Senior Application Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Application Security Engineer: Securing the Temporal development pipeline, product, and customer execution environment with an accent on building security deeply into the platform across multiple clouds. Focus on shaping how AI is used responsibly in both the product and engineering processes, and enabling engineering teams to build and ship securely.
Location: United States - Remote Opportunity
Salary: $140,000 - $175,000
Company
Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things like delivering features faster.
What you will do
- Integrate security principles into the design and architecture of products.
- Conduct threat modeling and risk assessments to identify vulnerabilities and potential attack vectors.
- Manage the Secure Development pipeline including code security and 3rd party library supply chain security.
- Stay current on emerging standards and guidance and translate these into actionable internal policy.
- Triage Bug Bounty findings and responsibility disclosed vulnerabilities.
- Participate in on-call rotation.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
- 5+ years in application or product security or a related role.
- Proven partnership with engineering teams, bringing security expertise to the planning and development process.
- Knowledge of encryption, authentication, and secure communication protocols.
- Familiarity with tools like SAST, DAST, and penetration testing frameworks.
- Expertise in at least one programming language, familiarity with Python and Go.
Nice to have
- Kubernetes security posture management and auditing, including workload hardening, RBAC design, and admission control.
- Demonstrated experience with multi-tenant security architecture, including data plane isolation, control plane hardening, and cross-tenant data leakage prevention.
- Distributed computing and related vulnerability experience.
- Running a Security Champions program.
- Open Source automation or automation projects.
Culture & Benefits
- Unlimited PTO, 12 Holidays + 2 Floating Holidays
- 100% Premiums Coverage for Medical, Dental, and Vision
- Empower 401K Plan
- Additional Perks for Learning & Development, Lifestyle Spending, In-Home Office Setup, Professional Memberships, WFH Meals, Internet Stipend and more!
- Occasional travel may be required for company events, team offsites, and other meaningful moments that bring us together.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →