Clera - Your AI talent agent
LoginStart
Start
Kong logo
Kong

Staff Security Engineer - Penetration Tester

full-time•Milan

Summary

Location

Milan

Type

full-time

Experience

5-10 years

Company links

WebsiteLinkedInLinkedIn

About this role

Are you ready to power the World's connections?

If you don’t think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we’re looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.

About the Role

We’re hiring our first in-house Penetration Tester to help us proactively identify and mitigate security risks across Kong’s products, infrastructure, and internal systems. This is a high-impact role where you’ll help define how offensive security is done at Kong.

As Kong’s first dedicated Penetration Tester, you’ll work closely with our Security, Platform, and Engineering teams to continuously test, challenge, and improve the security of our products and services.

You’ll conduct hands-on offensive security assessments, partner with engineers to remediate findings, and help establish scalable, repeatable security testing practices across a modern, cloud-native, open-source environment.

This role blends deep technical testing, strong collaboration, and real influence on how security is embedded into our engineering culture.

What You’ll Be Doing

  • Perform penetration testing across:

  • Web applications, APIs, and microservices

  • Cloud infrastructure and Kubernetes environments

  • CI/CD pipelines and internal tooling

  • Identify, exploit, and clearly document security vulnerabilities and misconfigurations

  • Work closely with engineering teams to validate findings, prioritize risk and support remediation efforts.

  • Design and improve internal processes for continuous security testing, secure development practices and threat modeling and attack simulation

  • Support third-party security assessments, bug bounty programs, and compliance efforts

  • Help educate engineers on common attack vectors and defensive best practices

  • Contribute to building a strong, security-first culture across Kong.

What You’ll Bring

  • Proven experience in penetration testing, offensive security, or red teaming

  • Strong understanding of:

  • Web application and API security (OWASP Top 10)

  • Authentication, authorization, and identity systems

  • Cloud security concepts and shared responsibility models

  • Hands-on experience testing modern, cloud-native systems

  • Ability to clearly communicate security findings to technical and non-technical audiences

  • A pragmatic mindset: focused on real risk reduction, not just theoretical issues

  • Curiosity, ownership, and comfort working in a fast-moving, engineering-driven environment

Bonus Points

  • Experience testing API gateways, service meshes, or distributed systems

  • Familiarity with Kubernetes and container security

  • Experience with open-source security tools or contributing to open-source projects

  • Bug bounty participation or published research

  • Experience working in a SaaS or enterprise software company

About Kong:

Kong Inc., a leading developer of cloud API technologies, is on a mission to enable companies around the world to become “API-first” and securely accelerate AI adoption. Kong helps organizations globally — from startups to Fortune 500 enterprises — unleash developer productivity, build securely, and accelerate time to market. For more information about Kong, please visit www.konghq.com or follow us on X @thekonginc.

What you'll do

  • The Staff Security Engineer - Penetration Tester will conduct hands-on offensive security assessments and work closely with engineering teams to validate findings and support remediation efforts. This role also involves designing and improving internal processes for continuous security testing and contributing to a strong security-first culture.

About Kong

Powering the API World. No AI without APIs. Kong enables any company to become an API-first company. Kong’s unified cloud native API platform is easy to use and works in any environment — unleashing developer productivity, automating security, and boosting performance of APIs and microservices at scale.

Ready to join Kong?

Take the next step in your career journey

Frequently Asked Questions

What does a Staff Security Engineer - Penetration Tester do at Kong?

Toggle
As a Staff Security Engineer - Penetration Tester at Kong, you will: the Staff Security Engineer - Penetration Tester will conduct hands-on offensive security assessments and work closely with engineering teams to validate findings and support remediation efforts. This role also involves designing and improving internal processes for continuous security testing and contributing to a strong security-first culture..

Is the Staff Security Engineer - Penetration Tester position at Kong remote?

Toggle
The Staff Security Engineer - Penetration Tester position at Kong is based in Milan, Lombardy, Italy. Contact the company through Clera for specific work arrangement details.

How do I apply for the Staff Security Engineer - Penetration Tester position at Kong?

Toggle
You can apply for the Staff Security Engineer - Penetration Tester position at Kongdirectly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process.
Clera - Your AI talent agent
© 2026 Clera Labs, Inc.TermsPrivacyHelp

Join Clera's Talent Pool

Get matched with similar opportunities at top startups

This role is hosted on Kong's careers site.
Join our talent pool first to get notified about similar roles that match your profile.