Jobedly Post a Job

Senior Security Engineer II

Careem · Karachi
Full-timeInformation SecurityTechnology$179,000–$241,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Senior Security Engineer II role

Senior Security Engineer II positions focus on delivering results in their domain. This page aggregates open Senior Security Engineer II roles and what employers typically expect.

Careem is building the Everything App for the greater Middle East — making it easy to move around, order food and groceries, manage payments, and more. Our purpose is simple: to simplify and improve people’s lives and build an awesome organisation that inspires. Since 2012, Careem has enabled earnings for over 2.5 million Captains, simplified the lives of more than 70 million customers, and built a platform where the region’s best talent and entrepreneurs thrive. We operate in 70+ cities across 10 countries, from Morocco to Pakistan. We’re now entering our next chapter — one powered by AI. We’re looking for AI talent: curious problem-solvers who know how to apply AI to build tools, automate workflows, and create real impact. Whether it’s streamlining operations, enhancing customer experience, or reimagining internal systems — we want people who can make Careem work smarter and move faster. About the Role We are looking for a Senior Security Engineer II to join our Security Engineering team. This is a hands-on, high-ownership role for someone who thrives at the intersection of cloud security, infrastructure hardening, and agentic/AI security. You'll be expected to independently drive security initiatives across a large-scale, multi-vertical tech organization - not just advise, but build, ship, and operate. What You'll Do Cloud & Infrastructure Security Own and drive cloud security posture across AWS environments (EC2, EBS, IAM, GuardDuty, Bottlerocket, Beanstalk) including enforcement of encryption-by-default, golden AMI pipelines, and auto-remediation frameworks. Build and maintain hardened golden images; manage CVE patching pipelines and track fleet-wide vulnerability remediation health. Own KSPM (Kubernetes Security Posture Management) and CSPM controls; lead contingency planning and incident response for infrastructure-level vulnerabilities. Report on server hardening KPIs, vulnerability patching health, and compliant network security controls for executive/compliance audiences. Edge & Network Security (Cloudflare) Manage SSL/TLS certificate health, TLS version enforcement, and bot traffic analysis across production domains. Analyze and respond to anomalies, bot vs human traffic breakdowns, DDoS patterns, firewall rule tuning. Investigate CDN misconfigurations and drive root-cause analysis and mitigation for HackerOne-reported issues. DDoS Simulation & Resilience Testing Lead and operate DDoS simulation tooling (e.g., Kratos) across business verticals in collaboration with QA and SRE teams. Integrate simulation platforms into internal developer portals with built-in auth, audit workflows, and approval controls. Agentic AI & MCP Security Conduct security reviews for agentic AI systems, MCP servers, and n8n automation workflows covering agent permissions, tool usage, OAuth/JWT auth, and SSRF/injection risks. Publish security guidelines for agentic AI deployments; build automated tooling to assess agent/workflow security at scale. Present security architecture proposals (e.g., AWS SSO for agentic identity) to Architecture Review Boards. Security Reviews & Threat Modelling Conduct infrastructure threat modelling and security assessment reports across product verticals (Remittance, Pay, Food, Groceries, DineOut, AppEngine, etc.). Drive RFC, PRD, and code security reviews with strong security reasoning and written communication. Review secrets management approaches, enforce environment separation (dev vs prod controls). Infrastructure as Code & Automation Contribute to IaC-based security baselining repositories; build auto-remediation proof-of-concepts that can scale across dozens of AWS accounts Use agentic AI tooling to automate infrastructure security operations accelerating gap identification and response. What You'll Need: 8-10 years of hands-on security engineering experience in a cloud-native environment. Deep expertise in AWS security (IAM, GuardDuty, EBS encryption, EC2/Beanstalk hardening, Bottlerocket, Secrets Manager…

Salary estimate

$179,000 – $241,000/yr
Provided by the employer.

Skills for this role

AWSKubernetesCommunicationSecurityQAAutomation

Resume tips for Senior Security Engineer II applicants

Interview preparation

Prepare concrete STAR-format stories that show Senior Security Engineer II outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Senior Security Engineer II problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Careem

Careem is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles