2 hours ago
Responsibilities
- Lead threat modeling and security reviews for products and cloud infrastructure, identifying attack surfaces and developing scalable mitigations.
- Build automation, policy-as-code, and security tooling that integrates security throughout development workflows.
- Design and implement secure baselines for cloud resources and Kubernetes infrastructure.
- Lead vulnerability management and remediation, including prioritization, mitigation, and preventative controls across the software supply chain.
- Extend detection and response capabilities to identify malicious activity, triage alerts, investigate incidents, and drive remediation.
- Partner with engineering and operations teams to deliver secure-by-design solutions.
Requirements
- 7+ years of experience in security engineering or security operations in cloud environments.
- Experience with AWS cloud security, or equivalent Azure and GCP experience with some AWS experience.
- Experience with cloud-native Kubernetes services including EKS, GKE, or AKS and container security principles.
- Experience securing IAM and cloud identities at scale.
- Experience leading technical security reviews, conducting threat modeling, and translating findings into actionable controls.
- Practical understanding of web application security concepts such as OWASP Top 10.
- Hands-on experience with infrastructure as code and tools including Terraform, CloudFormation, Helm, or Pulumi.
- Experience developing automation and tooling with one or more of Python, Go, Shell, HCL, or Rego.
- Bachelor's degree in computer science or a related field is preferred, with equivalent job experience accepted in lieu of a degree.
- Experience with remote, globally distributed teams, software or managed infrastructure organizations, and CNAPP, CSPM, or CIEM solutions is preferred.
- Legal authorization to work in the position's country without visa sponsorship is required.
