
Senior Software Security Engineer, Infrastructure & Identity
DepthFirst12 hours ago
Responsibilities
- Own and improve depthfirst’s infrastructure security foundations from design through production.
- Improve cloud security posture across IAM, networking, and system security by building preventive controls and secure defaults.
- Strengthen authentication, authorization, human and workload identities, and secrets management across infrastructure and products.
- Build and maintain production software, tooling, and automation to prevent security issues, detect configuration drift, and reduce manual work.
- Partner with infrastructure and product engineers to review designs, address vulnerabilities, and deliver scalable security improvements.
- Help mature centralized security logging and detection and response capabilities.
Requirements
- Strong software engineering skills and a deep understanding of security principles, best practices, and common vulnerabilities.
- Proactive ability to identify and address security gaps or inefficiencies through automation and tooling.
- Track record of delivering scalable solutions and driving impactful infrastructure changes in real-world projects.
- Expertise in cloud platform security, including Amazon AWS, and familiarity with container security, orchestration security, and authentication and authorization.
- Strong written and verbal communication skills for explaining complex security issues to technical and non-technical audiences.
- Bonus: experience at a high-growth startup or early-stage company.
- Bonus: familiarity with security, infrastructure, or developer tooling markets.
Benefits
- Competitive salary with meaningful equity.
- Health, vision, and dental insurance.
- Office lunch and dinner at the San Francisco office.
- Ownership and significant room to grow as the company scales.
About DepthFirst
DepthFirst builds an AI-driven security platform that analyzes source code, infrastructure, and business logic to detect and help remediate software vulnerabilities, including potential zero-days. It sells enterprise security software and services to engineering and security teams at organizations with large codebases and open-source dependencies. Privately held and headquartered in San Francisco, the company focuses on general security intelligence delivered by AI agents that continuously scan customer and popular open-source projects.