Were looking for a Senior Product Security Engineer who is passionate about partnering with engineers to assess the security risk of new products & features.
As a member of the Secure Design team, you will report to the Senior Manager of Product Security. Our Secure Design team enables DigitalOcean to build secure-by-design products. We leverage strong relationships with both product teams & the rest of security engineering to be successful. Our scope is primarily focused on reviewing early-stage decisions, helping develop threat models, scaling impact via automation, curating security patterns, authoring security guidance, training, & championing security initiatives.
You will collaborate with other security teams & the rest of DigitalOcean to guide secure architecture design, reduce security risk in the organization, & empower engineers to make informed security decisions. Security at DO means solving incredibly complex problems at a high-scale that have real impact for our customers, our products, & the larger internet community.
What youll do:
Threat model application designs & solutions & provide security risk assessments (70%)
- Provide deep technical expertise in software & network architecture during holistic assessments of security layers across infrastructure, application, people, & process.
- Collaborate with product managers, designers, & engineers to threat model & architect secure & resilient systems.
- Identify the trade-offs of different solutions & recommend the efficient design to achieve both functional goals & security requirements.
- Provide hands-on remediation guidance to development teams.
Cultivate & promote a security culture (20%)
- Champion an internal security culture (developer training, internal CTFs, etc.).
- Mentor software engineering teams in security best practices.
- Help oversee our vulnerability management program (we call it security debt).
- Help DigitalOcean engineers understand how security events impact them. Do they need to worry about the next Log4j CVE? How does RetBleed impact DigitalOceans fleet?
Build security tooling & automations to help scale the Product Security team's practices (10%)
- Use software architecture & coding patterns to reduce the impact of security issues.
- Drive architecture, patterns, & processes across engineering that make security the easiest path.
- Integrate custom security tooling into engineering workflows.
What youll add to DigitalOcean:
Required qualifications:
- Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities.
- Ability to clearly communicate security topics & vulnerability classes (e.g. OWASP Top Ten) & ability to provide actionable direction to product teams.
- A record of partnering with internal engineering teams to tackle security problems across an entire stack with empathy & creativity. Engineering teams are our partners, not our adversaries.
- Working knowledge of modern development concepts (virtualized environments, containerization, continuous integration + delivery).
Preferred qualifications:
- 5+ years experience guiding software teams on secure architecture design.
- Proficiency in network and/or system architecture design: with concepts such as BGP & gNMI, & you think of TCP, not geography, when someone says Reno.
- A big part of our product is our networking layer. If you get excited about the thought of driving the secure design of network-level architecture, let us know!
- Experience building or reviewing threat models & ability to craft malicious user, attacker, & abuse/misuse cases.
- Working knowledge of hardware & software supply chain security.
- Familiarity with object oriented & functional programming concepts, particularly with languages such as Go, JavaScript, Rust, or C.
Why Youll Like Working for DigitalOcean:
- We innovate with purpose. Youll be a part of a cutting-edge technology company with an upward trajectory, who are proud to simplify cloud & AI so builders can spend more time creating software that changes the world. As a member of the team, you will be a Shark who thinks big, bold, & scrappy, like an owner with a bias for action & a powerful sense of responsibility for customers, products, employees, & decisions.
- We prioritize career development. At DO, youll do the best work of your career. You will work with some of the smartest & most interesting people in the industry. We are a high-performance organization that will always challenge you to think big. Our organizational development team will provide you with resources to ensure you keep growing. We provide employees with reimbursement for relevant conferences, training, & education. All employees have access to LinkedIn Learning's 10,000+ courses to support their continued growth & development.
- We care about your well-being. Regardless of your location, we will provide you with a competitive array of benefits to support you from our Employee Assistance Program to Local Employee Meetups to flexible time off policy, to name a few. While the philosophy around our benefits is the same worldwide, specific benefits may vary based on local regulations & preferences.
- We reward our employees. The salary range for this position is $135,000 - $185,000 based on market data, relevant years of experience, & skills. You may qualify for a bonus in addition to base salary; bonus amounts are determined based on company & individual performance. We also provide equity compensation to eligible employees, including equity grants upon hire & the option to participate in our Employee Stock Purchase Program.
- We value diversity & inclusion. We are an equal-opportunity employer, & recognize that diversity of thought & background builds stronger teams & products to serve our customers. We approach diversity & inclusion seriously & thoughtfully. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.
*This is a remote role.
#LI-Remote
|