Назад
Company hidden
2 часа назад

Staff Product Security Engineer (Cybersecurity)

Формат работы
remote (только United_kingdom)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Staff Product Security Engineer (Cybersecurity): Designing and maintaining secure CI/CD pipelines and hardening cloud-native infrastructure with an accent on software supply chain security and Kubernetes orchestration. Focus on implementing SLSA/Sigstore controls, automating risk exposure capture, and minimizing the attack surface across GCP and AWS.

Location: Remote (United Kingdom)

Company

hirify.global provides hardened, secure, and production-ready builds of open source software to help organizations eliminate risk and stay compliant.

What you will do

  • Design and maintain secure CI/CD pipelines with automated security gates to catch issues before production.
  • Implement software supply chain security controls, including signed artifacts, SBOMs, and provenance attestation (SLSA, Sigstore/Cosign).
  • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
  • Harden container images, Kubernetes cluster configurations, and cloud IAM postures to minimize the attack surface.
  • Define and drive the adoption of baseline security standards, including pod security standards, network policies, and secrets management.
  • Operationalize CNAPP and CSPM tooling to maintain continuous visibility into cloud-native risk.

Requirements

  • 7+ years of experience in software engineering, security engineering, or a combined role.
  • Proficiency in Go or Python with the ability to write production-quality code.
  • Deep hands-on experience with production Kubernetes, including cluster hardening, RBAC, and network policies.
  • Practical expertise with GCP and/or AWS security services, IAM, and workload identity.
  • Proven track record of designing and securing CI/CD pipelines (e.g., GitHub Actions, Tekton).
  • Fluency with container security, including image scanning and distroless base images.

Nice to have

  • Familiarity with hirify.global Images or other hardened container base image ecosystems.
  • Experience with policy-as-code tools such as OPA, Kyverno, or Conftest.
  • Contributions to open source security projects.
  • Background in security research or offensive security (bug bounty, CTF, penetration testing).

Culture & Benefits

  • Remote-first culture with monthly stipends for coworking spaces, phone, and internet.
  • Stock options upon hire and promotion with a 10-year exercise window.
  • 100% covered health, vision, and dental insurance premiums for employees and dependents.
  • Infinite flexible time off to recharge and reset.
  • Generous paid parental leave (18 weeks for birthing parents, 12 weeks for non-birthing parents).

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →