Strengthen MongoDB’s server products through product security assessments, threat modeling, vulnerability research, and security controls. The role requires application or product security experience, C++ expertise with low-level codebases, scripting ability, and strong cross-team communication.
106k – 209k/yr
Remote5+ YOESecurity Engineering
About the role
Responsibilities
Take ownership, define strategy, and drive improvement for security program areas such as fuzzing, threat modeling, secrets management, and container security.
Support engineering teams responding to security issues by providing risk analysis and proofs of concept.
Advocate for and contribute to complex security projects from inception through completion.
Drive architecture, patterns, and processes across Server Engineering that make security the easiest path.
Partner with engineering teams to design and implement security controls across software and systems.
Research and proof-of-concept new attacks against systems.
Plan and perform product security assessments, including architecture reviews, threat modeling, code review, penetration testing, and general security consulting.
Serve as a security subject matter expert for software security and architecture.
Educate the engineering organization through CTFs, lunch-and-learns, and one-on-one mentorship.
Requirements
3 years of experience in application security, software security, or product security.
Experience with C++ programming, security assessments of low-level codebases, and remediation of memory-related security flaws such as buffer overflows and memory leaks.
Scripting experience and the ability to contribute code to engineering environments.
Ability to lead threat modeling and serve as a security ambassador to engineering teams.
Ability to communicate complex technical issues clearly to varied audiences.
Strong ownership and delivery skills.
Ability to facilitate collaborative conversations.
Ability to provide collaborative, actionable feedback.
Nice-to-Haves
Subject matter expertise in database security or data security.
Knowledge of database engines, database internals, or applied cryptography.
Experience partnering with security researchers to identify vulnerabilities published as CVEs or handling CNA administrative responsibilities.
Success in This Role
See projects through from conception to completion to deliver new services or capabilities.
Establish yourself as a go-to person for security topics.
Compensation and Benefits
U.S. base salary range: $106,000–$209,000 USD.
Compensation is based on factors including skills, experience, qualifications, and work location.
Total compensation may also include equity and participation in the employee stock purchase program.
Eligible benefits may include flexible paid time off, 20 weeks of fully paid gender-neutral parental leave, fertility and adoption assistance, a 401(k) plan, mental health counseling, transgender-inclusive health insurance coverage, and health benefits offerings.
Support engineers in Identity and Access Management, AI, and Cloud security at Chainguard. Ideal for those with strong IT admin or software development foundations seeking to grow into security roles, with hands-on experience in at least one focus area.
Tier 3 engineer deploys/manages EDR tools, conducts incident response, vulnerability assessments, and identity protection for clients. Monitors threats, automates workflows with SOAR/Python, and handles fraud resolution. Requires 3+ years cybersecurity experience.
110k – 130k/yrRemote3+ YOESecurity Engineering
Application Software Engineer, Endpoint Security
OneleetBeaverton, OR
Develops and maintains cross-platform endpoint security agent for Windows, macOS, and Linux using Go and JavaScript. Handles system monitoring, threat detection, secure cloud communication, and compliance enforcement. Requires 5+ years systems programming experience and OS internals knowledge.
110k – 180k/yrRemote5+ YOESecurity Engineering
GRC Analyst II
MetropolisLos Angeles, CA
GRC Analyst responsible for authoring security policies, managing company-wide security awareness training programs, establishing AI governance frameworks, conducting risk assessments on AI tools and models, and ensuring compliance with frameworks like SOC 2 and PCI-DSS. Requires 3+ years in information security GRC or compliance plus a Bachelor's degree.
100k – 135k/yrOn-site3+ YOESecurity Engineering
Application Security Engineer
ZocdocUnited States
Application Security Engineer partnering with engineering teams to embed security into the SDLC, triage SAST/SCA findings, provide remediation guidance on OWASP issues, maintain security docs/playbooks, support governance/audits, and integrate GenAI tools while building AI governance guardrails.