Product Security Engineer focused on securing infrastructure and services for public sector customers. Conduct code reviews, SAST/DAST, implement secure CI/CD and Terraform, influence security strategy, and explain vulnerabilities. Requires product security experience, proficiency in TypeScript/Python/Kubernetes, and strong problem-solving/communication skills.
149k – 342k/yr
On-site5+ YOESecurity Engineering
About the role
Responsibilities
Conduct in-depth code reviews to identify and remediate security vulnerabilities.
Evaluate and enhance the security of product offerings through RFC and service review.
Implement and maintain CI/CD pipelines with a strong focus on security.
Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify vulnerabilities in production code.
Utilize Terraform orchestration to ensure secure and efficient infrastructure management.
Guide engineering teams to build robust long-term solutions that consider security and privacy.
Clearly explain the mechanics and significance of security vulnerabilities, including their exploitability and potential impact.
Influence the security strategy and direction of the team, advocating for best practices and continuous improvement.
Requirements
Proven experience as a Security Engineer with a focus on product security.
Proficiency in NodeJS, TypeScript, Python, and/or Kubernetes.
Strong understanding of modern Javascript application design.
Production experience with Kubernetes backed services.
Hands-on experience with SAST and DAST tools and methodologies.
Familiarity with Terraform orchestration for infrastructure management.
Ability to structure complex problems and diagnose root causes independently, providing actionable insights without requiring manager input.
Excellent communication skills, with the ability to clearly present technical concepts and their implications to both technical and non-technical stakeholders.
Demonstrated ability to influence security strategies and drive improvements within a team.
Nice-to-Haves
At least a Secret level government security clearance.
Infrastructure Security Engineer securing large-scale cloud environments, Kubernetes clusters, and infrastructure-as-code (Terraform) for the Public Sector team. Requires active Top Secret clearance, infrastructure security experience, and proficiency in cloud, Kubernetes, and scripting languages.
149k – 342k/yr
On-site5+ YOESecurity Engineering
Security Engineer
FigmaSan Francisco, CA +1
Security Engineer drives security improvements across Figma's AI, platform, product, and anti-abuse teams through assessments, tooling development, threat detection, and incident response. Requires 5+ years engineering experience, strong security judgment, and proficiency in a general-purpose language.
149k – 350k/yr
Remote5+ YOESecurity Engineering
Cloud Security Engineer
Virta HealthDenver, CO +1
Builds and matures cloud security program for GCP/Kubernetes platform, integrating security into development lifecycle, automating vulnerability management, and refining IAM/network controls. Requires hands-on experience with app sec, IaC (Terraform), and coding in Go/Python.
149k – 188k/yr
RemoteSecurity Engineering
Security & Compliance Engineer
AurelianSeattle, WA
Security & Compliance Engineer owning end-to-end security posture and compliance programs (SOC 2, CJIS) for public safety AI tools. Blend of hands-on cloud security engineering (Azure, IAM, logging) and compliance ownership, including questionnaires, policies, and automation.
150k – 215k/yr
On-site5+ YOESecurity Engineering
GRC Manager
BasetenSan Francisco, CA +1
GRC Manager responsible for building and managing Baseten's security governance, risk assessment, compliance programs (SOC 2, ISO 27001, FedRAMP, HIPAA), audits, vendor risk, and customer assurance in a fast-growing AI infrastructure startup. Requires 5+ years in GRC or security compliance, preferably in SaaS/cloud environments.