Senior Security Engineer II
Careem · Karachi, Pakistan · 2026-07-09
About this role
<div class="content-intro"><p><span style="font-family: helvetica, arial, sans-serif; font-size: 12pt;">Careem is building the Everything App for the greater Middle East — making it easy to move around, order food and groceries, manage payments, and more. Our purpose is simple: to simplify and improve people’s lives and build an awesome organisation that inspires.</span><br><span style="font-family: helvetica, arial, sans-serif; font-size: 12pt;">Since 2012, Careem has enabled earnings for over 2.5 million Captains, simplified the lives of more than 70 million customers, and built a platform where the region’s best talent and entrepreneurs thrive. We operate in 70+ cities across 10 countries, from Morocco to Pakistan.</span></p> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 12pt;"><strong data-stringify-type="bold"><em data-stringify-type="italic">We’re now entering our next chapter — one powered by AI. We’re looking for AI talent: curious problem-solvers who know how to apply AI to build tools, automate workflows, and create real impact. Whether it’s streamlining operations, enhancing customer experience, or reimagining internal systems — we want people who can make Careem work smarter and move faster.</em></strong></span></p></div><p></p> <div><strong>About the Role<br></strong><br>We are looking for a Senior Security Engineer II to join our Security Engineering team. This is a hands-on, high-ownership role for someone who thrives at the intersection of cloud security, infrastructure hardening, and agentic/AI security. You'll be expected to independently drive security initiatives across a large-scale, multi-vertical tech organization - not just advise, but build, ship, and operate.<br><br><strong>What You'll Do</strong></div> <div><br><span style="text-decoration: underline;"><strong>Cloud &amp; Infrastructure Security</strong></span></div> <ul> <li>Own and drive cloud security posture across AWS environments (EC2, EBS, IAM, GuardDuty, Bottlerocket, Beanstalk) including enforcement of encryption-by-default, golden AMI pipelines, and auto-remediation frameworks.</li> <li>Build and maintain hardened golden images; manage CVE patching pipelines and track fleet-wide vulnerability remediation health.</li> <li>Own KSPM (Kubernetes Security Posture Management) and CSPM controls; lead contingency planning and incident response for infrastructure-level vulnerabilities.</li> <li>Report on server hardening KPIs, vulnerability patching health, and compliant network security controls for executive/compliance audiences.</li> </ul> <div><span style="text-decoration: underline;"><strong>Edge &amp; Network Security (Cloudflare)</strong></span></div> <ul> <li>Manage SSL/TLS certificate health, TLS version enforcement, and bot traffic analysis across production domains.</li> <li>Analyze and respond to anomalies, bot vs human traffic breakdowns, DDoS patterns, firewall rule tuning.</li> <li>Investigate CDN misconfigurations and drive root-cause analysis and mitigation for HackerOne-reported issues.&nbsp;</li> </ul> <div><span style="text-decoration: underline;"><strong>DDoS Simulation &amp; Resilience Testing</strong></span></div> <ul> <li>Lead and operate DDoS simulation tooling (e.g., Kratos) across business verticals in collaboration with QA and SRE teams.</li> <li>Integrate simulation platforms into internal developer portals with built-in auth, audit workflows, and approval controls.</li> </ul> <div><span style="text-decoration: underline;"><strong>Agentic AI &amp; MCP Security</strong></span></div> <ul> <li>Conduct security reviews for agentic AI systems, MCP servers, and n8n automation workflows&nbsp; covering agent permissions, tool usage, OAuth/JWT auth, and SSRF/injection risks.</li> <li>Publish security guidelines for agentic AI deployments; build automated tooling to assess agent/workflow security at scale.</li> <li>Present security architecture proposals (e.g., AWS SSO for agentic identity) to Architecture Review Boards.</li> </ul> <div><span style="text-decoration: underline;"><strong>Security Reviews &amp; Threat Modelling</strong></span></div> <ul> <li>Conduct infrastructure threat modelling and security assessment reports across product verticals (Remittance, Pay, Food, Groceries, DineOut, AppEngine, etc.).</li> <li>Drive RFC, PRD, and code security reviews with strong security reasoning and written communication.</li> <li>Review secrets management approaches, enforce environment separation (dev vs prod controls).</li> </ul> <div><span style="text-decoration: underline;"><strong>Infrastructure as Code &amp; Automation</strong></span></div> <ul> <li>Contribute to IaC-based security baselining repositories; build auto-remediation proof-of-concepts that can scale across dozens of AWS accounts</li> <li>Use agentic AI tooling to automate infrastructure security operations&nbsp; accelerating gap identification and response.</li> </ul> <div><br><strong>What You'll Need:</strong></div> <ul> <li>8-10 years of hands-on security engineering experience in a cloud-native environment.</li> <li>Deep…
Skills asked for
- aws
- kubernetes
- sre
- terraform
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.