TL;DR
Product Security Engineer: Improving the security posture of hirify.global Cloud and OSS platforms and services with an accent on threat modeling, secure implementation, and vulnerability management. Focus on driving adoption of modern security processes, implementing engineering security tools, and handling information security incidents across products.
Location: Fully remote anywhere in Germany
Company
hirify.global is a fast-growing, globally distributed cloud company recognized for its real-time analytics, data warehousing, observability, and AI workloads.
What you will do
- Collaborate with engineering and product on improving and building secure product features, focusing on threat modeling, assurance, and secure implementation (e.g., key management, authentication, isolation).
- Identify security gaps and vulnerabilities in hirify.global Cloud and OSS, and triage issues from bug bounty programs and disclosures.
- Improve and develop security assurance activities including pentests, vulnerability assessments, and fuzzing.
- Drive implementation and usage of engineering security tools such as static/dynamic code analysis and dependency checks.
- Handle information security events and incidents across hirify.global products and services.
- Develop processes, tooling, and automation to scale security processes and mitigate business risks.
Requirements
- Experience supporting engineering and product implementation with threat assessments, assurance activities, and advisory across distributed systems.
- Strong knowledge and experience with one or more cloud service providers (AWS, GCP, Azure), Kubernetes, and Cilium.
- Experience implementing and operating engineering security tools and processes (e.g., static/dynamic code analysis, SBOM, OWASP SAMM, fuzzing).
- Significant development and automation experience, with the ability to work with C++ code.
- A security as code mindset, focusing on solving problems with automation and scale.
- English: B2 required
Nice to have
- BS, MS, or PhD in Computer Science or a related field.
- Previous contributions to open source projects.
- Security or cloud related certifications (AWS, GCP, Azure).
Culture & Benefits
- Flexible work environment: Globally distributed and remote-friendly.
- Employer contributions towards healthcare.
- Equity in the company through stock options.
- Flexible time off (US) / generous entitlement (other countries).
- $500 Home office setup for remote employees.
- Opportunities to engage with colleagues at company-wide offsites.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →