Empowering every homeowner with ease, security, and financial know-how.
Staff Product Security Engineer – Customer Platform
Location
United States
Posted
121 days ago
Salary
$190K - $260K / year
Seniority
Lead
Job Description
Staff Product Security Engineer – Customer Platform
Valon
• Define and evolve product security architecture and strategy for Valon’s multi-tenant SaaS platform • Architect and guide secure implementation of customer-facing security capabilities in conjunction with Engineering (e.g., authentication / authorization models, identity integration, access controls, audit and logging, encryption / key management) • Build and maintain security reference architectures and standardized secure design patterns for product teams • Lead threat modeling, security design and code reviews for new features, services, and major architectural changes • Collaborate with Product, Engineering, Data, Compliance, Legal, and other teams to identify and drive mitigation for product and data security risks • Support vulnerability triage, remediation strategy, and root cause analysis for product security issues • Support security compliance and regulatory needs (e.g., SOC 2, CCPA, NYDFS, FTC), including customer-facing security discussions and due diligence • Develop, implement, and enforce security policies, standards, and procedures • Support operational activities including security advisory and consultative reviews, incident response, issue remediation, and other security processes
Job Requirements
- 8+ years in progressive senior security engineering or architect level roles, with 3+ years leading security design for enterprise-grade cloud and SaaS platforms
- Bachelor's degree in Information Security, Computer Science, Technology or related field
- Relevant security certifications (e.g., CISSP, CISM, CCSK, CCSP or similar)
- Proven ability to design security reference architectures and implement customer platform security controls and technologies (IAM, API security, encryption/key management, logging/monitoring)
- Hands-on experience with modern security technologies and tooling across cloud and application security
Benefits
- Competitive salary with a meaningful stake in the company via equity, and 401k plan
- We’ll invest in your physical and mental well-being with comprehensive medical, dental, & vision benefits
- Commuter benefits: pre-tax deductions for public transportation, rideshare services, and parking expenses
- Company wide orientation for successful onboarding and learning & development opportunities including regular review cycles featuring 360 degree feedback
- Quarterly budgets for team and company outings, for team swag, cooking classes, or team dinners!
- Flexible paid time off, sick days, and 11 company holidays
- Baby bonding time: 12 weeks off for both birthing and non-birthing parents - fully paid
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Analyst, Governance, Risk & Compliance, Information Security
Mondelēz InternationalWe’re a house of incredible brands providing people with the right snack, for the right moment, made the right way.
• Execute risk assessment testing supporting the Risk Manager. • Document risk assessment results. • Support Risk Manager in drafting risk assessment reports. • Perform administrative management of risk register (additions/editions/deletions, etc). • Document risk acceptance/exemptions that have been approved per the program. • Manage quarterly/annual review of risk acceptance/exceptions. • Manage risk assessment results in relevant dashboards. • Document Issues and Remediation activities for all exceptions noted during risk assessments. • Perform quarterly compliance assurance testing. • Document compliance testing results. • Maintain Management Action Plan (MAP) catalog with due dates. • Manage monthly audit MAPs. • Provide administrative support for ad-hoc external audits. • Provide administrative support for internal audits. • Support compliance program reporting activities.
• Define and maintain observability architecture and strategy, aligned with resilience and regulatory requirements; • Design and configure dashboards, SLOs/SLAs, and alerts for different stakeholders; • Develop scripts and automations for advanced administration and monitoring (Dynatrace, Python, Workflow); • Implement observability extensions and tools for non-native technologies and integration with OpenTelemetry; • Analyze data, optimize queries, and extract key business and capacity/performance management metrics; • Efficiently manage resources and licenses in Dynatrace DPS, ensuring compliance with DORA requirements.
Staff Cloud Security Engineer
CalixTo enable broadband service providers of all sizes to simplify, innovate and grow.
• Conduct regular security assessments and audits of cloud infrastructure and services • Monitor and respond to security events and incidents in cloud environments • Develop and maintain cloud security policies, standards, and procedures • Stay current with emerging cloud security threats and mitigation strategies • Develop and maintain Infrastructure as Code (IaC) - Terraform templates with embedded security controls • Implement, manage, and monitor endpoint security solutions in cloud environments, including tools such as Cortex XDR and SentinelOne • Configure, manage, and troubleshoot cloud-based firewall technologies • Apply zero trust principles through strict network segmentation, authentication, and authorization across our cloud environments • Collaborate with development teams to ensure security best practices are integrated into CI/CD pipelines • Provide technical leadership and mentorship to junior engineers, fostering a culture of continuous learning and improvement
• Responsible for creating and driving their sales pipeline • Capture leads outside of specialization and use closed-loop lead management to ensure assignment and follow-up by others • Maintains knowledge of competitors in account to strategically position the company’s products and services better • Use specialty expertise to seek out new opportunities and expand and enhance existing opportunities to build the pipeline in and drive pursuit • Provide support to Account managers and provide input regarding business development and solution expertise • Development of quota objectives and future direction for defined product category • Establish a professional, working, and consultative relationship with the client, up to and including the C-level for mid-to-large accounts.




