Security Engineer
Quick Summary
Provide security guidance to Engineering and Product teams. Build threat models and conduct risk assessments for new features and services. Perform design and code reviews (lots of them!). Identify,
Workstream is a mission-driven company building the all-in-one HR, payroll, and hiring platform for managing the hourly workforce. There are 2.7 billion hourly workers, making up 80% of the global workforce, but this market has been heavily underserved by technology and deserves better. Workstream has been purpose-built for the hourly workforce from day one so that these businesses and their employees can thrive.
Our customers include leading brands from multiple sectors, including Burger King, Carl's Jr./Hardee's, IHOP, KFC, and Culvers. We are a high growth series B company and quickly expanding our product portfolio to deliver on our vision. We are backed by legendary VCs and industry experts like Founders Fund, BOND, and Coatue.
- Provide security guidance to Engineering and Product teams.
- Build threat models and conduct risk assessments for new features and services.
- Perform design and code reviews (lots of them!).
- Identify, triage, resolve, and manage security vulnerabilities identified in Workstream products.
- Build libraries and tools to make software built and deployed at Workstream secure by default.
- Make security an integral part of our CI/CD pipeline.
- Perform internal penetration tests and participate in blue team exercises.
- 4+ years of security experience.
- 4+ years of software development experience.
- Strong understanding of Web application security, including hands-on exploitation skills coupled with defensive skills.
- Familiarity with secure development practices and security testing techniques (SAST, DAST, fuzzing, etc.).
- Familiarity with infrastructure and systems security domains.
- Familiarity with web application security defense techniques and technologies (WAF, RASP, sanitization/validation, etc.
- Familiarity with microservices architectures, platforms, and 12-factor design
- Familiarity with relevant technologies (listed below)
- Strong understanding of Ruby on Rails or NodeJS. Knowledge of mobile development, such as Flutter and React Native will be nice to have.
- Modest ability to build tools and automation in Python or other languages.
- Ability to explain complex security issues and their impact to diverse audiences.
- Be a fast learner and have experience partnering with cross-functional teams.
- BA/BS in Computer Science or similar technical degree or equivalent experience.
Must have:
- Web:
Frameworks: Ruby on Rails, NodeJS, ReactJS.
Web protocol standards (REST, RPC, SOAP) - Infrastructure:
Container and container infrastructure (e.g. Docker, container, k8s)
Cloud technology (e.g. AWS, Azure) Unix/Linux - Nice to have:
Flutter, React Native.
Modest competency in common scripting and automation languages (Python, Ruby, Golang, etc.)
What We Offer
~1 min readListing Details
- Posted
- March 17, 2026
- First seen
- March 26, 2026
- Last seen
- April 20, 2026
Posting Health
- Days active
- 25
- Repost count
- 0
- Trust Level
- 31%
- Scored at
- April 20, 2026
Signal breakdown

Workstream is the top HR and Payroll platform designed for the hourly workforce, streamlining hiring and administrative processes for businesses.
View company profilePlease let Workstream know you found this job on Jobera.
4 other jobs at Workstream
View all →Explore open roles at Workstream.
Similar Security Engineer jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.