Security Engineer - Product
Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.
About the job
Responsibilities
- Lead threat modeling and security reviews across products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
- Build automation, policy-as-code, and security tooling to help development teams integrate end-to-end security into their workflows.
- Design and implement secure baselines for cloud resources and Kubernetes infrastructure.
- Drive vulnerability management and remediation by prioritizing issues, implementing mitigations, and designing preventative controls across software supply chains from development through production.
- Extend detection and response capabilities by building scalable solutions to identify malicious activity, triage alerts, investigate incidents, and support remediation.
- Partner with engineering and operations teams to deliver secure-by-design solutions.
Requirements
- 7+ years of experience in security engineering or security operations in cloud environments.
- AWS cloud security experience, or equivalent Azure and Google Cloud experience with some AWS experience.
- Experience with cloud-native Kubernetes services and container security principles.
- Experience securing IAM and cloud identities at scale.
- Experience leading technical security reviews, conducting threat modeling, and translating findings into actionable controls.
- Practical understanding of web application security concepts, including OWASP Top 10.
- Hands-on experience with infrastructure as code and related tools.
- Experience developing automation and tooling with one or more of Python, Go, Shell, HCL, or Rego.
Nice-to-haves
- Bachelor's degree in computer science or a related field, or equivalent experience.
- Experience working with remote, globally distributed teams.
- Experience at organizations that develop software or operate managed infrastructure and technology services.
- Experience with CNAPP, CSPM, or CIEM solutions.
Compensation and Benefits
- Applicants must have the legal right to work in the country where the position is based without visa sponsorship.
- This role does not offer visa sponsorship.
Skills
AWS, Azure, GCP, Kubernetes, EKS, GKE, Aks, IAM, Terraform, CloudFormation, Helm, Pulumi, Python, Go, Shell
Similar jobs
Security Engineering jobsSenior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Senior security engineer who red teams formally verified systems, assesses proof and threat-model boundaries, and builds AI-driven vulnerability discovery and exploit-generation tooling. Requires hands-on offensive security, formal methods, systems expertise, software development, and rigorous technical reporting.
Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.