About the job
Join Us in Empowering Global Connections!
If you feel that you may not fulfill all the required criteria but are enthusiastic about this opportunity, we encourage you to apply. Perfection is not a prerequisite; we value candidates who excel in certain areas while possessing a keen interest and capability in others.
About the Position:
We are on the lookout for our inaugural in-house Penetration Tester to actively identify and mitigate security risks across Kong’s diverse products, infrastructure, and internal systems. This pivotal role will define how we approach offensive security practices at Kong.
As the first dedicated Penetration Tester at Kong, you will collaborate closely with our Security, Platform, and Engineering teams to rigorously test, challenge, and enhance the security of our products and services.
You will conduct hands-on offensive security assessments, partner with engineers to address findings, and contribute to establishing scalable and repeatable security testing methodologies within a modern, cloud-native, open-source ecosystem.
This role combines deep technical testing with strong collaboration, allowing you to have a significant influence on how security is integrated into our engineering culture.
Key Responsibilities:
You will be responsible for performing penetration testing across:
Web applications, APIs, and microservices
Cloud infrastructure and Kubernetes environments
CI/CD pipelines and internal tooling
Identify, exploit, and thoroughly document security vulnerabilities and misconfigurations
Collaborate with engineering teams to validate findings, prioritize risks, and support remediation activities.
Design and enhance internal processes for continuous security testing, secure development practices, threat modeling, and attack simulation
Assist in third-party security assessments, bug bounty programs, and compliance initiatives
Educate engineers on common attack vectors and best defense practices
Contribute to fostering a robust, security-first culture at Kong.
What You Bring to the Team:
Proven experience in penetration testing...

