refresh

トレンド企業

Trending

採用

JobsKong

Staff Security Engineer - Penetration Tester

Kong

Staff Security Engineer - Penetration Tester

Kong

Milan

·

On-site

·

Full-time

·

1w ago

Required Skills

Penetration Testing

Offensive Security

Web Application Security

API Security

Cloud Security

Are you ready to power the World's connections?

If you don’t think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we’re looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.

ABOUT THE ROLE:

We’re hiring our first in-house Penetration Tester to help us proactively identify and mitigate security risks across Kong’s products, infrastructure, and internal systems. This is a high-impact role where you’ll help define how offensive security is done at Kong.

As Kong’s first dedicated Penetration Tester, you’ll work closely with our Security, Platform, and Engineering teams to continuously test, challenge, and improve the security of our products and services.

You’ll conduct hands-on offensive security assessments, partner with engineers to remediate findings, and help establish scalable, repeatable security testing practices across a modern, cloud-native, open-source environment.

This role blends deep technical testing, strong collaboration, and real influence on how security is embedded into our engineering culture.

WHAT YOU’LL BE DOING:

Perform penetration testing across:

  • Web applications, APIs, and microservices

  • Cloud infrastructure and Kubernetes environments

  • CI/CD pipelines and internal tooling

  • Identify, exploit, and clearly document security vulnerabilities and misconfigurations

  • Work closely with engineering teams to validate findings, prioritize risk and support remediation efforts.

  • Design and improve internal processes for continuous security testing, secure development practices and threat modeling and attack simulation

  • Support third-party security assessments, bug bounty programs, and compliance efforts

  • Help educate engineers on common attack vectors and defensive best practices

  • Contribute to building a strong, security-first culture across Kong.

WHAT YOU’LL BRING:

  • Proven experience in penetration testing, offensive security, or red teaming

  • Web application and API security (OWASP Top 10)

  • Authentication, authorization, and identity systems

  • Cloud security concepts and shared responsibility models

  • Hands-on experience testing modern, cloud-native systems

  • Ability to clearly communicate security findings to technical and non-technical audiences

  • A pragmatic mindset: focused on real risk reduction, not just theoretical issues

  • Curiosity, ownership, and comfort working in a fast-moving, engineering-driven environment

BONUS POINTS:

  • Experience testing API gateways, service meshes, or distributed systems

  • Familiarity with Kubernetes and container security

  • Experience with open-source security tools or contributing to open-source projects

  • Bug bounty participation or published research

  • Experience working in a SaaS or enterprise software company

About Kong:

Kong Inc., a leading developer of API and AI connectivity technologies, is building the infrastructure that powers the agentic era. trusted by the Fortune 500 and startups alike, Kong's unified API and AI platform, Kong Konnect, enables organizations to secure, manage, accelerate, govern, and monetize the flow of intelligence across APIs and AI models. For more information, visit www.konghq.com http://www.konghq.com.

Total Views

0

Apply Clicks

0

Mock Applicants

0

Scraps

0

About Kong

Kong

Kong

Bootstrapped

The Kong Company is an American company headquartered in the state of Colorado that develops, designs, and produces lines of dog toys and cat toys. Its primary line of product is a snowman-like chew toy for dogs also named KONG.

the state

Headquarters

Reviews

3.8

48 reviews

Work Life Balance

3.4

Compensation

4.2

Culture

3.9

Career

3.9

Management

3.6

78%

Recommend to a Friend

Pros

Good work-life balance and flexible environment

Competitive compensation and benefits

Opportunity for career growth

Cons

Career progression could be clearer

Some organizational bureaucracy

Room for improvement in processes

Salary Ranges

1 data points

Junior

Junior · Software Engineer

1 reports

$62,000

total / year

Base

$62,000

Stock

-

Bonus

-

$62,000

$62,000

Interview Experience

3 interviews

Difficulty

4.0

/ 5

Duration

14-28 weeks

Experience

Positive 0%

Neutral 0%

Negative 100%

Interview Process

1

Application Review

2

HR/Recruiter Screen

3

Technical Assessment

4

Technical Interview

5

Take-home Project

6

Final Interview

Common Questions

Coding/Algorithm

Technical Knowledge

Behavioral/STAR

System Design