The Database for Developers
Software Engineer – Information Security
Location
California
Posted
51 days ago
Salary
$140K - $320K / year
Seniority
Senior
Job Description
Software Engineer – Information Security
PlanetScale
• Design and implement security controls for PlanetScale's cloud-native database platform • Collaborate with engineering teams to conduct security reviews, threat modeling, and provide secure coding guidance • Focus on proactive red teaming and testing to identify vulnerabilities • Evaluate, procure, and implement proactive security tools • Work with compliance team to ensure adherence to security frameworks (SOC 2, PCI DSS) • Build security automation and tooling to scale security practices • Respond to security incidents and conduct post-incident reviews
Job Requirements
- 5+ years of software engineering experience with a focus on security engineering or application security
- Strong proficiency in Go, with experience in other languages like Python, Java, or C++
- Experience securing cloud-native applications and infrastructure (AWS, GCP, Azure)
- Knowledge of database security, encryption, and access controls
- Experience with security frameworks and compliance requirements (SOC 2, PCI DSS)
- Understanding of threat modeling, security architecture, and secure coding practices
- Experience with database internals, distributed systems security, or infrastructure security
- Background in security tool evaluation, implementation, and automation
- Experience with Kubernetes security, container security, and cloud security posture management
- Knowledge of security monitoring, incident response, and vulnerability management
- Previous experience at a high-growth technology company or in a security engineering role
- Relevant security certifications (CISSP, CISM, CEH, etc.)
Benefits
- Employee equity
- Flexible hours
- Remote-first culture
- Diversity, equity and inclusion initiatives
- Support for disabilities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Serve as the primary authority for the security posture of Oklo’s information systems. • Implement, maintain, and continuously improve information system security controls in alignment with NIST 800-53 and NIST 800-171. • Ensure security requirements are embedded into system design, configuration, and operations across on-premises and cloud environments. • Implement, assess, and remediate system configurations against security baselines and hardening standards, including DISA STIGs and CIS Benchmarks, ensuring secure and compliant system configurations across servers, endpoints, and cloud resources. • Partner with IT and engineering teams to ensure secure architectures, access controls, encryption, and monitoring. • Oversee system-level security monitoring, logging, and alerting to detect and respond to security events. • Lead incident response activities, including investigation, containment, remediation, and post-incident reviews. • Coordinate vulnerability management activities, including scanning, remediation tracking, and validation. • Ensure timely application of security patches and configuration hardening across systems and platforms. • Own execution of security compliance activities related to various standards and contract requirements such as SOX, NIST and CMMC. • Build, Create and Maintain System Security Plans (SSPs), policies, procedures, and supporting security artifacts. • Conduct system risk assessments and track risks through mitigation, acceptance, or remediation. • Support internal and external audits and assessments, ensuring evidence readiness and corrective action tracking. • Enforce controls related to export-controlled data (DOE ECI), including access restrictions, segmentation, and secure data handling. • Develop, maintain, and enforce information security policies, standards, and procedures. • Ensure security documentation is accurate, current, and aligned with operational reality. • Provide clear, actionable guidance to system owners and users regarding security responsibilities and expectations. • Act as a trusted advisor to the Senior Manager of IT and Cyber on system security risks, gaps, and improvement opportunities • Partner with engineering, operations, and compliance teams to balance security, usability, and innovation • Communicate security risks, decisions, and requirements effectively to both technical and non-technical stakeholders
• Prevent and mitigate malicious cyber actions, whether intentional or accidental; • Analyze and evaluate network events and system anomalies in a SOC environment; • Analyze, create, and tune alerts generated by security appliances such as SIEM, IPS, FW, etc.; • Create and follow security playbooks for triage and escalation of security alerts; • Collaborate with Level 2+ analysts to research and investigate cybersecurity threats; • Maintain an investigative and curious mindset when approaching security events; • Knowledge of security tools to detect, prevent, and mitigate intrusions; • Handle incidents, requests, problems, and changes related to managed solutions; • Prepare analytical reports; • Support the development and maintenance of KPIs.
• Lead the execution of sales initiatives, programs, and activities to achieve revenue, growth, and market expansion goals • Own the financial health, operational budget, and P&L performance of the specialty sales organization • Lead sales pipeline management, providing accurate forecasting and lead generation initiatives to secure large-scale IT outsourcing deals • Drive solution-led selling across partner ecosystems including Microsoft, AWS, Google Cloud, and others • Spearhead the adoption of NTT DATA’s "Smart AI Agent Ecosystem," moving beyond simple automation to human-orchestrated autonomy in managed services • Design and implement repeatable, scalable solution plays that leverage our unified platform to outpace larger, traditional outsourcers • Authorize and drive solution design reviews to ensure technical feasibility, cost-efficiency (onshore/offshore balance), and alignment with client business outcomes • Direct and coach a matrixed team of individual contributors and directors, fostering a culture of innovation and operational excellence
• Ensure secure architectures for applications, APIs, and websites. • Implement and enhance secure CI/CD pipelines in GitLab (SAST, DAST, SCA, secrets). • Support teams in secure development (Secure SDLC). • Develop security automations for detection, incident response, and system hardening. • Work on multi-cloud security (AWS, Azure, GCP, OCI). • Promote a security culture and act as a technical reference.




