2 months ago
Mountain View, CA, USASenior
Base Salary
$190k - $250k/yr
Responsibilities
- Design, build, and maintain complex security systems for Kodiak’s central command-and-control application environment.
- Identify risks through threat modeling and risk assessment, then implement controls and supporting infrastructure.
- Provide security design patterns and enable engineering teams to own more of their security responsibilities.
- Develop the developer security program and integrate security practices into software development workflows.
- Harden CI/CD pipelines against supply-chain attacks using isolated builds, signed attestations, dependency verification, and policy enforcement.
- Architect credential issuance, rotation, workload authentication, identity, and secrets-management systems across multi-cloud environments.
- Implement cloud security controls including IAM, network segmentation, VPC architecture, and encryption across cloud and on-premises environments.
- Implement Kubernetes controls including RBAC, namespace isolation, workload identity, pod security, and cloud security posture management.
- Build security foundations including cryptographic frameworks, mTLS infrastructure, secure serialization, and authorization systems.
- Partner with product, research, infrastructure, and security teams to integrate security frameworks and controls.
Requirements
- At least 6 years of software engineering experience with deep security expertise and experience independently leading complex security initiatives.
- Bachelor’s degree in Computer Science or equivalent industry experience.
- Strong programming skills in Python or a systems language such as Go, Rust, or C/C++.
- Deep understanding of identity systems, cryptographic primitives, and secrets management.
- Working knowledge of Kubernetes security primitives including RBAC, namespaces, network policies, and service accounts.
- Experience leading cross-functional security initiatives and navigating complex organizational dynamics.
- Strong communication, ownership, problem-solving, collaboration, and team-development skills.
- Preferred experience designing identity and secrets-management systems for large-scale AI or cloud infrastructure.
- Preferred experience building organization-wide security frameworks, developer security programs, secure build infrastructure, and SDLC integrations.
- Preferred experience with Nix, Bazel, SPIFFE/SPIRE, mTLS, Linux internals, multi-cloud security architecture, service mesh security, CNI-level policy, eBPF, or kernel security policies.
Benefits
- Competitive compensation including equity and annual bonuses.
- Medical, dental, and vision plans, including infertility benefits, plus legal services, identity and fraud protection, hospital indemnity, accident, and critical illness insurance.
- Flexible PTO, 10 paid holidays, generous parental leave, and short- and long-term disability and life insurance.
- Mountain View, California office with dog-friendly facilities, catered lunch, stocked kitchen, and free EV charging.
- Wellbeing benefits including Headspace, Calm, One Medical, Gympass, Spring Health, and Rula.
- Fidelity 401(k), commuter benefits, FSA, dependent care FSA, HSA, referral bonuses, and patent bonuses.
- Office-based role with the office located in Mountain View, California; the listed base salary applies to the SF/Silicon Valley location.
