We are seeking a highly motivated Staff Software Engineer, Security Engineering to lead strategic initiatives in dependency vulnerability management and cloud-native security. This role requires technical expertise in remediating dependency vulnerabilities but also a proven ability to design, build, and deploy cutting-edge automation (including AI/ML/LLM solutions) to scale our remediation efforts. You will be a key driver in establishing security best practices for our containerized environments and maturing our overall security posture.
Key Responsibilities:
- Architect, develop, and deploy highly scalable security automation and tooling to significantly reduce Time-to-Remediate (TTR) identified risk.
- Lead the integration of advanced AI/ML capabilities into the vulnerability management lifecycle, focusing on automated vulnerability validation, intelligent patch suggestion, and PR generation for dependency remediation.
- Serve as a technical expert for complex dependency vulnerability triage and remediation, particularly for critical and zero-day issues identified by SCA tools.
- Establish patterns and best practices for the end-to-end remediation process, including analysis, automated PR creation, and validation testing.
- Drive the prioritization and remediation strategy across multiple engineering teams and product lines.
- Design, implement, and govern the process for building and maintaining hardened container base images for development and production environments, focusing on minimizing attack surface.
- Provide technical guidance and engineering solutions for securing Kubernetes (K8s) and containerized workloads, including runtime security, network policies, and admission controllers.
- Contribute significantly to the overall Security Engineering roadmap and strategy.
- Provide consultation on application security architecture and design to engineering leadership.
- Demonstrated success through cross functional collaboration and team work, ability to drive solutions beyond their individual contribution.
Our Ideal Candidate Will Have:
- Deep, proven experience with container security, including designing and deploying hardened container images and securing Kubernetes clusters.
- Expert-level proficiency in Software Composition Analysis (SCA) and hands-on experience in the practical remediation of third-party and open-source dependency vulnerabilities at scale.
- Strong practical experience in building and operating security automation, with development expertise in languages like Go and/or Python
- Expertise in using GitHub, and CI/CD systems (GitHub Actions, Jenkins) from an architectural and engineering perspective.
- Proficient in application security principles, secure code review, and the OWASP Top 10.
- Direct experience or strong conceptual understanding of applying AI/ML, Large Language Models (LLMs), or MCP techniques to security challenges (e.g., automated vulnerability fixing, intelligent alert grouping).
- Expert familiarity with cloud platforms (AWS, Azure) and their security services, with a focus on container orchestration.
Nice to Have:
- Experience with Infrastructure as Code (IaC) tools, especially Terraform, for provisioning security controls.
- Published research, talks, or contributions to open-source security projects.
- Experience with supply chain security frameworks (e.g., SLSA).
- Advanced knowledge of Application security (OWASP Top 10)