Security Infrastructure Engineer
Builds security controls across cloud, Kubernetes, networks, and CI/CD for Tailscale. Audits infrastructure, implements security features in Go/Terraform, and provides threat modeling expertise. Requires cloud security and infrastructure experience.
Job Summary
Seeking a software engineer specializing in security and infrastructure to strengthen Tailscale's product security team. Focus on advancing security while collaborating asynchronously with technical teams. Role involves 25-50% software development.
Key Responsibilities
- Design and build security controls across cloud platforms, OS, Kubernetes, networks, and CI/CD to defend against adversaries and insider threats.
- Improve Tailscale's security and privacy through features, bug fixes, and defense-in-depth implementations.
- Audit infrastructure for security weaknesses and drive resolutions.
- Provide threat modeling, security analysis, and expertise for engineering decisions.
What We Are Looking For
Technical
- Expertise in cloud platform security (e.g., AWS), multi-cloud networks, and cloud-agnostic systems.
- Familiarity with container security, orchestration security, authentication/authorization.
- Knowledge of internet/web security: WAFs, TLS, PKI, DNS security.
- Proficiency in programming (Tailscale uses Go) and IaC tools (Terraform, Ansible).
- Prior experience in infrastructure security, security operations, threat modeling, digital forensics, or incident response.
- Knowledge of OS internals, security mechanisms, and networking protocols.
- Act as SME during security incidents for infrastructure containment and remediation.
Team Fit
- Give and process constructive feedback.
- Work independently and collaboratively.
- Adapt to startup dynamics.
- Balance security expertise with practical solutions.
Product Security Engineer
Product Security Engineer embedding into engineering workflows to conduct architecture reviews, threat modeling, and penetration testing coordination while serving as GCP security SME. Requires 5-7 years experience and strong GCP and Python skills.
Senior Product Security Engineer II
Senior security engineer focused on offensive security testing, penetration testing, and scaling security practices across Instacart's product suite. Requires 7+ years in security engineering or pentesting with experience in mobile, cloud, or AI security.
Senior Security Engineer, GRC
Senior GRC engineer owning customer security questionnaires, compliance automation, risk assessments, and policy management across SOC 2, ISO 27001, and HIPAA. Requires 8+ years experience, scripting skills, and strong customer-facing communication.
Director, Product Security Engineering
Lead product security initiatives by embedding security into the SDLC, performing threat modeling, building security tooling, and mentoring teams. Requires 8-10+ years of product security experience and deep expertise in cloud, application, and mobile security.