Staff Cyber Security Engineer

3 ore fa


Milano, Lombardia, Italia Kong A tempo pieno

Are you ready to power the World's connections?

If you don't think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we're looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.

As a Staff Security Engineer, you will serve as the technical security lead for securing the world's most popular API gateway. You will apply deep expertise in high-performance networking and distributed systems to shape the security posture of the Kong Cloud. You'll spend your time architecting the evolution of our security capabilities—specifically focused on leveraging Open Source (OSS) and building state of the art network and application security solutions..

What you'll do:

  • Domain Expertise: Act as the lead subject matter expert for the Kong Cloud Security Operations.

  • Threat Defense Leadership: Architect and implement next-generation WAF, IDS, and IPS capabilities at the gateway level to protect against OWASP Top 10, zero-day exploits, and sophisticated API abuse.

  • Multi-Cloud Security: Design and implement "Zero Trust" security models that operate seamlessly across hybrid and multi-cloud environments (AWS, Azure, GCP, On-prem).

  • Strategic Roadmap: Partner with Product and Architecture leads to define the multi-year security roadmap for Kong Gateway, balancing the needs of the OSS community with Enterprise requirements.

  • Incident Resolution: Lead the response to complex, multi-faceted security challenges—from supply chain vulnerabilities in open-source dependencies to high-stakes CVE remediations.

  • Mentorship & Influence: Champion a "Security-First" culture by mentoring engineers on secure coding practices and influencing the long-term cybersecurity maturity of the entire organization.

What you'll bring:

  • 8+ years' experience in Cybersecurity Engineering, with a focus on high-traffic infrastructure or API management.

  • Extensive experience with Kong Gateway, Nginx, eBPF, or similar technologies.

  • Cloud-Native & Multi-Cloud: Expert-level knowledge of multi-cloud solution design, specifically securing traffic across disparate cloud providers and Kubernetes environments.

  • Security Domain Specialist: Proven track record in designing/deploying WAF, IDS, and IPS systems at scale, with an understanding of signature-based vs. ML-based detection.

  • Programming Proficiency:Python, Go or Rust

  • Open Source Contributor: Experience contributing to or maintaining open-source security projects is a significant asset.

  • Design Excellence: Ability to produce high-quality, high-performance security designs that do not compromise the "millisecond-latency" promise of the gateway.

About Kong:

Kong Inc., a leading developer of API and AI connectivity technologies, is building the infrastructure that powers the agentic era. trusted by the Fortune 500 and startups alike, Kong's unified API and AI platform, Kong Konnect, enables organizations to secure, manage, accelerate, govern, and monetize the flow of intelligence across APIs and AI models. For more information, visit



  • Milano, Lombardia, Italia RAD Cyber Security A tempo pieno

    Junior Cyber Security Consultant Milano / Ibrido | Full-time | Entry-level (0–3 anni)Vuoi entrare nel mondo della Cyber Security e lavorare su progetti che fanno davvero la differenza?In RAD ti aspetta un ambiente stimolante, dove potrai sviluppare le tue competenze tecniche e personali, lavorando fianco a fianco con professionisti esperti e...


  • Milano, Lombardia, Italia WIIT A tempo pieno

    ABOUT THE JOBIn WIIT, società italiana di respiro internazionale quotata al segmento Star, abbiamo scelto di fare la differenza per i nostri clienti. Siamo leader nell'erogazione di servizi di Hosted Private e Hybrid Cloud per aziende con necessità di servizi di gestione di processi critici.Ricerchiamo valore in ogni cosa che facciamo mettendo al...


  • Milano, Lombardia, Italia WIIT S.p.A. A tempo pieno

    SENIOR CYBER SECURITY ENGINEER (L2/L3)ABOUT THE JOBIn WIIT, società italiana di respiro internazionale quotata al segmento Star, abbiamo scelto di fare la differenza per i nostri clienti. Siamo leader nell'erogazione di servizi di Hosted Private e Hybrid Cloud per aziende con necessità di servizi di gestione di processi critici.Ricerchiamo valore in ogni...


  • Milano, Lombardia, Italia Kong A tempo pieno

    Are you ready to power the World's connections?If you don't think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we're looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.As a Staff Security Engineer, you will serve as the...


  • Milano, Lombardia, Italia WIIT - The Premium Cloud A tempo pieno

    About The JobIn WIIT, società italiana di respiro internazionale quotata al segmento Star, abbiamo scelto di fare la differenza per i nostri clienti. Siamo leader nell'erogazione di servizi di Hosted Private e Hybrid Cloud per aziende con necessità di servizi di gestione di processi critici.Ricerchiamo valore in ogni cosa che facciamo mettendo al centro le...


  • Milano, Lombardia, Italia 7Layers A tempo pieno

    In qualità di azienda di riferimento del gruppo Fastweb in ambito Cyber Security, siamo alla ricerca di unCyber Security Analyst con comprovata esperienza sulla tecnologia IBM QRadar, che possa supportare il team diCyber Securityin attività di consulenza operativa e di alto livello tecnico, su importanti clienti enterprise e PA.La risorsa sarà coinvolta...


  • Milano, Lombardia, Italia Fineco Bank A tempo pieno

    Company DescriptionFineco Bank is a leading European bank with a 20 years history and a fully digital DNA with a branchless approach since the start. Fineco is one of the banks with the widest products range available. We have developed a truly one-stop-solution which includes trading, investment and payment services. We have developed a 100% proprietary...


  • Milano, Lombardia, Italia Luna Labs A tempo pieno

    Stiamo ricercando dei profili esperti Cloud Security Engineer. Le attività prevedono:Valutazione del rischio di sistemi/architetture software.Valutazione della conformità di un sistema software alle principali best practices relative alla Cyber Security, in particolare in ambito Cloud Computing.Utilizzo degli strumenti per la gestione di Identity and...


  • Milano, Lombardia, Italia Insight A tempo pieno

    Insight Enterprises, Inc. is a Solutions Integrator and one of the Global Fortune 500 companies that helps organizations accelerate their transformation by leveraging human and technological capital. We design, build, and manage solutions for complex IT environments to deliver results that contribute to our clients' success.Our digital transformation...


  • Milano, Lombardia, Italia Cool Technology SRLS A tempo pieno

    Siamo alla ricerca di un/unaJunior Cyber Security Specialistda inserire a supporto delle attività operative di sicurezza informatica.La risorsa lavorerà a stretto contatto con ilSOCe con il team infrastrutturale, contribuendo al monitoraggio e alla gestione degli aspetti di security dell'ambiente IT.Il ruolo è pensato per una personajunior, proattiva e...