4 days ago
Base Salary
$175k - $200k/yr
Responsibilities
- Partner with product and engineering teams on architecture reviews, threat modeling, secure design, and practical security recommendations.
- Evaluate and roll out AI-assisted and agentic security workflows for security reviews, vulnerability triage, and remediation.
- Improve first- and third-party security tooling, including Doppel’s in-house ASPM platform.
- Strengthen SDLC and CI/CD security controls, including code and dependency scanning, software supply chain protections, and safeguards for AI-assisted development.
- Advise engineering teams on GCP security, including networking, data protection, secrets management, workload runtimes, logging, and monitoring.
- Implement least-privilege IAM, secure workload identities, and security guardrails through policy and infrastructure-as-code.
- Drive vulnerability management from triage through resolution, including risk assessment, ownership, remediation tracking, exceptions, and risk acceptance.
- Coordinate penetration testing engagements and remediation and retesting activities.
- Help scale the product security program and communicate risks, progress, and outcomes to security leadership.
- Enable engineers through documentation, reusable guidance, targeted training, and mentorship.
Requirements
- 5–7 years of experience in product security, cloud security engineering, software development, or a related field.
- Practical experience applying AI and agentic workflows to security reviews, vulnerability triage, and remediation, including understanding of AI-assisted development risks.
- Strong knowledge of Google Cloud Platform services and security best practices, including IAM, networking, data protection, and workload runtimes.
- Hands-on experience with penetration testing coordination, threat modeling, and risk assessment.
- Proficiency in Python and cloud-native programming or scripting languages for security automation, policy enforcement, and continuous compliance controls using infrastructure as code.
- Familiarity with least-privilege IAM design and enforcement and access reviews.
- Ability to communicate security risks and recommendations clearly to engineering and leadership audiences.
Benefits
- $175,000–$200,000 USD compensation; Canadian compensation follows Canadian compensation bands and may vary by location.
- Meaningful equity.
- Remote-first flexibility, with the role open remotely across the U.S. and Canada or hybrid from New York, San Francisco, or Toronto.
- Quarterly offsites and frequent opportunities to travel to company offices.
- Flexible PTO, comprehensive health benefits, and parental leave.
- High-growth environment with immediate impact and visibility.
Tech Stack
Categories
About Doppel
Doppel builds an AI-driven social engineering defense platform that unifies email security, digital risk/brand protection, and human risk management for enterprises. The SaaS platform disrupts phishing and impersonation by scanning across web and communication channels and executing automated takedowns of lookalike domains, rogue profiles, and malicious infrastructure. Privately held and founded in 2022, it is backed by a16z and Bessemer, with customers including OpenAI, United Airlines, and Coinbase.
