Senior Security Engineer at Orkes
In Office - Santa Clara, CA
$180,000–$240,000from the description
Aug 2, 2026
In Office - Santa Clara, CA
Sep 24, 2026
What this job asks for AI summary
A hands-on Senior Security Engineer role at an AI workflow orchestration startup, responsible for owning the end-to-end security roadmap across a multi-cloud control plane and customer-hosted deployments. The position involves writing production code to ship security fixes and platform guardrails, designing RBAC/authorization systems, conducting threat modeling, and embedding security tooling into the CI/CD pipeline. It suits an experienced security engineer who is equally comfortable architecting programs and coding fixes.
Senior level · 7+ years · San Jose-Sunnyvale-Santa Clara, CA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 20 people in the San Jose-Sunnyvale-Santa Clara, CA area plausibly meet what this posting asks for (information security analysts). range 9–35
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $179,993 (middle half $128,832–$221,179). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 4, 2026. It is a model, not a headcount.
Why we read it this way (6)
This role sits at the boundary between security analysis (15-1212) and software development (15-1252): the posting explicitly requires shipping production code (Java/Python/TypeScript) alongside owning the security roadmap, making it a genuine hybrid. 15-1212 was chosen as primary because security architecture, threat modeling, penetration testing response, and CVE triage are framed as the core mission; the coding requirement is in service of that mission rather than the other way around.
The three production languages (Java, Python, TypeScript) are listed together as a single 'ships fixes in production code' requirement. They are emitted as separate skills with each other as alternatives, reflecting that the posting treats them as a combined capability rather than three independent gates.
Multi-cloud coverage (AWS/Azure/GCP) is similarly listed as a single requirement; each cloud is emitted as a required skill with the others as alternatives, consistent with the 'or similar' substitution-qualifier rule.
Red-team experience appears under Nice-to-haves in the posting but was not emitted as a standalone skill because it is framed as a general experience area rather than a named technology or tool.
Equity is mentioned as part of total compensation but no figures are provided; only the stated base salary range is captured.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Detection engineering.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.