Назад
Company hidden
6 часов назад

Senior Security Engineer (Cloud Security)

130 000 - 150 000CAD
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US/Ireland +1 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer (Cloud Security): Securing Tigera’s Calico product suite and SaaS infrastructure with an accent on vulnerability management, threat modeling, application security, and cloud security. Focus on building security tooling and automation, hardening Kubernetes and cloud environments, developing detection capabilities, and supporting Security Incident Response Team investigations.

Location: Vancouver, Canada — hybrid

Salary: CAD $130,000–$150,000 per year

Company

hirify.global develops Calico, an open-source and commercial network security and observability platform for Kubernetes clusters.

What you will do

  • Own vulnerability management across the Calico portfolio, including security testing, triage, exploitability assessment, proof-of-concept development, CVE coordination, and remediation.
  • Lead threat modeling and security design reviews for Calico Open Source, Calico Enterprise, and Calico Cloud.
  • Drive product hardening, cloud infrastructure security, secure code review, SAST, and dependency scanning.
  • Build internal security tooling, contribute to patches, and develop secure-by-default patterns and automated guardrails.
  • Contribute to detection engineering and participate in Security Incident Response Team investigations and post-incident reviews.
  • Partner with engineering teams to improve security through automation and developer enablement.

Requirements

  • 5+ years of hands-on security engineering experience in product and/or cloud security.
  • Experience with end-to-end vulnerability management, threat modeling, and security design reviews.
  • Experience testing web applications, APIs, and cloud infrastructure using industry-standard tools such as Burp Suite.
  • Familiarity with Kubernetes, containers, and cloud security across GCP, Azure, or AWS.
  • Ability to code in Python, Go, or a similar language.
  • Strong written and verbal communication skills, including security advisories and customer-facing security artifacts.

Nice to have

  • Software supply-chain security and securing hosts, databases, applications, microservices, or cloud architectures.
  • Purple-team penetration testing, detection engineering, or experience with security platforms.
  • Open-source security contributions, bug bounty participation, public CVE disclosures, or security research publications.
  • OSCP, OSWE, CISSP, GIAC, or equivalent certification.

Culture & Benefits

  • Collaborative and flexible work environment based on respect, openness, and teamwork.
  • Full health, vision, and dental benefits.
  • Opportunity to work on security technology used across major cloud providers and Kubernetes distributions.
  • International team with offices in San Francisco, San Jose, Vancouver, Cork, and London.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →