Remote job
Senior Product Security Engineer
Job details
About this role
Role overview
This is a deeply technical security engineering role embedded directly within product development rather than functioning as a downstream review gate. The work centers on securing CI/CD pipelines and hardening cloud-native infrastructure for Kubernetes-based workloads running on major cloud providers.
Responsibilities
- Design, build, and maintain secure CI/CD pipelines with automated security gates that catch issues before production - Implement and enforce software supply chain controls including signed artifacts, SBOMs, and provenance attestation such as SLSA, Sigstore, and Cosign - Systematically and automatically capture the risk exposure of products across releases - Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS - Harden container images, Kubernetes cluster configurations, and cloud IAM postures to minimize attack surface - Define and drive adoption of baseline security standards including pod security standards, network policies, workload identity, and secrets management - Proactively identify emerging customer security needs and build solutions to address them
Requirements
- 5+ years in software engineering, security engineering, or a combined role with hands-on security ownership throughout - Strong proficiency in Go or Python with the ability to write, review, and debug production-quality code - Deep Kubernetes experience in production covering cluster hardening, RBAC, network policies, and admission controllers - Practical expertise with GCP and/or AWS including IAM, workload identity, secrets management, and security services - Proven track record designing and securing CI/CD pipelines such as GitHub Actions, Cloud Build, or Tekton - Fluency with container security including image scanning, minimal or distroless base images, and runtime security - Hands-on experience with supply chain security tooling and frameworks including Sigstore, SLSA, and SBOM generation - Working knowledge of OWASP, NIST, and cloud security frameworks applied pragmatically
Nice to have
- Familiarity with minimal or hardened container base image ecosystems - Experience with policy-as-code tools such as OPA, Kyverno, or Conftest - Contributions to open source security projects - Background in offensive security, bug bounty, CTF, or penetration testing
Benefits and work setup
- Base salary range of $157,000–$184,000 USD - Remote-first culture with team meetups, bi-annual destination summits, and a monthly stipend for coworking, phone, and internet - Equity grants upon hire and promotion, with participation in secondary offerings and a 10-year option exercise window - 100% employer-paid health, vision, and dental insurance for employees and dependents - Flexible paid time off - 18 weeks paid parental leave for birthing parents and 12 weeks for non-birthing parents