Remote job
Senior Product Security Engineer
Job details
About this role
Role overview Senior Product Security Engineer role embedded directly inside engineering rather than placed at the end of the release process. The position focuses on securing software supply chains and hardening cloud-native product infrastructure built on Kubernetes across GCP and AWS.
Responsibilities - Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before production. - Implement and enforce software supply chain security controls including signed artifacts, SBOMs, and provenance attestation aligned with frameworks such as SLSA, Sigstore, and Cosign. - Lead security architecture reviews and threat modeling for Kubernetes-based workloads running on GCP and AWS. - Harden container images, Kubernetes cluster configurations, and cloud IAM postures to reduce attack surface. - Define and drive adoption of baseline security standards covering pod security, network policies, workload identity, and secrets management. - Proactively identify emerging customer security needs and build solutions to address them.
Requirements - At least five years in software engineering, security engineering, or a combined role with hands-on security responsibility. - Strong proficiency in Go or Python, with the ability to write, review, and debug production-quality code. - Deep hands-on experience with Kubernetes in production, including cluster hardening, RBAC, network policies, and admission controllers. - Practical expertise with GCP and/or AWS security services, IAM, workload identity, and secrets management. - Proven track record designing and securing CI/CD pipelines using tools such as GitHub Actions, Cloud Build, or Tekton. - Experience with software supply chain security tooling and frameworks including Sigstore, SLSA, and SBOM generation, plus familiarity applying OWASP, NIST, and cloud security frameworks.
Nice to have Familiarity with minimal or hardened container base image ecosystems, policy-as-code tools such as OPA, Kyverno, or Conftest, contributions to open source security projects, or a background in security research or offensive security.
Benefits and work setup Remote-first culture with team meetups, bi-annual destination summits, and a monthly stipend for coworking, phone, and internet costs. Equity granted on hire and promotion with extended exercise windows, 100% covered health, vision, and dental insurance for employees and dependents, flexible time off, and 18 weeks of paid parental leave for birthing parents and 12 weeks for non-birthing parents. Base salary range of $157,000 to $184,000 USD.