2 months ago
Base Salary
$205k - $240k/yr
Responsibilities
- Own cloud security strategy, architecture, implementation, and operations across AWS, Kubernetes, and the microservices platform.
- Design and implement workload identity, organization-wide IAM, least privilege, secrets management, and certificate and key lifecycle controls.
- Harden containers and orchestration through image provenance, admission control, runtime and network policy, service mesh configuration, and microservice isolation.
- Secure the software supply chain with SBOM generation, dependency and image scanning, signed artifacts, and CI/CD security controls.
- Build authorization services, policy enforcement, provisioning, and rotation tooling in Go, while providing DevSecOps guardrails and policy as code.
- Operate security detection and response through logging, telemetry, alerting, runbooks, security incident on-call, and blameless postmortems.
- Secure the vehicle-to-cloud boundary through device identity, provisioning, certificate rotation, OTA update paths, anomaly detection, and tamper detection.
- Contribute to backend engineering and own penetration testing, vulnerability management, evidence collection, and standards-related assurance work.
Requirements
- 10+ years of backend and infrastructure engineering experience, with substantial production security ownership.
- Expert hands-on AWS experience, including IAM, VPC, KMS, Secrets Manager, GuardDuty, Security Hub, CloudTrail, Config, SCPs, EKS, ECS, ECR, Lambda, DynamoDB, and S3.
- Deep Kubernetes and container security experience, including RBAC, admission controllers, pod security standards, network policy, secrets handling, runtime detection, image hardening, and cluster operations.
- Current production experience designing, reviewing, and shipping Go code.
- Experience securing microservices and distributed systems, including service authentication and authorization, API gateways, rate limiting, tenant isolation, and event-driven pipelines.
- Practical experience with OAuth2, OIDC, JWT, SAML, mutual TLS, PKI, and certificate lifecycle management at scale.
- Experience with infrastructure as code, policy as code, and security gates in CI/CD pipelines.
- Experience with threat modeling, secure architecture reviews, and leading incident response through postmortems.
- Demonstrated 0-to-1 ownership of a security function or program.
Benefits
- Health, dental, and vision insurance covered up to 100% with FSA and HSA options.
- One Medical membership and dedicated insurance advocates.
- Fertility and family-building benefits through Progyny.
- Flexible time off.
- 401(k) match.
Tech Stack
Categories
About ALSO
ALSO builds small, efficient electric vehicles for moving people and goods in dense urban settings, with options planned for both driver-operated and autonomous use. The privately held company, founded in 2025 and headquartered in Palo Alto, was originally incubated within Rivian and follows a vertically integrated approach spanning vehicle hardware, software, and sensing, selling directly through demos, retail experiences, and community activations.
