Назад
2 дня назад

Engineer II, Software Assurance, Product Security

100 000 - 145 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Engineer II, Software Assurance, Product Security: Assessing, designing, and implementing security controls across the software supply chain with an accent on securing open-source footprints and upstream dependencies. Focus on building GitHub security tooling (guardrails, secret scanning), monitoring emerging vulnerabilities and malicious packages, and hardening public-facing and internal source code repositories against active and emerging threats.

Company

CrowdStrike is a cybersecurity company protecting organizations with an AI-native security platform.

What you will do

  • Assess software supply chain risk and provide security guidance to engineers on open-source usage and repository configurations.
  • Design, implement, and maintain tools and processes to secure public/private GitHub organizations, including repository guardrails and secret scanning.
  • Harden open-source code usage across the enterprise, covering development, ingestion, and distribution.
  • Investigate open-source dependencies and third-party packages to mitigate supply chain threats (e.g., typosquatting, dependency confusion).
  • Promote secure coding and open-source compliance practices across engineering.
  • Deliver security initiatives that harden software supply chain and code-hosting environments.

Requirements

  • Experience implementing, supporting, and monitoring software security systems in an engineering role.
  • Strong experience with GitHub, including repository administration, GitHub Actions, branch protection rules, and access management.
  • Experience identifying and mitigating open-source vulnerability risks (SCA, dependency management, licensing risks).
  • Experience securing Linux and/or other Unix-like configurations.
  • Proficiency in one or more scripting languages such as Python, Golang, Shell, or JavaScript to automate security checks.
  • Familiarity with SDLC, secure coding practices, code reviews, and source control security.

Nice to have

  • Experience with monitoring/log aggregation tools (e.g., Splunk, Datadog, Prometheus, LogScale).
  • Familiarity with other SCM tools (e.g., Bitbucket) and artifact storage (e.g., Artifactory, S3).
  • Understanding of CI/CD pipelines and tools (e.g., Jenkins, Argo CD) from an integration/ingestion perspective.
  • Experience working with and securing large-scale cloud platform configurations.
  • Experience with code signing, PKI, and verifying artifact integrity.
  • Experience using AI technologies to enhance decision-making or automate vulnerability triage.

Culture & Benefits

  • Remote work based in the USA.
  • Market-competitive compensation and equity awards.
  • Comprehensive physical and mental wellness programs.
  • Competitive vacation and holidays, plus paid parental and adoption leaves.
  • Professional development opportunities for all employees.
  • Employee networks and volunteer opportunities; vibrant office culture.

Hiring process

  • Interviews focused on security engineering experience, GitHub/open-source security, and supply chain risk mitigation.
  • Evaluation of collaboration and ability to deliver security initiatives in a remote environment.

Location: USA - Remote

Salary: $100,000 - $145,000 per year

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →