Back to job search
Ennote Security logo
Ennote SecurityVerified Job Source

Security Engineer

  • Canada
  • Remote
  • Posted Jul 21, 2026
  • 1 position

Opens an external site

Sign in to save this job
Employment type
Contract
Experience level
Senior · 5+ years
Posting language
English
Working hours
40 hours per week
Location requirements
Country, Estonia
Application method
Direct apply is available

Job summary

The Security Engineer will lead offensive security efforts by performing adversarial testing on the CLI, encryption flows, and Kubernetes agents. They are responsible for identifying vulnerabilities, documenting findings, and collaborating with engineering to implement remediations and support compliance readiness.

Job details

About Ennote Ennote Security is the identity-driven secret manager unifying human collaboration and machine automation. Our platform centralizes governance for passwords, environment variables, API keys, and infrastructure certificates - replacing scattered .env files and legacy vaults with a single, hardware-backed source of truth. Ennote is live in production and used by engineering teams to manage secrets across their Kubernetes infrastructure, with real-time sync, native SSO/RBAC, and immutable audit logging. Our architecture is built on a strict zero-persistence principle: plaintext secrets are never written to disk. Every credential is encrypted client-side, encapsulated using post-quantum cryptography, and decapsulated only transiently in volatile memory inside a hardware-backed enclave before being re-wrapped for the requesting identity. We're building toward SOC 2 Type II and ISO 27001 certification, and we're growing our customer base among engineering teams who depend on us to protect their most sensitive infrastructure credentials. The Role We're hiring a Security Engineer to own offensive security at Ennote - someone who will treat our platform the way a real attacker would, and who takes ownership of finding what we've missed before someone else does. This isn't a theoretical audit of a whiteboard architecture. You'll be testing a system that active customers rely on today: our CLI and client-side encryption flow, our real-time gRPC synchronization layer, our Kubernetes-native agents, and our BYOK integrations with customer-managed KMS. Because all cryptographic operations happen client-side by design - we deliberately avoid exposing a server-side API as an attack surface - your testing will focus heavily on the client, the sync protocol, and the enclave boundary rather than a traditional API perimeter. You'll be working directly against production-grade code and logic; high-impact or potentially disruptive exploitation attempts will run in a dedicated staging cluster that mirrors production, so we can protect customer SLAs while you push as hard as you need to. Your job is to break our security assumptions, document exactly how, and work directly with engineering to close the gap. Responsibilities Adversarial testing: Design and execute structured, documented penetration tests against the Ennote CLI, our client-side encryption flow, our gRPC sync streams, and our Kubernetes Smart Agents. Identity and access testing: Attempt to defeat our ephemeral identity and bootstrap token model; probe for privilege escalation paths across SSO, RBAC, and workspace isolation boundaries. Memory and enclave auditing: Verify that our transient key re-wrapping process holds up under adversarial conditions - confirming no plaintext or key material persists outside volatile memory. Cloud KMS / BYOK review: Audit our AWS/GCP KMS integrations and customer-owned key flows for misconfiguration or exploitable trust boundaries. Audit log validation: Confirm our immutable audit logs hold up under attack - if you bypass an RBAC boundary, the logs need to capture exactly how and under which identity. This evidence is required for our SOC 2 Type II and ISO 27001 work. Reporting and remediation: Deliver clear, prioritized findings to engineering leadership, and work collaboratively through remediation and re-testing. Compliance readiness: Support our SOC 2 Type II and ISO 27001 preparation with evidence from real testing, not just checklist review. What We're Looking For You've pentested real production systems before - SaaS platforms, cloud infrastructure, cryptographic systems - not just labs, CTFs, or certs. You know Kubernetes security well, and you're comfortable around hardware-backed enclaves (Intel TDX or similar) and HSM/KMS key management. You've worked with multi-tenant systems and ideally streaming protocols like gRPC. You default to assuming something's broken until you've proven otherwise. You'll tell us what's wrong directly, even if it's not what we want to hear. Compensation We have paying customers and a live product, and we're currently closing institutional funding to grow the team properly. Until that round closes, this role is equity-only - no salary. We're offering a meaningful stake because this function matters to us and we want the right person to have real skin in the game. Once we close funding or hit sustainable revenue, our plan is to move this into a paid position. If getting in early and owning security at a company that's already proving itself in the market sounds interesting to you, let's talk.

What you’ll do

The Security Engineer will lead offensive security efforts by performing adversarial testing on the CLI, encryption flows, and Kubernetes agents. They are responsible for identifying vulnerabilities, documenting findings, and collaborating with engineering to implement remediations and support compliance readiness.

Requirements

Candidates must have professional experience pentesting production SaaS or cloud infrastructure rather than just lab environments. Proficiency in Kubernetes security, hardware-backed enclaves, and managing KMS/HSM integrations is required.

Benefits

  • Equity

Listed skills

  • Flows · Preferred
  • Kubernetes · Preferred
  • Production · Preferred
  • Collaboration · Preferred
  • Teams · Preferred
  • Client · Preferred
  • Compliance · Preferred
  • Integrations · Preferred
  • Amazon Web Services · Preferred
  • Time · Preferred
  • Audit · Preferred
  • Customer · Preferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Penetration Testing
  • Offensive Security
  • Kubernetes Security
  • gRPC
  • Cloud KMS
  • AWS
  • GCP
  • Hardware-backed Enclaves
  • Intel TDX
  • HSM
  • RBAC
  • SSO
  • Cryptographic Systems
  • Identity and Access Management
  • SOC 2 Type II
  • ISO 27001

Job areas

  • Security & Safety
  • Technology
  • Engineering
  • Software

More jobs from Ennote Security

See all jobs from Ennote Security