We are looking for a Product Security Specialist with a strong background in cloud-native applications and DevOps practices to help secure our products throughout the software development lifecycle. You will partner with engineering and DevOps teams to identify risks, improve resilience, and embed security into every phase of the product pipeline.
This role is ideal for someone who thrives at the intersection of security and engineering and is passionate about securing modern, scalable applications.
Key Responsibilities:
Security Risk Analysis: Evaluate new features, services, and architectural changes for potential security risks in cloud-native environments (e.g., Kubernetes, serverless, microservices).
Threat Modeling: Lead and facilitate threat modeling sessions with engineering teams to identify potential risks and mitigation strategies early in the design process.
Security Review & Assessment: Conduct in-depth security reviews of cloud infrastructure, CI/CD pipelines, and application designs.
Vulnerability & Patch Management: Collaborate with DevOps and SRE teams to monitor vulnerabilities, manage security patches, and improve response times across containers, runtimes, and third-party libraries.
Security Automation & Scanning: Integrate and analyze results from automated security tools (e.g., SAST, DAST, SCA) in CI/CD pipelines, and guide teams on remediation.
DevSecOps Enablement: Champion secure coding and DevSecOps practices by working closely with developers and DevOps teams to implement security controls as code.
This role is ideal for someone who thrives at the intersection of security and engineering and is passionate about securing modern, scalable applications.
Key Responsibilities:
Security Risk Analysis: Evaluate new features, services, and architectural changes for potential security risks in cloud-native environments (e.g., Kubernetes, serverless, microservices).
Threat Modeling: Lead and facilitate threat modeling sessions with engineering teams to identify potential risks and mitigation strategies early in the design process.
Security Review & Assessment: Conduct in-depth security reviews of cloud infrastructure, CI/CD pipelines, and application designs.
Vulnerability & Patch Management: Collaborate with DevOps and SRE teams to monitor vulnerabilities, manage security patches, and improve response times across containers, runtimes, and third-party libraries.
Security Automation & Scanning: Integrate and analyze results from automated security tools (e.g., SAST, DAST, SCA) in CI/CD pipelines, and guide teams on remediation.
DevSecOps Enablement: Champion secure coding and DevSecOps practices by working closely with developers and DevOps teams to implement security controls as code.
Requirements:
3+ years of experience in product security, DevSecOps, or cloud security.
Hands-on experience securing cloud-native environments (e.g., Kubernetes, Docker, microservices architectures).
Strong understanding of CI/CD pipelines, infrastructure as code (e.g., Terraform, Helm), and related DevOps practices.
Solid knowledge of application security principles, OWASP Top 10, and vulnerability remediation techniques.
Proficiency with at least one programming/scripting language (e.g., Python, Go, Bash).
Familiarity with cloud platforms (AWS, GCP, or Azure) and their security models.
Nice to Have:
Certifications such as CISSP, CSSLP, CKS, AWS Security Specialty, or GIAC DevSecOps.
Experience working in regulated or high-compliance environments.
Contributions to open-source security or DevOps tooling.
3+ years of experience in product security, DevSecOps, or cloud security.
Hands-on experience securing cloud-native environments (e.g., Kubernetes, Docker, microservices architectures).
Strong understanding of CI/CD pipelines, infrastructure as code (e.g., Terraform, Helm), and related DevOps practices.
Solid knowledge of application security principles, OWASP Top 10, and vulnerability remediation techniques.
Proficiency with at least one programming/scripting language (e.g., Python, Go, Bash).
Familiarity with cloud platforms (AWS, GCP, or Azure) and their security models.
Nice to Have:
Certifications such as CISSP, CSSLP, CKS, AWS Security Specialty, or GIAC DevSecOps.
Experience working in regulated or high-compliance environments.
Contributions to open-source security or DevOps tooling.
This position is open to all candidates.