Staff Security Engineer

🕒 il y a 1 mois

🌐 États-Unis, Canada – Distant

infoinfo

💵 $210 000 - $247 000 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

👻 Score fantôme 10%

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Redpanda Data

Redpanda Data

51 - 200 employés

Fondée en 2019

🏢 Entreprise

☁️ SaaS

🤝 B2B

💰 €100 000 000 Series D - Redpanda Data en 2025-04

Enterprise • SaaS • B2B

Redpanda Data est l'entreprise derrière Redpanda, une plateforme de streaming de données haute performance compatible avec l'API d'Apache Kafka. Redpanda offre un moteur de diffusion de messages à un seul binaire, avec une faible latence et un débit élevé, ainsi que des offres cloud managées conçues pour remplacer facilement Kafka afin de simplifier les pipelines de données en temps réel, les applications orientées événements, les journaux et les métriques. L'entreprise se concentre sur la fourniture d'une infrastructure de streaming de qualité professionnelle pour les équipes de développement et d'exploitation à travers un logiciel auto-géré et des services SaaS/cloud managés.

Description

• Own and scale application security across Redpanda’s C++ core streaming engine, Go cloud control plane, Console, and Rust/Go data-transform SDKs • Lead threat modeling and secure design reviews for new product features • Own and tune SAST, SCA/dependency scanning, secret scanning, and DAST across C++, Go, and Rust • Build coverage-guided and protocol-aware fuzzing harnesses for the core engine and integrate sanitizers • Conduct secure code reviews in systems languages and eradicate classes of vulnerabilities • Operate PSIRT and coordinated vulnerability disclosure, including triaging researcher reports, driving fixes, and publishing advisories and CVEs • Strengthen software supply-chain security through dependency hygiene, SBOMs, build provenance, and SLSA progress • Establish a security champions program and secure-by-default libraries, patterns, and guardrails • Define security requirements and shape security release gates • Advise on authentication, authorization/RBAC, encryption, audit logging, multi-tenant isolation, and the Agentic Data Plane • Raise security standards through training, pragmatic standards, hands-on engineering partnership, and AI-assisted development workflows • Partner with the Director of Information Security, infrastructure security engineer, platform engineering, and product engineering teams

🎯 Exigences

• 7+ years in application security, product security, or adjacent specialties • Track record of owning AppSec initiatives end-to-end and influencing engineering teams without direct authority • Ability to review and reason about code in a systems language; C++ or Rust strongly preferred and Go valuable • Strong understanding of memory safety, concurrency, use-after-free, buffer overflow, injection, and authorization flaws • Comfort with security risks of memory-unsafe code and willingness to fuzz it • Practical proficiency with SAST, SCA, secret scanning, and DAST • Experience leading threat modeling and secure design reviews for non-trivial systems • Working knowledge of dependencies, SBOMs, signing, SLSA, and secure CI/CD • Familiarity with AWS, GCP, or Azure and Kubernetes security at the application layer • Excellent written and verbal communication skills • Comfort working in a globally distributed, async environment • Fuzzing with libFuzzer, AFL++, or OSS-Fuzz and sanitizers such as ASan, UBSan, or MSan is a plus • Background securing distributed systems, databases, or data-infrastructure products is a plus • PSIRT, CNA, bug bounty, or coordinated disclosure experience is a plus • Exposure to SOC 2, ISO 27001, HIPAA, or FedRAMP compliance programs is a plus • Open-source security contributions or public repository vulnerability-handling experience is a plus

🏖️ Avantages

• Salary ranges determined by role, level, and location • Individual base salary consideration based on job-related skills, location, experience, relevant education or training • Latest AI tools and budget to use them • People-first organization • Culture based on trust, transparency, communication, and kindness • Diverse, global team

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

Brown Medicine

201 - 500

🏥 Santé

📚 Éducation

🔬 Science

Principal Security Architect securing Brown University Health’s hybrid and multi-cloud healthcare environments. Governing identity, data, network, AI, and enterprise security architecture.

🗣️🇺🇸🇬🇧 Anglais requis

Ansible

AWS

Azure

Cloud

DNS

Firewalls

Linux

Python

Switching

Terraform

Vault

🕒 il y a 1 mois

Beshenich Muir & Associates

51 - 200

🎖️ Défense

🚀 Aérospatiale

🏛️ Gouvernement

R&D Cybersecurity Engineer supporting DLA Okta environments and government information systems. Administering secure infrastructure, automation, maintenance, networking, and technical support.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Azure

Cyber Security

🕒 il y a 1 mois

Optiv

1001 - 5000

Principal AI cybersecurity advisor designing scalable security solutions for Optiv, a company managing cyber risk. Driving AI security strategy, thought leadership, and services sales for enterprise clients.

🗣️🇺🇸🇬🇧 Anglais requis

Cyber Security

🕒 il y a 1 mois

Beyond Finance

1001 - 5000

💸 Finance

💳 Fintech

👥 B2C

Staff Cloud Security Engineer hardening AWS infrastructure and CI/CD for Beyond Finance, helping Americans escape crippling debt. Owning Wiz-based cloud security and vulnerability management.

🇺🇸 États-Unis – Télétravail

💵 $160 000 - $195 000 / an

💰 €110 000 000 Debt Financing en 2021-02

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Snowflake

5001 - 10000

☁️ SaaS

🏢 Entreprise

🤝 B2B

Staff Security Engineer protecting Snowflake’s enterprise endpoints with AI-driven security platforms. Owning endpoint security tooling, automation, detection, incident response, and strategy across multi-cloud environments.

🇺🇸 États-Unis – Télétravail

💵 $211 000 - $303 600 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis