2 hours ago
Responsibilities
- Lead threat modeling and security reviews for products and cloud infrastructure, identifying attack surfaces and scalable mitigations.
- Build automation, policy-as-code, and security tooling that integrates security into development workflows.
- Design and implement secure baselines for cloud resources and Kubernetes-based infrastructure.
- Drive vulnerability management, remediation, and preventative controls across the software supply chain.
- Extend detection and response capabilities to identify malicious activity, triage alerts, investigate incidents, and remediate threats.
- Partner with engineering and operations teams to deliver secure-by-design solutions.
Requirements
- 7+ years of experience in security engineering or security operations in cloud environments.
- Experience with AWS cloud security, or equivalent Azure and GCP experience with some AWS experience.
- Experience with cloud-native Kubernetes services such as EKS, GKE, or AKS and container security principles.
- Experience securing IAM and cloud identities at scale.
- Experience leading product and architecture security reviews, threat modeling, and translation of findings into security controls.
- Practical understanding of web application security concepts, including OWASP Top 10.
- Hands-on experience with infrastructure as code and tools such as Terraform, CloudFormation, Helm, and Pulumi.
- Experience developing automation and tooling with one or more of Python, Go, Shell, HCL, or Rego.
- Bachelor’s degree in computer science or a related field, or equivalent job experience in lieu of a degree, is preferred.
- Experience with CNAPP, CSPM, or CIEM solutions is preferred.
- Applicants must have legal authorization to work in the position’s country without visa sponsorship.
