Staff Application Security Engineer (DevSecOps)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Staff Application Security Engineer (DevSecOps): Own the AppSec/DevSecOps program strategy for embedding security into the SDLC with shift-left practices, paved roads, and automation, with an accent on secure CI/CD, Kubernetes/GCP tooling, and AI/ML workflow controls. Focus on designing guardrails that reduce developer risk and cognitive load while leading security architecture, threat modeling, and incident-response readiness across multiple teams.
Location: Remote within the United States or Canada
Salary: $198,000–$233,000 USD (high cost of living areas) or $172,000–$216,000 USD (all other US locations), plus bonus eligibility and equity
Company
provides real-time internet visibility and actionable threat intelligence for security teams and governments.
What you will do
- Own and drive the AppSec/DevSecOps roadmap, defining how security is embedded into the SDLC through shift-left practices, paved roads, and automation instead of gates.
- Design, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform (GCP), including support for AI/ML workloads.
- Integrate security into CI/CD pipelines (code scanning, secret detection, software composition analysis, and infrastructure policy enforcement) with engineering teams.
- Deliver hardened service templates, secure service catalogs, and guardrails that reduce developer risk and cognitive load.
- Set security architecture direction for AI/ML workflows, implementing controls for training/deployment/inference pipelines (access control, artifact validation, sanitization, and provenance tracking).
- Provide technical leadership and mentorship via design reviews and threat modeling; participate in shared on-call rotation for security incident response readiness.
Requirements
- 10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles, including leading security initiatives across multiple teams.
- Deep expertise securing Kubernetes environments (container images, network policies, and supply chain protections such as Helm and Crossplane).
- Strong application security tooling experience (dependency scanning, static analysis, and policy enforcement) integrated into CI/CD (e.g., GitHub Actions, ArgoCD) and ability to bridge engineering with Security Operations.
- Strong understanding of attacker TTPs and familiarity with MITRE ATT&CK.
- Strong cloud security experience with GCP preferred, including securing data pipelines and model hosting endpoints.
- Proficiency with Infrastructure-as-Code (e.g., Terraform, Crossplane) and scripting/automation (e.g., Python, Bash).
Culture & Benefits
- Equity, health/dental/vision coverage, retirement with company contribution, parental leave, and mental health & wellness benefits.
- Flexible PTO and a professional development stipend.
- Bonus eligibility and equity; annual bonus plan for eligible non-sales roles.
- Remote role with onboarding in-person at HQ in Ann Arbor (Michigan).
- Shared on-call rotation with Infrastructure and SRE teams.
Hiring process
- Interview process includes objective assessment of skills, prior relevant experience, potential impact, and role scope.
- Video interviews require candidates to keep cameras on.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →