Senior Security Engineer
Software Engineering
Matn, Lebanon
About Toters
Toters is a leading on-demand e-commerce and delivery platform across the Middle East, empowering customers to order anything in their city with unmatched speed and convenience. Technology is at the core of everything we do. If you thrive in a fast-growing startup environment and want to shape how millions of customers shop and receive goods in the region while raising the bar on security, we’d love to hear from you.
Role Overview
As a
Senior Security Engineer you will own security problem spaces that span your team and adjacent teams. You will ensure the security, confidentiality, and integrity of our network and cloud infrastructure at scale, while driving meaningful security improvements across multiple services and engineering groups. You will operate self-directedly, make sound risk-based decisions in ambiguous situations, influence secure architecture and design decisions, and collaborate closely with DevOps, Engineering, and cross-functional teams to embed security throughout the development lifecycle in a fast-moving environment.
Key Responsibilities
- Own and lead the design and implementation of security controls across network and cloud infrastructure, spanning multiple teams and services.
- Drive cross-team threat modeling, vulnerability assessments, and penetration testing; identify systemic risks and prioritize remediation.
- Define and maintain multi-team security standards, policies, and procedures that are adopted consistently across adjacent teams.
- Partner with DevOps and Engineering to integrate security best practices into the SDLC and guide secure design decisions across team boundaries.
- Lead complex incident response efforts: perform cross-team root-cause analysis, coordinate remediation, and drive resilience improvements.
- Design and enhance monitoring, log analysis, and threat detection capabilities (Datadog, New Relic, Grafana, SIEM, etc.) to reduce noise and improve response readiness.
- Identify and eliminate cross-team security inefficiencies through reusable patterns, automation, and simplified workflows.
- Mentor engineers across teams, raise the overall security culture, and share knowledge through documentation, sessions, and coaching.
- Stay ahead of evolving network and cloud security threats and proactively assess their impact on our infrastructure.
- Design and operate AI-assisted security automation for alert triage, vulnerability prioritization, security testing, evidence collection, and remediation tracking, while maintaining human review and validation for security decisions.
- Establish secure-use guardrails for AI tools and workflows to protect source code, credentials, customer data, payment information, and other sensitive company assets.
- Secure fintech and payment-related products by assessing payment flows, payment APIs, sensitive financial data, tokenization, fraud-abuse risks, and third-party payment integrations.
Required Qualifications
- 5+ years of hands-on experience in infrastructure and application security, with strong focus on cloud environments (AWS preferred).
- Proven experience owning security initiatives that span multiple teams (threat modeling, vulnerability management, incident response, secure SDLC).
- Deep expertise in cloud security services, cloud networking (firewalls, load balancers, WAF), and DDoS mitigation (Cloudflare or equivalent).
- Strong working knowledge of security tools and platforms: SIEM, vulnerability scanners, IDS/IPS, Datadog, Grafana, etc.
- Proven ability to translate regulatory, compliance, and risk requirements into scalable, technically verifiable cloud, application, identity, and operational security controls (SOC2, PCI DSS, ISO 27001, NIST, CIS).
- Demonstrated ability to operate independently, make risk-based trade-offs, influence without authority, and drive alignment across teams.
- Excellent communication and collaboration skills; able to explain complex security topics clearly to both technical and non-technical stakeholders.
- Working knowledge of OWASP Top 10, OWASP API Security Top 10, and OWASP MASVS/MASTG or equivalent mobile application security standards.
- Experience securing payment and fintech applications, including payment APIs, sensitive financial data, and third-party payment integrations.
Nice-to-Haves
- Hands-on penetration testing experience.
- Relevant certifications (CISSP, CISM, AWS Certified Security – Specialty or equivalent).
- Experience shifting security left and integrating security into CI/CD pipelines.
- Background in food delivery, e-commerce, or high-traffic consumer applications.
- Fluency in English and Arabic (French is a plus).
- Strong technical documentation and knowledge-sharing skills.
What We Offer
- Competitive compensation package.
- Discounts on Toters orders.
- First-class medical insurance.