Lead Product Security Engineer

🕒 il y a 1 mois

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Aalyria

Aalyria

51 - 200 employés

📡 Télécommunications

🏢 Entreprise

☁️ SaaS

Telecommunications • Enterprise • SaaS

Aalyria est une entreprise spécialisée dans les technologies de l'espace et des communications, qui crée, organise et gère des réseaux à l'échelle planétaire en combinant des communications laser atmosphériques cohérentes sans fil (Tightbeam) avec une plateforme logicielle d'orchestration de réseau alimentée par l'IA (Spacetime). L'entreprise permet une connectivité multi-domaines et multi-orbites à travers la terre, la mer, l'air et l'espace — soutenant des constellations de satellites, des architectures 5G/NTN et des réseaux hybrides — et travaille avec des partenaires commerciaux et gouvernementaux pour déployer des matériels et logiciels pour des communications résilientes et haute-capacité.

Description

• You'll be the technical voice of product security across Aalyria, reporting to the Director of Security & IT. • You'll own application security, CI/CD and supply-chain security, our Kubernetes-based product infrastructure, product-side authentication and PKI. • You'll partner closely with hardware engineering on Tightbeam. • Application & software security. SAST/DAST/SCA, secure SDLC, threat modeling, and software vulnerability management across our codebase. • CI/CD and supply-chain security. Hardening our GitLab pipelines, build provenance, dependency integrity, signing, and SLSA-aligned controls. • Product infrastructure security. GKE and Kubernetes hardening, container security, workload identity, network policy, and runtime protection. • Product PKI. Certificate lifecycle, issuance, rotation, and mTLS architecture across distributed services and remote assets. • Vulnerability management. Triage, prioritization, remediation tracking, and exception handling, for both disclosed upstream issues and internal findings. • Product incident response. Leading triage and response for product-side security incidents, coordinating with corporate IR, and driving post-mortems to action. • Product infra hardening. Baseline configurations, secure defaults, and compensating controls across product environments. • Hardware security partnership. Working with the Tightbeam team on firmware security, secure boot, key storage, and hardware supply-chain integrity.

🎯 Exigences

• Senior- or staff-level hands-on experience in product security or security engineering, with significant depth in software/AppSec. • Production experience securing cloud environments such as IAM, org policy, VPC Service Controls, KMS, and Kubernetes at depth. • Strong cryptographic foundations, PKI architecture, key management, signing, mTLS, and secrets handling at scale. • Hands-on coding ability in Python, Bash, and Go, you can write tooling, automate controls, and ship Terraform/scripts when the situation calls for it. • Comfort reviewing code is a plus. • A track record of building security programs, not just operating tools someone else stood up. • Experience leading product incident response, triage, response, coordination with engineering teams, customer comms, and post-mortem ownership. • A pattern of mentoring engineers and raising the security bar of teams around you, even without direct reports. • Experience interfacing with hardware/firmware teams, even if hardware isn't your primary domain. • Strong written communication, you'll write threat models, design docs, and program updates that go to the executives, customers, and assessors. • Working knowledge of the compliance frameworks that govern our environment such as CMMC, FedRAMP, and DFARS along with the ability to translate controls into engineering work.

🏖️ Avantages

• Innovative Environment: Work at a cutting-edge company shaping the future of aerospace communications. • Impactful Work: Directly contribute to critical national security programs and initiatives. • Growth Opportunities: Expand your career with opportunities for professional development and advancement. • Inclusive Culture: Be part of a collaborative, supportive, and inclusive workplace where your contributions matter. • Flexibility: Flexible working arrangements including hybrid remote/in-office schedules.

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

Gainwell Technologies

10 000+ employés

⚕️ Assurance santé

Senior Identity & Access Management Engineer implementing and operating federated identity integrations using modern protocols. Supporting healthcare applications with a focus on security and automation.

🇺🇸 États-Unis – Télétravail

💵 $110 000 - $150 000 / an

💰 Grant en 2023-06

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Insight Therapy Solutions

51 - 200

⚕️ Assurance santé

🧘 Bien-être

📚 Éducation

Freelance consultant auditing WordPress site for HIPAA compliance, covering security risks in telehealth. Focused on privacy, data handling, reporting, and remediation planning.

🇺🇸 États-Unis – Télétravail

💵 $20 - $25 / heure

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Firewalls

WordPress

🕒 il y a 1 mois

Gainwell Technologies

10 000+ employés

⚕️ Assurance santé

Senior Identity & Access Management Engineer responsible for authentication integrations at Gainwell. Implementing solutions supporting modern healthcare applications with a focus on identity configurations and automation.

🇺🇸 États-Unis – Télétravail

💵 $110 000 - $150 000 / an

💰 Grant en 2023-06

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

NVIDIA

10 000+ employés

🤖 Intelligence artificielle

🎮 Jeux vidéo

Cloud Security Architecture Lead guiding security for global cloud and datacenter infrastructure at NVIDIA. Ensuring protection of critical AI workloads with advanced security frameworks and mentoring a team.

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Salesloft

501 - 1000

🤝 B2B

☁️ SaaS

⚡ Productivité

Manager of Security Engineering and Operations at Clari + Salesloft, leading the information security team. Responsible for building and mentoring security analysts and engineers while ensuring security integration in operations.

🗣️🇺🇸🇬🇧 Anglais requis