Skip to main content

Careers at KKR

Product Security Engineer

BostonFrom $175kfull-timemidAdded today

About this role

KKR seeks an experienced Product Security Engineer to design and implement security measures across internally and externally facing applications in Boston. You will conduct vulnerability assessments, guide development teams on secure coding practices, and maintain security standards while working 4 days on-site and 1 day remote.

What you'll do

  • Conduct application security assessments and penetration testing to identify vulnerabilities
  • Collaborate with software development teams to embed secure coding practices throughout the SDLC
  • Design and implement security solutions to protect applications from threats
  • Integrate security tools into CI/CD pipelines and develop security standards and policies
  • Lead incident response activities for application security incidents
  • Provide security training and awareness sessions to development teams

What they're looking for

  • Application security assessment and penetration testing
  • Secure coding practices and SDLC knowledge
  • Cloud security and DevSecOps
  • Security tools (firewalls, VPNs, IDS/IPS, NAC)
  • OWASP Top Ten and security frameworks
  • CI/CD pipeline security integration
  • Incident response and threat analysis
  • Regulatory compliance and industry best practices
Apply on the employer's site

Opens the official application on the employer’s site. No login required.

Careers at KKR

KKR builds and maintains technology infrastructure that powers its investment operations, including investment systems, data platforms, and security solutions. The company is hiring experienced engineers—including software engineers, security engineers, and data platform specialists—to drive technical initiatives, manage complex systems, and mentor teams across its technology organizations.

Website
kkr.com
View all jobs at Careers at KKR

Likely interview questions

  • Walk us through your experience conducting penetration tests and how you've prioritized remediation findings for development teams.
  • Describe your approach to integrating security into a CI/CD pipeline and which tools have you used most effectively.