2 hours ago
Responsibilities
- Lead threat modeling and security reviews for products and cloud infrastructure, identifying attack surfaces and scalable mitigations.
- Build automation, policy-as-code, and security tooling that integrates security into development workflows.
- Design and implement secure baselines for cloud resources and Kubernetes infrastructure.
- Drive vulnerability management, remediation, and preventative controls across software supply chains from development through production.
- Extend detection and response capabilities for malicious-activity identification, alert triage, incident investigation, and remediation.
- Partner with engineering and operations teams to deliver secure-by-design solutions.
Requirements
- At least 7 years of experience in security engineering or security operations in cloud environments.
- Experience with AWS cloud security, or equivalent Azure and GCP experience with some AWS experience.
- Experience with cloud-native Kubernetes services including EKS, GKE, or AKS, plus container security principles.
- Experience securing IAM and cloud identities at scale.
- Experience leading technical security reviews, conducting threat modeling, and translating findings into actionable controls.
- Practical understanding of web application security concepts such as OWASP Top 10.
- Hands-on experience with infrastructure-as-code tools including Terraform, CloudFormation, Helm, or Pulumi.
- Experience developing automation and tooling with one or more of Python, Go, Shell, HCL, or Rego.
- Bachelor’s degree in computer science or a related field is preferred, with equivalent job experience accepted in lieu of a degree.
- Experience with remote, globally distributed teams; software development or managed infrastructure organizations; and CNAPP, CSPM, or CIEM solutions is preferred.
- Applicants must have legal authorization to work in the position’s country without visa sponsorship.
