4 months ago
Remote, United StatesStaff+
Responsibilities
- Own application and software security, including SAST, DAST, SCA, secure SDLC, threat modeling, and vulnerability management.
- Harden GitLab CI/CD pipelines and software supply-chain controls, including build provenance, dependency integrity, signing, and SLSA-aligned controls.
- Secure GKE and Kubernetes product infrastructure through container security, workload identity, network policy, runtime protection, and hardened baselines.
- Design and operate product PKI, including certificate issuance, lifecycle management, rotation, key management, and mTLS architecture.
- Lead vulnerability triage, prioritization, remediation tracking, exception handling, and product-side incident response.
- Partner with hardware and firmware teams on secure boot, key storage, firmware security, and hardware supply-chain integrity.
- Build security tooling and automation with Python, Bash, Go, Terraform, and scripts.
- Mentor engineers, lead architecture reviews, write security documentation, and translate compliance controls into engineering work.
Requirements
- Senior- or staff-level hands-on experience in product security or security engineering with significant software and AppSec depth.
- Production experience securing cloud environments, including IAM, organization policy, VPC Service Controls, KMS, and Kubernetes.
- Strong cryptographic foundations and experience with PKI architecture, key management, signing, mTLS, and secrets handling at scale.
- Hands-on coding ability in Python, Bash, and Go, with the ability to ship tooling, Terraform, and scripts.
- Experience building security programs, leading product incident response, coordinating with engineering teams, and owning post-mortems.
- Experience mentoring engineers and raising the security standards of teams, including without direct reports.
- Experience interfacing with hardware and firmware teams and strong written communication skills.
- Working knowledge of CMMC, FedRAMP, and DFARS compliance frameworks.
- Preferred experience with NIST 800-53, NIST 800-171, DoD SRG environments, government-cloud platforms, HSMs, TPMs, secure elements, supply-chain attestation, embedded or firmware security, secure boot, RoT, OTA update integrity, vulnerability disclosure programs, bug bounties, and CVE coordination.
- Applicants must satisfy the stated U.S. export-control access requirements or be eligible and reasonably likely to obtain the necessary export authorization.
Benefits
- Flexible working arrangements, including hybrid remote/in-office schedules.
- Comprehensive benefits including 401(k), dental, vision, health, and life insurance.
- Paid time off and equity options.
- Professional development and career advancement opportunities.
- Collaborative, inclusive work environment focused on aerospace communications and national security programs.