS and compute architecture, establish threat models, harden infrastructure and operating systems, and automate detection and response capabilities. Core technical areas include Terraform or CloudFormation, IAM, VPC design, Kubernetes, CI/CD security tooling, Linux security, and cloud logging. The role also partners closely with engineering teams on remediation, policy implementation, and incident triage. It is a high-impact individual-contributor position within a newly created Security Engineering team.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

4/5
IndependentCollaborative
AI insightThe position requires deep, hands-on expertise across cloud, platform, Linux, container, and application-security domains while building scalable controls in a changing environment. It also carries significant ownership for architectural guidance, remediation strategy, automation, and initial incident response.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive
$210,960
US market range$170k–$250k
AI insightThe disclosed US annual salary range is $172,279 to $249,640 USD, with a midpoint of $210,959.50. This aligns with the estimated US market range of $170,000 to $250,000 annually for a senior infrastructure security engineer with AWS, Kubernetes, security automation, and incident-response responsibilities. Separate Canada-specific CAD ranges are also disclosed but are not combined with the US USD salary fields.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you approach securing an AWS environment managed through infrastructure as code?

I would begin by establishing secure baseline modules and guardrails for IAM, networking, encryption, logging, and account separation. I would integrate policy-as-code and IaC scanning into pull requests and deployment pipelines, then continuously monitor deployed resources for drift and misconfiguration. Findings should be prioritized by exposure and business impact, with clear ownership and remediation workflows.

Describe how you would threat-model a new Kubernetes-based service.

I would map assets, trust boundaries, data flows, identities, ingress and egress paths, and administrative interfaces. I would evaluate threats such as overly permissive RBAC, insecure workload identities, exposed APIs, vulnerable images, secret leakage, and lateral movement. The resulting controls would include namespace isolation, network policies, admission controls, image scanning, runtime detection, and centralized audit logging.

What security checks would you integrate into a CI/CD pipeline?

I would include secret detection, dependency and SBOM scanning, SAST, IaC scanning, container image scanning, and targeted DAST where appropriate. Checks should provide actionable feedback early in development, with risk-based blocking for critical issues and exceptions governed through a documented process. I would also measure remediation time and recurring finding types to improve the engineering workflow.

How do POSIX capabilities and seccomp improve container security?

POSIX capabilities allow a process to receive only the privileges it needs rather than broad root-level privileges. Seccomp restricts the system calls a containerized process can invoke, reducing its available attack surface. Used alongside non-root execution, read-only filesystems, restrictive RBAC, and runtime monitoring, they materially limit the impact of a compromised workload.

How would you handle initial triage of a suspected cloud security incident?

I would first validate the signal, establish scope, and preserve relevant evidence such as CloudTrail, identity, workload, and network logs. I would assess urgency based on affected assets, privilege level, potential data exposure, and active attacker behavior, then coordinate containment actions that minimize business disruption. After containment, I would drive root-cause analysis, remediation, detection improvements, and a documented incident review.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.
Opportunity details

About this role.

[Quora is a privately held, “remote-first” company. This position can be performed remotely from anywhere in Canada or the United States. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by country.]

About Quora:

Quora’s mission is to grow the world’s collective intelligence. To do so, we have two platforms:

  • Quora: a global knowledge sharing platform with millions of monthly unique visitors, bringing people together to share insights on various topics and providing a unique platform to learn and connect with others.

  • Poe: a cloud workspace where millions of users run multiple AI agents on shared context and tools. One subscription, every frontier model, and the collaboration layer that makes them work together.

Behind these products are passionate, collaborative, and high-performing global teams. We have a culture rooted in transparency, idea-sharing, and experimentation that allows us to celebrate success and grow together through meaningful work. Join us on this journey to create a positive impact and make a significant change in the world.

This role will be supporting both our Quora and Poe products.

About the Team and Role:

You will be a key member of the newly created Security Engineering Team, with a mission to keep Quora safe from security problems by building robust protections around our products, infrastructure and people. Our small engineering team works on challenging problems every day. We have a culture that’s rooted in constantly learning and improving, and our engineers are encouraged to think big and experiment with new ideas.

What We’re Looking For:

  • Sweat The Right Details: you thrive in understanding the details but will also know to ruthlessly prioritize the critical issues.

  • Right-Size The Solution: you recognize guidelines and framework do not always fit the problem and know how to adjust the solution for scalability not always at-scale.

  • Ownership: you are outcome focused and can deftly navigate obstacles, decompose complexities, manage your time and can communicate your vision to peers and management.

An Ideal Candidate Would…

be a capable software engineer while also spiking in at least one of the following domain expertise:

  • Cloud Infrastructure Security: You have hands-on experience securing large-scale cloud environments, particularly with AWS. You are passionate about building secure infrastructure-as-code (IaC) pipelines using tools like Terraform or CloudFormation. You understand IAM policies, network segmentation, and VPC design and have a thorough grasp of monitoring and logging in cloud-native environments. You are skilled in identifying misconfigurations, mitigating risks, and driving remediation processes. Bonus points if you’ve implemented security in Kubernetes clusters or serverless architectures.

  • Automation and Secure Development Practices: You believe in “security as code” and are skilled at automating security processes. You can develop and integrate security tools into CI/CD pipelines to ensure secure code delivery. Tools like SAST, DAST, and dependency scanning are part of your daily toolkit, and you have experience integrating them into workflows to catch vulnerabilities early. You also advocate for secure coding practices and are skilled at mentoring teams to write resilient, secure applications.

  • Linux/System Security: You are well versed in AWS infrastructure security but also are passionate about scalability, reliability and operational rigor. Beyond that, you know that root does not mean root and are passionate about container security, POSIX Capabilities, SECCOMP and have a favorite flavor of LSM. In your spare time, you love playing around with OSQuery and eBPF.

  • Product Security (nice-to-have): Not a requirement, but a real plus: experience building secure web applications and APIs, with a working grasp of the OWASP Top 10 and common vulnerabilities such as XSS, CSRF, and SQL injection. It complements the infrastructure security focus of this role and helps when partnering with product teams.

Responsibilities:

  • Partner with engineering teams to review cloud and compute architecture design changes

  • Establish threat models for cloud and compute paved roads to identify security risks

  • Develop or adopt open-source tools to monitor and harden our cloud Infrastructure, harden our OS, develop security logging pipelines and detect intrusions

  • Apply your expert knowledge of security best practices for AWS and Kubernetes to inform remediations and the team’s control roadmap

  • Drive the definition and implementation of security policies and monitor in conformance to the policies

  • Write code for automations that support security requirements like threat detection, incident containment, and network access management.

  • Conduct initial incident triage; determine scope, urgency, and potential impact of security incidents; participate in the incident response process

At Quora, we value diversity and inclusivity and welcome individuals from all backgrounds, including marginalized or underrepresented groups in tech, to apply for our job openings. We encourage all candidates who share a passion for growing the world’s knowledge, even those who may not strictly meet all the preferred requirements, to apply, as we know that a diverse range of perspectives can have a significant impact on our products and our culture.

Additional Information:

Successful candidates must have availability for meetings and impromptu communication during Quora’s “coordination hours” (Mon-Fri: 9am-3pm Pacific Time).

We are accepting applications on an ongoing basis.

Quora offers a wide range of benefits including medical/dental/vision coverage, equity refreshers, remote work reimbursement, paid time off, employee assistance programs, and more. Benefits are country-specific and may vary.

There are many factors that will determine the starting compensation, including but not limited to experience, location, education, and business needs.

  • US candidates only: For US based applicants, the salary range is $172,279 – $249,640 USD + equity + benefits.

  • Canada candidates only: For Toronto and Vancouver based applicants, the salary range is $221,209 – $256,433 CAD + equity + benefits. For all other locations in Canada, the salary range is $206,461 – $239,337 CAD + equity + benefits.

  • In equity-eligible countries, we currently also offer a flexible equity program where a portion of equity compensation may be taken as cash.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

AI technology may assist in sorting applications and recording interview notes, but all decisions are made by a member of our team.

To ensure a secure hiring process, all final candidates will undergo identity verification and a comprehensive background check prior to onboarding.

Job Applicant Privacy Notice: https://www.careers.quora.com/pages/quora-global-job-applicant-privacy-notice

#LI-JC1
#LI-REMOTE

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. .

Log in to save
One quick step before you apply

Sign in to continue.

Sign in or create a free account to continue to the employer's application.

Applying is free. After signing in, return to this job and select Apply Now.
Add alert
Jobs Talent AI Tools Salaries
Menu