Remote job
Senior Product Security Engineer
Job details
About this role
Role overview A staff-level individual contributor role embedded inside product engineering rather than gated at the end of the process. The position owns the secure software supply chain posture for a portfolio of container-based products, with hands-on responsibility for pipeline hardening and cloud-native infrastructure security. The work blends deep technical execution with cross-team influence, threat modeling, and proactive identification of emerging customer security needs.
Responsibilities - Design, build, and maintain CI/CD pipelines with security gates that block risky changes before production - Continuously and automatically surface risk exposure across the product portfolio - Implement software supply chain controls including signed artifacts, SBOMs, and provenance attestation aligned to frameworks such as SLSA and Sigstore/Cosign - Anticipate emerging customer security requirements and translate them into shipped solutions - Lead security architecture reviews and threat models for Kubernetes workloads running on GCP and AWS - Harden container images, Kubernetes cluster configurations, and cloud IAM postures to shrink attack surface - Define baseline standards for pod security, network policies, workload identity, and secrets management, and drive cross-team adoption
Requirements - 7+ years in software engineering, security engineering, or a combined role with substantial hands-on security ownership - Strong proficiency in Go or Python, including the ability to write, review, and debug production-quality code - Deep production experience hardening Kubernetes clusters: RBAC, network policies, admission controllers - Practical expertise with GCP and/or AWS security services, IAM, workload identity, and secrets management - Proven track record securing CI/CD pipelines using tools such as GitHub Actions, Cloud Build, or Tekton - Fluency with container security including image scanning, distroless or minimal base images, and runtime defenses - Working knowledge of Sigstore, SLSA, SBOM generation, and pragmatic application of OWASP and NIST frameworks
Nice to have - Familiarity with minimal or hardened container base image ecosystems - Experience with policy-as-code tools such as OPA, Kyverno, or Conftest - Contributions to open source security projects - Background in security research, bug bounty work, CTF, or penetration testing
Benefits and work setup - Remote-first culture with team meetups and bi-annual destination summits - Monthly stipend for coworking, phone, and internet - Stock options with a 10-year exercise window and participation in secondary offerings - 100% employer-covered health, vision, and dental premiums for employee and dependents - Flexible time off and 18 weeks paid parental leave for birthing parents (12 weeks for non-birthing parents)