almost 2 years ago
Responsibilities
- Design, implement, and manage preventative and response-oriented security measures for cloud infrastructure, applications, and data.
- Collaborate with engineering teams to integrate secure coding standards, automated security testing, and secure architecture into the software development lifecycle.
- Monitor current security threats, vulnerabilities, and mitigation strategies.
- Conduct security code reviews and remediate identified vulnerabilities.
- Develop and implement automated security testing procedures and mitigation strategies.
- Respond to security incidents and participate in incident response procedures.
- Document security processes, procedures, and best practices.
- Lead security awareness and training programs for team members.
Requirements
- At least five years of experience as a Security Engineer focused on product security.
- Strong experience securing cloud-based environments across AWS, Azure, or GCP and applying Infrastructure as Code security practices.
- Proficiency in TypeScript and Python.
- Expertise in application security, network security, security operations, and incident response.
- Experience with container security, including Docker Security and Kubernetes Security.
- Familiarity with AWS services including VPC, EC2, Lambda, Amazon RDS, and S3.
- Knowledge of CI/CD pipeline tools and practices, ideally with GitHub Actions or Jenkins.
- Knowledge of security compliance frameworks and regulations such as ISO 27001, SOC 2, and GDPR, plus experience with security assessments and third-party audits.
- Proficiency with firewalls, IDS/IPS, vulnerability scanners, WAF, SIEM, and encryption solutions.
- Ability to influence security strategy and drive improvements within a team.
Benefits
- The team works in the office five days per week in San Francisco, within walking distance of Caltrain.
Tech Stack
Categories
About Factory
Factory is an AI research lab, bringing autonomy to software engineering with Droids.
