Staff Product Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Staff Product Security Engineer (Cybersecurity): Designing and maintaining secure CI/CD pipelines and hardening cloud-native infrastructure with an accent on software supply chain security and Kubernetes orchestration. Focus on implementing SLSA/Sigstore controls, automating risk exposure capture, and minimizing the attack surface across GCP and AWS.
Location: Remote (United Kingdom)
Company
provides hardened, secure, and production-ready builds of open source software to help organizations eliminate risk and stay compliant.
What you will do
- Design and maintain secure CI/CD pipelines with automated security gates to catch issues before production.
- Implement software supply chain security controls, including signed artifacts, SBOMs, and provenance attestation (SLSA, Sigstore/Cosign).
- Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS.
- Harden container images, Kubernetes cluster configurations, and cloud IAM postures to minimize the attack surface.
- Define and drive the adoption of baseline security standards, including pod security standards, network policies, and secrets management.
- Operationalize CNAPP and CSPM tooling to maintain continuous visibility into cloud-native risk.
Requirements
- 7+ years of experience in software engineering, security engineering, or a combined role.
- Proficiency in Go or Python with the ability to write production-quality code.
- Deep hands-on experience with production Kubernetes, including cluster hardening, RBAC, and network policies.
- Practical expertise with GCP and/or AWS security services, IAM, and workload identity.
- Proven track record of designing and securing CI/CD pipelines (e.g., GitHub Actions, Tekton).
- Fluency with container security, including image scanning and distroless base images.
Nice to have
- Familiarity with Images or other hardened container base image ecosystems.
- Experience with policy-as-code tools such as OPA, Kyverno, or Conftest.
- Contributions to open source security projects.
- Background in security research or offensive security (bug bounty, CTF, penetration testing).
Culture & Benefits
- Remote-first culture with monthly stipends for coworking spaces, phone, and internet.
- Stock options upon hire and promotion with a 10-year exercise window.
- 100% covered health, vision, and dental insurance premiums for employees and dependents.
- Infinite flexible time off to recharge and reset.
- Generous paid parental leave (18 weeks for birthing parents, 12 weeks for non-birthing parents).
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →