[All remote jobs](https://jobicy.com/jobs.md)[![Quora logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200916172339-629302.jpg)](https://jobicy.com/company/quora.md)[Quora](https://jobicy.com/company/quora.md)

# Senior Software Engineer – Infrastructure Security

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/quora.md)ShareRemote from[USA](https://jobicy.com/job-region/usa.md), [Canada](https://jobicy.com/job-region/canada.md)SalaryUSD 172,279–249,640 / yrDepartment[Cybersecurity](https://jobicy.com/categories/cybersecurity.md)EmploymentFull TimeExperienceSeniorPublished29 Sep 2026Apply before29 Oct 2026Listing views32Application actions1Application toolkit

## Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

## The role, at a glance.

This senior infrastructure security role builds and operates security controls across Quora and Poe cloud environments. The engineer will review AWS and compute architecture, establish threat models, harden infrastructure and operating systems, and automate detection and response capabilities. Core technical areas include Terraform or CloudFormation, IAM, VPC design, Kubernetes, CI/CD security tooling, Linux security, and cloud logging. The role also partners closely with engineering teams on remediation, policy implementation, and incident triage. It is a high-impact individual-contributor position within a newly created Security Engineering team.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

4/5IndependentCollaborative

AI insightThe position requires deep, hands-on expertise across cloud, platform, Linux, container, and application-security domains while building scalable controls in a changing environment. It also carries significant ownership for architectural guidance, remediation strategy, automation, and initial incident response.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive$210,960US market range$170k–$250k0$275k

AI insightThe disclosed US annual salary range is $172,279 to $249,640 USD, with a midpoint of $210,959.50. This aligns with the estimated US market range of $170,000 to $250,000 annually for a senior infrastructure security engineer with AWS, Kubernetes, security automation, and incident-response responsibilities. Separate Canada-specific CAD ranges are also disclosed but are not combined with the US USD salary fields.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[AWS security](https://jobicy.com/jobs?search_keywords=AWS%20security.md)[cloud infrastructure security](https://jobicy.com/jobs?search_keywords=cloud%20infrastructure%20security.md)[Terraform](https://jobicy.com/jobs?search_keywords=Terraform.md)[Kubernetes security](https://jobicy.com/jobs?search_keywords=Kubernetes%20security.md)[IAM](https://jobicy.com/jobs?search_keywords=IAM.md)[network security](https://jobicy.com/jobs?search_keywords=network%20security.md)[CI/CD security](https://jobicy.com/jobs?search_keywords=CICD%20security.md)[SAST and DAST](https://jobicy.com/jobs?search_keywords=SAST%20and%20DAST.md)[Linux security](https://jobicy.com/jobs?search_keywords=Linux%20security.md)[incident response](https://jobicy.com/jobs?search_keywords=incident%20response.md)

Sample interview questionsHow would you approach securing an AWS environment managed through infrastructure as code?I would begin by establishing secure baseline modules and guardrails for IAM, networking, encryption, logging, and account separation. I would integrate policy-as-code and IaC scanning into pull requests and deployment pipelines, then continuously monitor deployed resources for drift and misconfiguration. Findings should be prioritized by exposure and business impact, with clear ownership and remediation workflows.

Describe how you would threat-model a new Kubernetes-based service.

I would map assets, trust boundaries, data flows, identities, ingress and egress paths, and administrative interfaces. I would evaluate threats such as overly permissive RBAC, insecure workload identities, exposed APIs, vulnerable images, secret leakage, and lateral movement. The resulting controls would include namespace isolation, network policies, admission controls, image scanning, runtime detection, and centralized audit logging.

What security checks would you integrate into a CI/CD pipeline?

I would include secret detection, dependency and SBOM scanning, SAST, IaC scanning, container image scanning, and targeted DAST where appropriate. Checks should provide actionable feedback early in development, with risk-based blocking for critical issues and exceptions governed through a documented process. I would also measure remediation time and recurring finding types to improve the engineering workflow.

How do POSIX capabilities and seccomp improve container security?

POSIX capabilities allow a process to receive only the privileges it needs rather than broad root-level privileges. Seccomp restricts the system calls a containerized process can invoke, reducing its available attack surface. Used alongside non-root execution, read-only filesystems, restrictive RBAC, and runtime monitoring, they materially limit the impact of a compromised workload.

How would you handle initial triage of a suspected cloud security incident?

I would first validate the signal, establish scope, and preserve relevant evidence such as CloudTrail, identity, workload, and network logs. I would assess urgency based on affected assets, privilege level, potential data exposure, and active attacker behavior, then coordinate containment actions that minimize business disruption. After containment, I would drive root-cause analysis, remediation, detection improvements, and a documented incident review.

Opportunity details

## About this role.

[[Quora is a privately held, “remote-first” company](https://www.quora.com/q/quora/Remote-First-at-Quora). This position can be performed remotely from anywhere in Canada or the United States. Please visit [careers.quora.com/eligible-countries](http://careers.quora.com/eligible-countries) for details regarding employment eligibility by country.]

### About Quora:

Quora’s mission is to grow the world’s collective intelligence. To do so, we have two platforms:

*

[Quora](http://quora.com): a global knowledge sharing platform with millions of monthly unique visitors, bringing people together to share insights on various topics and providing a unique platform to learn and connect with others.

*

[Poe](https://poe.com/): a cloud workspace where millions of users run multiple AI agents on shared context and tools. One subscription, every frontier model, and the collaboration layer that makes them work together.

Behind these products are passionate, collaborative, and high-performing global teams. We have a culture rooted in transparency, idea-sharing, and experimentation that allows us to celebrate success and grow together through meaningful work. Join us on this journey to create a positive impact and make a significant change in the world.

This role will be supporting both our Quora and Poe products.

### About the Team and Role:

You will be a key member of the newly created Security Engineering Team, with a mission to keep Quora safe from security problems by building robust protections around our products, infrastructure and people. Our small engineering team works on challenging problems every day. We have a culture that’s rooted in constantly learning and improving, and our engineers are encouraged to think big and experiment with new ideas.

### What We’re Looking For:

*

Sweat The Right Details: you thrive in understanding the details but will also know to ruthlessly prioritize the critical issues.

*

Right-Size The Solution: you recognize guidelines and framework do not always fit the problem and know how to adjust the solution for scalability not always at-scale.

*

Ownership: you are outcome focused and can deftly navigate obstacles, decompose complexities, manage your time and can communicate your vision to peers and management.

### An Ideal Candidate Would…

be a capable software engineer while also spiking in at least one of the following domain expertise:

*

Cloud Infrastructure Security: You have hands-on experience securing large-scale cloud environments, particularly with AWS. You are passionate about building secure infrastructure-as-code (IaC) pipelines using tools like Terraform or CloudFormation. You understand IAM policies, network segmentation, and VPC design and have a thorough grasp of monitoring and logging in cloud-native environments. You are skilled in identifying misconfigurations, mitigating risks, and driving remediation processes. Bonus points if you’ve implemented security in Kubernetes clusters or serverless architectures.

*

Automation and Secure Development Practices: You believe in “security as code” and are skilled at automating security processes. You can develop and integrate security tools into CI/CD pipelines to ensure secure code delivery. Tools like SAST, DAST, and dependency scanning are part of your daily toolkit, and you have experience integrating them into workflows to catch vulnerabilities early. You also advocate for secure coding practices and are skilled at mentoring teams to write resilient, secure applications.

*

Linux/System Security: You are well versed in AWS infrastructure security but also are passionate about scalability, reliability and operational rigor. Beyond that, you know that root does not mean root and are passionate about container security, POSIX Capabilities, SECCOMP and have a favorite flavor of LSM. In your spare time, you love playing around with OSQuery and eBPF.

*

Product Security (nice-to-have): Not a requirement, but a real plus: experience building secure web applications and APIs, with a working grasp of the OWASP Top 10 and common vulnerabilities such as XSS, CSRF, and SQL injection. It complements the infrastructure security focus of this role and helps when partnering with product teams.

### Responsibilities:

*

Partner with engineering teams to review cloud and compute architecture design changes

*

Establish threat models for cloud and compute paved roads to identify security risks

*

Develop or adopt open-source tools to monitor and harden our cloud Infrastructure, harden our OS, develop security logging pipelines and detect intrusions

*

Apply your expert knowledge of security best practices for AWS and Kubernetes to inform remediations and the team’s control roadmap

*

Drive the definition and implementation of security policies and monitor in conformance to the policies

*

Write code for automations that support security requirements like threat detection, incident containment, and network access management.

*

Conduct initial incident triage; determine scope, urgency, and potential impact of security incidents; participate in the incident response process

At Quora, we value diversity and inclusivity and welcome individuals from all backgrounds, including marginalized or underrepresented groups in tech, to apply for our job openings. We encourage all candidates who share a passion for growing the world’s knowledge, even those who may not strictly meet all the preferred requirements, to apply, as we know that a diverse range of perspectives can have a significant impact on our products and our culture.

### Additional Information:

Successful candidates must have availability for meetings and impromptu communication during Quora’s “[coordination hours](https://quora.com/coordination_hours)” (Mon-Fri: 9am-3pm Pacific Time).

We are accepting applications on an ongoing basis.

Quora offers a wide range of benefits including medical/dental/vision coverage, equity refreshers, remote work reimbursement, paid time off, employee assistance programs, and more. Benefits are country-specific and may vary.

There are many factors that will determine the starting compensation, including but not limited to experience, location, education, and business needs.

*

US candidates only: For US based applicants, the salary range is $172,279 – $249,640 USD + equity + benefits.

*

Canada candidates only: For Toronto and Vancouver based applicants, the salary range is $221,209 – $256,433 CAD + equity + benefits. For all other locations in Canada, the salary range is $206,461 – $239,337 CAD + equity + benefits.

*

In equity-eligible countries, we currently also offer a flexible equity program where a portion of equity compensation may be taken as cash.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

AI technology may assist in sorting applications and recording interview notes, but all decisions are made by a member of our team.

To ensure a secure hiring process, all final candidates will undergo identity verification and a comprehensive background check prior to onboarding.

Job Applicant Privacy Notice: [https://www.careers.quora.com/pages/quora-global-job-applicant-privacy-notice](https://www.careers.quora.com/pages/quora-global-job-applicant-privacy-notice)

#LI-JC1
#LI-REMOTE

Show more

[Apply now >](https://jobicy.com/jobs/154209-senior-software-engineer-infrastructure-security.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

*
![Quora logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200916172339-629302.jpg)
Quora Sep 29  New

### [Detection & CorpSec Engineer](https://jobicy.com/jobs/151966-detection-corpsec-engineer.md)

[Quora is a privately held, “remote-first” company. This position can be performed remotely from anywhere in Canada or the United States. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by…

*
![Fastly logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/10/127f9e4bbbdb8767bef358a23bf7f73d.jpeg)
Fastly Sep 28  New

### [Threat Detection Analyst (Japanese Speaking)](https://jobicy.com/jobs/154166-threat-detection-analyst-japanese-speaking.md)

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and…

*
![Maze logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/f53dfbf3-221.png)
Maze Sep 28  New

### [Senior Security Engineer (Remote, EU/CET)](https://jobicy.com/jobs/154158-senior-security-engineer-remote-eu-cet.md)

About Maze Maze is the user research platform that helps companies build the right products faster by making user insights available at the speed of product development. In most companies,…

*
![Solace logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/4e37a66b-221.png)
Solace Sep 28  New

### [Sr. Security Engineer (Detection)](https://jobicy.com/jobs/154125-sr-security-engineer-detection.md)

About Solace Healthcare in the U.S. is fundamentally broken. The system is so complex that 88% of U.S. adults do not have the health literacy necessary to navigate it without…

*
![GitLab logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/12/WRILS-201207055737-109952.jpg)
GitLab Sep 28  New

### [Senior Security Engineer, Security Incident Response Team (SIRT) – EMEA](https://jobicy.com/jobs/149309-senior-security-engineer-security-incident-response-team-sirt-emea.md)

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50…

*
![Vercel logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/a6aded72-221.png)
Vercel Sep 28  New

### [Security Software Engineer, IAM](https://jobicy.com/jobs/147750-security-software-engineer-iam.md)

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built….

*
![LastPass logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13842160-221.png)
LastPass Sep 27

### [Principal Cloud Security Engineer](https://jobicy.com/jobs/151831-principal-cloud-security-engineer.md)

About LastPassLastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and…

*
![Ada logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/666ef11e-221.png)
Ada Sep 27

### [Compliance and Security Lead](https://jobicy.com/jobs/151791-compliance-and-security-lead.md)

About Us Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service…

*
![Bloomreach logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/60790cd5-221.png)
Bloomreach Sep 26

### [Director, AI Enablement & Security](https://jobicy.com/jobs/151780-director-ai-enablement-security.md)

Bloomreach is building the world’s premier agentic platform for personalization.We’re revolutionizing how businesses connect with their customers, building and deploying AI agents to personalize the entire customer journey. We’re taking…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI Sep 26

### [Security Engineer, Infrastructure Security](https://jobicy.com/jobs/151778-security-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

[Browse all jobs](https://jobicy.com/jobs.md)