Engineer II, Software Assurance, Product Security
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Engineer II, Software Assurance, Product Security: Assessing, designing, and implementing security controls across the software supply chain with an accent on securing open-source footprints and upstream dependencies. Focus on building GitHub security tooling (guardrails, secret scanning), monitoring emerging vulnerabilities and malicious packages, and hardening public-facing and internal source code repositories against active and emerging threats.
Company
CrowdStrike is a cybersecurity company protecting organizations with an AI-native security platform.
What you will do
- Assess software supply chain risk and provide security guidance to engineers on open-source usage and repository configurations.
- Design, implement, and maintain tools and processes to secure public/private GitHub organizations, including repository guardrails and secret scanning.
- Harden open-source code usage across the enterprise, covering development, ingestion, and distribution.
- Investigate open-source dependencies and third-party packages to mitigate supply chain threats (e.g., typosquatting, dependency confusion).
- Promote secure coding and open-source compliance practices across engineering.
- Deliver security initiatives that harden software supply chain and code-hosting environments.
Requirements
- Experience implementing, supporting, and monitoring software security systems in an engineering role.
- Strong experience with GitHub, including repository administration, GitHub Actions, branch protection rules, and access management.
- Experience identifying and mitigating open-source vulnerability risks (SCA, dependency management, licensing risks).
- Experience securing Linux and/or other Unix-like configurations.
- Proficiency in one or more scripting languages such as Python, Golang, Shell, or JavaScript to automate security checks.
- Familiarity with SDLC, secure coding practices, code reviews, and source control security.
Nice to have
- Experience with monitoring/log aggregation tools (e.g., Splunk, Datadog, Prometheus, LogScale).
- Familiarity with other SCM tools (e.g., Bitbucket) and artifact storage (e.g., Artifactory, S3).
- Understanding of CI/CD pipelines and tools (e.g., Jenkins, Argo CD) from an integration/ingestion perspective.
- Experience working with and securing large-scale cloud platform configurations.
- Experience with code signing, PKI, and verifying artifact integrity.
- Experience using AI technologies to enhance decision-making or automate vulnerability triage.
Culture & Benefits
- Remote work based in the USA.
- Market-competitive compensation and equity awards.
- Comprehensive physical and mental wellness programs.
- Competitive vacation and holidays, plus paid parental and adoption leaves.
- Professional development opportunities for all employees.
- Employee networks and volunteer opportunities; vibrant office culture.
Hiring process
- Interviews focused on security engineering experience, GitHub/open-source security, and supply chain risk mitigation.
- Evaluation of collaboration and ability to deliver security initiatives in a remote environment.
Location: USA - Remote
Salary: $100,000 - $145,000 per year
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →