We’re looking for an independent-minded, autodidact, and detail-oriented cloud security engineer to join our efforts to build a best-of-breed infrastructure-as-code security platform.
You would be working on our brand new infrastructure-as-code security product, expanding our security covers from source code down to the infrastructure. We recognize that developers are increasingly working with technologies like Kubernetes & Terraform, and it can be hard to stay secure and move fast - we provide that peace of mind with this product.
In this role, you would be responsible for the best practice security policies that we recommend developers adopt to stay secure—working closely with the product team to identify customer needs and staying close to the technologies and community to identify security best practices.
You’ll spend your time: owning and expanding our cloud security policies ruleset to cover the newest cloud services across AWS, Azure, and GCP creating threat models and attack scenarios for container orchestrators and cloud provider services evaluating the latest infrastructure as code tooling for their security controls, working to develop recommended security best practices converting cloud security whitepapers, documentation and API reference material to automated cloud security checks building technology for automating our capability to create policies quickly talking to our customers, making sure we’re building a product they truly love collaborating with your team, planning the most important projects to work on next sharing your security expertise by presenting to internal teams, and writing technical blog posts
You should apply if you: have experience with operating infrastructure on one or more public cloud platform providers (AWS /GCP/Azure) using infrastructure-as-code tooling have experience writing code across the stack have a software security mindset, you know the security and compliance best practices for AWS, Azure and Google Cloud ensure a high-quality code that can be safely co-authored in a fast-growing organization practice writing tests as an integral part of your software development life-cycle communicate proactively and have a team-first mindset love working in a fast-paced start-up environment that respects its engineers and customers
We’d especially love to hear from you if you: have experience with Open Policy Agent and have defined policies using Rego have experience with Kubernetes either as a stand-alone or as a hosted cloud-service (AWS ECS/EKS, GKE or Azure AKS) have experience with compliance programs (PCI, HIPAA, NIST, SOC II, etc.) have security research experience have a good track record of project leadership and mentorship of software engineers have strong community involvement (open source, conferences, meetups, etc.)