Job Closed

This listing is no longer active.

DigitalOcean logo
DigitalOcean

The cloud ☁️ of choice for developers, startups, and growing digital businesses around the world.

Staff Product Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 1,001-5,000Since 2011H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

72 days ago

Salary

$170K - $200K / year

Seniority

Lead

Job Description

Staff Product Security Engineer

DigitalOcean

Role Description We’re looking for a Staff Product Security Engineer who is passionate about partnering with engineers to assess the security risk of new products and features and build secure-by-default paved roads. As a member of the Product Security team, you will report to the Senior Manager of Product Security. Our mission is to minimize security risk while maximizing business velocity. This staff engineer will help oversee the strategic functions of two Product Security teams: Secure Design and Security Platform. - Threat model application designs and solutions and provide security risk assessments (60%) - Provide deep technical expertise in software and network architecture during holistic assessments of security layers across infrastructure, application, people, and process. - Collaborate with product managers, designers, and engineers to threat model and architect secure and resilient systems. - Identify the trade-offs of different solutions and recommend the efficient design to achieve both functional goals and security requirements. - Provide hands-on remediation guidance to development teams. - Build secure-by-default guardrails for engineers (30%) - Design and build internal tooling to provide engineering teams with secure-by-default configurations and libraries. - Write robust, resilient, and maintainable software, primarily in Go and Python. You may sometimes work on a frontend. - Prioritize the user experience (our customers are internal dev teams) to ensure security’s libraries and services are the easiest, fastest way to get work done. - Cultivate and promote a security culture (10%) - Champion an internal security culture (developer training, internal CTFs, etc.). - Mentor software engineering teams in security best practices. - Help oversee our vulnerability management program (we call it security debt). - Help DigitalOcean engineers understand how security events impact them. Qualifications - Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities. - Ability to clearly communicate security topics and vulnerability classes (e.g. OWASP Top Ten) and ability to provide actionable direction to product teams. - A record of partnering with internal engineering teams to tackle security problems across an entire stack with empathy and creativity. - Strong knowledge of modern development concepts (virtualized environments, containerization, continuous integration + delivery). Requirements - 6+ years experience guiding software teams on secure architecture design. - 5+ years of experience in software engineering projects, ideally with a security focus. - Experience building or reviewing threat models and ability to craft malicious user, attacker, and abuse/misuse cases. - Working knowledge of hardware and software supply chain security. - Familiarity with technologies such as gRPC, Docker, Prometheus, Kubernetes, HashiCorp Vault, and GitHub Actions. Benefits - Competitive array of benefits to support well-being, including Employee Assistance Program and flexible time off policy. - Reimbursement for relevant conferences, training, and education. - Access to LinkedIn Learning's 10,000+ courses for continued growth and development. - Salary range based on market data, relevant years of experience, and skills. - Potential for bonuses based on company and individual performance. - Equity compensation to eligible employees, including equity grants upon hire.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 10,001+Since 1956H1B Sponsor

• Schedule and coordinate in-person meetings with state or local government customers within the sales region • Provide presentations and demonstrations of our technology to existing and prospective customers • Identify new business opportunities in law enforcement, fire hazmat and narcotics identification markets • Work with channel partners including forecasting, training and goal setting • Provide input in technical consultation and problem solving to meet customer needs • Meet or exceed established sales goals by delivering bookings commitments in accordance with business unit targets • Build and implement strategies and tactical plans to drive growth • Communicate bookings outlook to management and the broader organization to ensure transparency into performance and timely delivery of products and services • Drive collaboration and accountability through improved sales pipeline and forecast management processes by using sales tools like Salesforce.com • Work with product management teams and make recommendations based on the understanding of marketing and new product plans • Prepare quotations and tender submissions for the market area in liaison with management and carry out follow-up with customers for products and services • Participate in trade shows and technical seminars/workshops

Maryland + 2 moreAll locations: Maryland | Massachusetts | Michigan
$71.3K - $107K / year
Job Closed
Full TimeRemoteTeam 1,001-5,000

At Morgan & Morgan, the work we do matters. For millions of Americans, we’re their last line of defense against insurance companies, large corporations or defective goods. From attorneys in all 50 states, to client support staff, creative marketing to operations teams, every member of our firm has a key role to play in the winning fight for consumer rights. Our over 6,000 employees are all united by one mission: For the People. Summary Morgan & Morgan is looking for an attorney to join its growing Social Security Disability practice. The attorney will handle a large case load and must have experience with Social Security Disability hearings. This position can sit in any of our offices in the United States. Responsibilities - Guide clients through the case process - Attendance and preparation for hearings and court appearances - Day-to-day handling of active case load - Properly delegating work and responsibilities between a team of case staff Qualification - Law degree from a fully accredited law school - An active member in good standing with a State Bar Association - Social Security Disability hearing experience - Ability to manage high volume of cases - Excellent client service and communication skills - Self-starter driven by long-term career goals - Superior writing and oral advocacy skills #LI-CB2 Benefits Morgan & Morgan is a leading personal injury law firm dedicated to protecting the people, not the powerful. This success starts with our staff. For full-time employees, we offer an excellent benefits package including medical and dental insurance, 401(k) plan, paid time off and paid holidays. Equal Opportunity Statement Morgan & Morgan provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. E-Verify This employer participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. If E-Verify cannot confirm that you are authorized to work, this employer is required to give you written instructions and an opportunity to contact Department of Homeland Security (DHS) or Social Security Administration (SSA) so you can begin to resolve the issue before the employer can take any action against you, including terminating your employment. Employers can only use E-Verify once you have accepted a job offer and completed the I-9 Form. Privacy Policy Here is a link to Morgan & Morgan's privacy policy.

United States
Nava logo

Senior Security Engineer, Azure Security

Nava

Building simple, effective government services. Want to contribute? We're hiring!

Full TimeRemoteTeam 501-1,000Since 2015H1B Sponsor

• Design and implement identity and access management (IAM) models, including RBAC and privileged access controls • Configure and advise on security tools such as Microsoft Defender for Cloud • Define and enforce security policies and governance guardrails using Azure Policy • Set up and guide centralized logging, monitoring, and threat detection capabilities • Design key management and secrets handling solutions (e.g., Azure Key Vault) • Support compliance efforts, including HIPAA alignment and ATO preparation activities • Collaborate with teams to identify security risks and define remediation approaches • Contribute to secure cloud architecture decisions, including networking and access patterns • Support Infrastructure-as-Code (IaC) and CI/CD practices to ensure secure deployments • Create security documentation, runbooks, and provide guidance to enable client teams to operate securely

Alabama + 28 moreAll locations: Alabama | Arizona | California | Colorado | Florida | Illinois | Louisiana | Maine | Nevada | New Jersey | New York | North Carolina | Ohio | Oklahoma | Oregon | Maryland | Massachusetts | Michigan | Minnesota | Missouri | Pennsylvania | Rhode Island | South Carolina | Tennessee | Texas | Utah | Virginia | Washington | Wisconsin
$144.5K - $153K / year
Job Closed
GuidePoint Security logo

Security Engineer - Heartland (Remote)

GuidePoint Security

Founded in 2011 and headquartered in Herndon, Virginia, GuidePoint Security furnishes commercial and federal organizations with customized information security

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk. Position Requirements: - 1-2 years of architecture, implementation, and troubleshooting experience with one or more SIEM/SOAR solutions - Proficiency developing log ingestion and aggregation strategies - Expertise developing security-focused content for one more more SIEM platforms (Splunk ES, Crowdstrike NG-SIEM, Elastic Security, Palo Alto XSIAM, Google SecOps, Microsoft Sentinel, SentinelOne AI SIEM), including creation of complex threat detection logic and operational dashboards - Expertise with SOAR platforms (Splunk SOAR, Palo Alto XSOAR, Tines, Torq) - Familiarity with key security events on common IT platforms - Deep proficiency in client and server operating systems including Windows, Mac, and Linux - General networking and security troubleshooting (firewalls, routing, NAT, etc.) - Scripting and development skills (BASH, Perl, Python or Java) with strong knowledge of regular expressions - Ability to autonomously prioritize and successfully deliver across a portfolio of projects Preferred Requirements: - Experience with other Information Security solutions including CrowdStrike, SentinelOne, ZScaler, Palo Alto Networks, Check Point, Microsoft Defender products, Carbon Black, Splunk, and/or Cisco - Experience authoring security runbooks, policy, and best practice documentation - Bachelor’s degree in a relevant discipline or equivalent professional experience We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application. Why GuidePoint? GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers. Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity. This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation. Some added perks…. - Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions) - Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options) - Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans - 12 corporate holidays and a Flexible Time Off (FTO) program - Healthy mobile phone and home internet allowance - Eligibility for retirement plan after 2 months at open enrollment - Pet Benefit Option

United States
Job Closed