Назад
3 дня назад

Engineer II, Software Assurance, Product Security (Remote)

100 000 - 145 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Engineer II, Software Assurance, Product Security (Remote) (GitHub/Open-Source Security): Securing CrowdStrike’s software supply chain and code-hosting environments through security assessments, repository controls, dependency analysis, and automation with an accent on open-source risk mitigation and GitHub security. Focus on investigating malicious packages, hardening source-code repositories, implementing secret scanning and guardrails, and building automated security checks with Python, Golang, Shell, or JavaScript.

Location: USA - Remote

Salary: $100,000–$145,000 per year, with eligibility for bonuses and equity grants.

Company

Cybersecurity company building an AI-native platform to protect organizations from advanced threats and software breaches.

What you will do

  • Assess open-source software risks and provide security guidance on usage, repository configurations, and secure coding.
  • Implement and maintain security controls for public and private GitHub organizations, including repository guardrails, branch protection, access management, and secret scanning.
  • Harden open-source code usage, development, ingestion, and distribution across the enterprise.
  • Investigate dependencies and third-party packages for supply chain threats such as typosquatting and dependency confusion.
  • Create tooling and automations to address security gaps and improve operational efficiency.
  • Collaborate with engineering teams on initiatives that harden source-code repositories and code-hosting environments.

Requirements

  • Experience implementing, supporting, and monitoring software security systems in an engineering role.
  • Strong experience with GitHub administration, GitHub Actions, branch protection rules, and access management.
  • Experience identifying and mitigating open-source risks, including SCA, dependency management, and licensing risks.
  • Experience securing Linux or other Unix-like systems and familiarity with artifact storage tools such as Artifactory and S3.
  • Proficiency in Python, Golang, Shell, JavaScript, or another common scripting language for automating security checks.
  • Knowledge of SDLC, secure coding, code reviews, source control security, cross-team security collaboration, and AI technologies for workflow or vulnerability-triage automation.

Nice to have

  • Experience with LogScale, Splunk, DataDog, Prometheus, or similar monitoring and log aggregation tools.
  • Understanding of CI/CD tools such as Jenkins and Argo CD from an integration and ingestion perspective.
  • Experience securing large-scale cloud platforms.
  • Ability to identify security problems and develop pragmatic solutions with development teams.

Culture & Benefits

  • Remote work environment with flexibility and autonomy.
  • Health, physical wellness, and mental wellness programs.
  • Competitive vacation and holidays, plus paid parental and adoption leave.
  • Professional development opportunities for employees at all levels.
  • Employee networks, geographic neighborhood groups, and volunteer opportunities.
  • Bonuses, equity grants, health insurance, 401(k), and paid time off.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →