CrowdStrike logo
CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Engineer II, Software Assurance, Product Security

Security EngineerSecurity EngineerFull TimeRemoteJuniorTeam 5,001-10,000Since 2011H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

1 day ago

Salary

$100K - $145K / year

Seniority

Junior

Bachelor Degree1 yr expExperience acceptedEnglishJavaScriptLinuxPythonSDLCUnixGo

Job Description

Engineer II, Software Assurance, Product Security

CrowdStrike

• Help us protect CrowdStrike and its customers from the most advanced threats by assessing, designing, and implementing security controls and systems associated with all aspects of the software supply chain. • CrowdStrike's Product Security team breaks the mold of traditional internal security, and focuses on active threats to CrowdStrike's products. • As a Security Engineer II, you will focus on securing our open-source footprint and upstream dependencies. • You will perform technical security assessments of GitHub organizations and open-source integrations, monitor for malicious packages, create tooling for known gaps, and create automations to make operations more efficient. • Additionally, you will collaborate on cross-cutting projects to further harden internal and public-facing source code repositories against active and emerging threats.

Job Requirements

  • Experience working in an engineering role implementing, supporting, and monitoring software security systems.
  • Strong working experience with GitHub, including repository administration, GitHub Actions, branch protection rules, and access management.
  • Familiarity with other source control management tools (e.g., BitBucket, GitLab)
  • Familiarity with artifact storage tools like Artifactory and S3.
  • Experience identifying and mitigating open-source risks (SCA, dependency management, licensing risks).
  • Experience working with and securing configurations of Linux and/or other Unix-like variants.
  • Proficiency in one or more common scripting languages, such as Python, Golang, Shell, or JavaScript, to automate security checks.
  • Domain knowledge of the software development lifecycle (SDLC), secure coding practices, code reviews, and source control security.
  • Collaborative mindset with experience contributing to cross-team security projects and initiatives.
  • Experience utilizing AI technologies to enhance decision-making, streamline workflows, or automate vulnerability triage.
  • Efficient communicator with strong writing skills, comfortable working in a remote environment.

Benefits

  • Health insurance
  • 401(k)
  • Paid time off
  • Competitive vacation and holidays for recharge
  • Professional development opportunities
  • Paid parental and adoption leaves

Related Categories

Related Job Pages

More Security Engineer Jobs

Role Description Compliance ist für dich kein Selbstzweck. Vielmehr möchtest du Strukturen entwickeln, die Vertrauen schaffen und gleichzeitig schnelle Entscheidungen ermöglichen. Du verstehst Informationssicherheit als Wettbewerbsvorteil und Governance als Fundament für nachhaltiges Wachstum. Du denkst strategisch, arbeitest pragmatisch und verlierst auch bei komplexen regulatorischen Anforderungen nie den Blick für das Wesentliche. Auditoren überzeugst du mit belastbaren Nachweisen, interne Teams mit sinnvollen Lösungen und unsere Kunden mit Professionalität und Kompetenz. Wir sind ISO 27001- und TISAX-zertifiziert und entwickeln unsere Assurance-Landschaft konsequent weiter. Der Aufbau eines internen Kontrollsystems nach ISAE 3402 / IDW PS 951 läuft bereits, SOC 2 Type II ist der nächste große Meilenstein. Genau hier kommst du ins Spiel. Deine Mission: - Du übernimmst die fachliche Verantwortung für Compliance und Information Security bei instellix und entwickelst unsere Governance-Landschaft konsequent weiter. - Gemeinsam mit unserer Informationssicherheitsbeauftragten stellst du sicher, dass unsere Sicherheits- und Compliance-Standards nicht nur Audits bestehen, sondern unseren Kunden jeden Tag Vertrauen geben. - Dabei arbeitest du eng mit Engineering, Product, People, Finance und der Geschäftsführung zusammen und sorgst dafür, dass Compliance als Enabler verstanden wird – nicht als Hindernis. Was gehört dazu? - Du entwickelst unser Compliance-Programm strategisch weiter und übernimmst die fachliche Verantwortung für unseren Compliance- und Information-Security-Bereich. - Du verantwortest die kontinuierliche Weiterentwicklung unseres Informationssicherheitsmanagementsystems nach ISO 27001:2022 – von Management Reviews über Zielplanung bis hin zu Überwachungs- und Rezertifizierungsaudits. - Du baust unser internes Kontrollsystem nach ISAE 3402 / IDW PS 951 weiter aus, etablierst belastbare Nachweis- und Evidenzprozesse und koordinierst die Zusammenarbeit mit Wirtschaftsprüfern. - Du führst unser SOC-2-Programm ein und steuerst sämtliche Aktivitäten von der System Description bis zur erfolgreichen Type-II-Prüfung. - Du entwickelst unsere Security Governance kontinuierlich weiter – von Richtlinien über Vendor-Management bis hin zu organisatorischen und technischen Sicherheitsmaßnahmen. - Du beobachtest regulatorische Entwicklungen wie NIS2, EU AI Act oder neue Compliance-Anforderungen und übersetzt sie in praktikable Maßnahmen für unser Unternehmen. - Du unterstützt unseren Vertrieb bei Enterprise-Kunden, beantwortest Security-Fragebögen, begleitest Kundenaudits und bist kompetente Ansprechperson für alle Security- und Compliance-Themen. - Du übernimmst als Senior Verantwortung über deine eigenen Aufgaben hinaus. Du hinterfragst bestehende Prozesse, entwickelst Strukturen weiter und bist Sparringspartner für Management und Fachbereiche. Qualifications - Du verfügst über mindestens fünf Jahre Berufserfahrung im Bereich Information Security Governance, IT-Compliance oder IT-Audit – beispielsweise in einer Wirtschaftsprüfungsgesellschaft, einer Beratung oder einem SaaS-Unternehmen. - Du hast praktische Erfahrung mit mindestens zwei relevanten Frameworks wie ISO 27001, ISAE 3402 / IDW PS 951, SOC 2 oder TISAX und idealerweise bereits Kontrollsysteme aufgebaut oder Audits verantwortlich begleitet. - Du verfügst über ein solides technisches Verständnis und kannst mit Engineering-Teams auf Augenhöhe über Cloud-Architekturen, Zugriffskonzepte, Change Management oder Verschlüsselung sprechen. - Du kommunizierst sicher mit Auditoren, Wirtschaftsprüfern, Enterprise-Kunden und internen Stakeholdern und schaffst es, komplexe Anforderungen verständlich zu vermitteln. - Du arbeitest strukturiert, eigenverantwortlich und lösungsorientiert. Statt Prozesse lediglich zu verwalten, entwickelst du sie aktiv weiter. - Du verstehst Compliance als Business Enabler. Dein Anspruch ist es, Anforderungen so umzusetzen, dass sie Sicherheit schaffen, ohne unnötige Bürokratie zu erzeugen. - Sehr gute Deutsch- und Englischkenntnisse in Wort und Schrift runden dein Profil ab. Requirements - Zertifizierungen wie CISA, CISM oder ISO 27001 Lead Implementer bzw. Lead Auditor sind ein Plus, kein Muss. - Erfahrung mit Compliance-Automatisierungslösungen wie Vanta oder Drata. - Kenntnisse zu GoBD, Datenschutz, NIS2 oder dem EU AI Act. Benefits - Gestaltung statt Verwaltung – Du übernimmst eine neu geschaffene Schlüsselrolle mit direkter Berichtslinie an die Geschäftsführung und großem Gestaltungsspielraum. - Starkes Fundament – Du baust nicht bei null auf. Ein zertifiziertes ISMS, etablierte Prozesse, eine klare Roadmap und eine erfahrene Informationssicherheitsbeauftragte bilden die Basis für deine Arbeit. - Innovatives Produkt – Du arbeitest mit an unserer SaaS-Plattform instellix, die den stark wachsenden Markt für Subscription Management, Billing, Payment und Accounting nachhaltig verändert. - Kollegiale Kultur – Unsere Zusammenarbeit basiert auf Vertrauen, Eigenverantwortung, Verbindlichkeit und dem gemeinsamen Anspruch, die beste Lösung zu finden. - Work-Life-Balance – Mit 100 % Remote-Arbeit innerhalb Deutschlands sowie flexiblen Arbeitszeiten ohne Kernzeiten kannst du Beruf und Privatleben optimal verbinden. - Teamevents – Obwohl wir deutschlandweit verteilt arbeiten, kommen wir regelmäßig zusammen. Ob Sommerfest, Offsites oder Weihnachtsfeier – wir investieren bewusst in persönliche Begegnungen. - Freiraum – Du erhältst die Freiheit, Ideen einzubringen, Verantwortung zu übernehmen und nachhaltige Veränderungen umzusetzen. Next Steps Wenn du Compliance nicht als Selbstzweck, sondern als strategischen Erfolgsfaktor verstehst und Lust hast, den nächsten Reifegrad unserer Governance-Landschaft aktiv mitzugestalten, freuen wir uns auf deine Bewerbung. Sende uns deinen Lebenslauf, relevante Zeugnisse sowie – wenn du möchtest – ein Anschreiben. Teile uns außerdem deine Verfügbarkeit und deine Gehaltsvorstellung mit. Wir freuen uns darauf, dich kennenzulernen.

Germany
Full TimeRemoteTeam 51-200

Role Description We're looking for a highly motivated Staff Security Engineer to join our DevSecOps team and help build and operate the security foundation of Nue's platform and engineering systems. This is not a policy or analyst role. We want someone who is hands-on, writes code, automates security controls, improves infrastructure, hardens systems, and helps engineers ship safely at speed. You'll work at the intersection of software engineering, cloud infrastructure, security operations, and developer enablement. You'll partner closely with Product Engineering, Platform, and DevSecOps teams to reduce real risk through practical engineering. If you're passionate about securing cloud-native systems, building internal tooling, improving detection and response, and making security a force multiplier for engineering, this is the role for you. Responsibilities - Drive secure-by-default patterns across the organization through reusable libraries, templates, guardrails, and paved-road workflows, improving security posture across cloud infrastructure, the application stack, and developer workflows. - Lead practical threat modeling for new product capabilities, platform changes, and high-risk workflows, translating findings into clear engineering actions. - Help define the security tooling strategy across application security, cloud security, detection, and developer workflows, evaluating and integrating tools that meaningfully reduce risk without slowing delivery. - Improve software supply chain security across build systems, dependencies, container images, secrets, and deployment processes. - Design, build, and operate security automation and production-quality tooling for identity and access management, secrets management, vulnerability management, and policy enforcement. - Harden AWS environments, containerized workloads, and CI/CD pipelines, using AI-assisted tooling to accelerate work where it genuinely helps. - Build and maintain detection and alerting for meaningful security events across endpoints, cloud infrastructure, application logs, audit trails, and identity systems. - Partner with engineering teams to review architecture, application design, infrastructure changes, and operational patterns with a focus on reducing exploitable risk. - Support compliance and audit needs through engineering-driven controls, evidence automation, logging, and repeatable operational practices. - Own hands-on incident response, including triage, containment, root cause analysis, remediation, and post-incident follow-through. - Participate in on-call rotations for high-severity security and platform incidents and build and test response procedures for scenarios such as credential compromise, privilege escalation, and exposed secrets. Qualifications - Bachelor's degree in Computer Science, Engineering, or equivalent practical experience. - 8+ years of experience across software engineering, infrastructure engineering, platform engineering, SRE, DevOps, security engineering, or related roles in production SaaS environments. - 3+ years of hands-on experience in security engineering, platform security, cloud security, or related security-focused roles. - Strong hands-on experience securing cloud-native environments on AWS. - Proven ability to write code for automation, integrations, internal tooling, and operational workflows using languages such as Python, Go, JavaScript, or Bash. - Experience operating in a DevSecOps or platform-adjacent model where security is embedded into delivery pipelines and engineering workflows. - Strong experience with identity and access management, secrets handling, key management, logging, auditability, and least-privilege design. - Experience building or operating security controls for CI/CD, infrastructure as code, containerized systems, and developer platforms. - Practical experience with security monitoring, detection engineering, alert tuning, and incident response. - Ability to assess real-world risk and prioritize pragmatic fixes over theoretical perfection. - Experience partnering with engineering teams to improve security architecture, code patterns, infrastructure posture, and operational readiness. - Demonstrated ability to use AI-assisted development tools to accelerate investigations, automate repetitive work, and improve engineering effectiveness while maintaining strong judgment. - Comfortable working in a fast-paced startup environment with a small, high-impact team. - Excellent communication and collaboration skills, able to explain trade-offs clearly and drive consensus without becoming a bottleneck.

United States

Information Security Officer

PROMOS consult

Bereits 1998 gegründet, zählt PROMOS consult zu den führenden Beratungs- und Systemhäusern, das Softwarelösungen speziell für die Wohnungs-, Bau- und Immobilienwirtschaft entwickelt. Seit vielen Jahren sind wir innovativ und arbeiten am Puls der Zeit. Das Portfolio setzt sich aus einem breiten Spektrum an Tools für das professionelle Immobilienmanagement zusammen – von der App über digitale Workflows in SAP® bis zum Full-Service im Rechenzentrum. Neugierig? Dann werde Teil unserer Vision von einer digitalisierten Zukunft!

Role Description - Gestaltung, Weiterentwicklung und Verbesserung von Informationssicherheit in einem Unternehmen - Analyse von Risiken und Entwicklung pragmatischer Lösungen zur Erhöhung des Sicherheitsniveaus - Erstellung von Richtlinien, Standards und Sicherheitskonzepten - Beratung von Kolleginnen und Kollegen sowie Zusammenarbeit mit unterschiedlichen Fachbereichen - Begleitung von Projekten und Veränderungen aus Sicht der Informationssicherheit - Durchführung von Audits, Reviews und Sicherheitsbewertungen - Vermittlung von Sicherheitswissen durch Schulungen und Awareness-Maßnahmen - Beobachtung neuer gesetzlicher, regulatorischer und technologischer Entwicklungen im Bereich Informationssicherheit Qualifications - Studium oder vergleichbare Qualifikation im Bereich Informationssicherheit, IT, Wirtschaftsinformatik, Informatik oder einem ähnlichen Fachgebiet - Erste praktische Erfahrungen im Bereich Informationssicherheitsmanagement (ISMS) - Interesse an Informationssicherheitsstandards wie ISO 27001 und ISO 27002 - Gutes technisches Grundverständnis von IT-Systemen und Prozessen - Interesse an Themen wie Datenschutz, Compliance, NIS2 und regulatorischen Anforderungen - Strukturiert, zuverlässig und eigenverantwortlich arbeitend - Freude an der Kommunikation mit unterschiedlichen Ansprechpartnern und Wissen zu vermitteln - Wunsch nach kontinuierlicher fachlicher und persönlicher Weiterentwicklung Benefits - Flexible Arbeitszeiten und die Möglichkeit, wo du möchtest zu arbeiten: in unseren Büroräumen, im Home-Office oder mobil in und außerhalb Deutschlands - 30 Tage Urlaub, eine 39 Stunden-Woche bei Vollzeit oder individuelle Teilzeitmodelle - Faires und branchenorientiertes Gehalt, das deiner Erfahrung und Qualifikation entspricht - Ausgewogenes Programm rund um health@PROMOS, wie z.B. Urban Sports-Mitgliedschaft, JobRad, monatliche Gesundheitsangebote und Zuschuss zur Arbeitsplatzbrille - Regelmäßige Teamevents sowie jährliche Sommer- und Weihnachtsfeste - Weitere Benefits, die PROMOS zum Great Place to Work machen Company Description Bereits 1998 gegründet, zählt PROMOS consult zu den führenden Beratungs- und Systemhäusern, das Softwarelösungen speziell für die Wohnungs-, Bau- und Immobilienwirtschaft entwickelt. Seit vielen Jahren sind wir innovativ und arbeiten am Puls der Zeit. Das Portfolio setzt sich aus einem breiten Spektrum an Tools für das professionelle Immobilienmanagement zusammen – von der App über digitale Workflows in SAP® bis zum Full-Service im Rechenzentrum. Neugierig? Dann werde Teil unserer Vision von einer digitalisierten Zukunft!

Germany
DYOPATH logo

Security Consultant – vCISO

DYOPATH

Driving Your Organizations's PATH to success.

Full TimeRemoteTeam 501-1,000Since 2020H1B Sponsor

• Serve as the primary security advisor for client organizations • Develop and lead enterprise security strategies, roadmaps, and governance frameworks • Translate technical risk into business and financial impact for executive and board-level audiences • Lead incident response planning, tabletop exercises, and breach investigations • Conduct risk assessments and maturity evaluations aligned to NIST, CIS, ISO, and other frameworks • Build and mature security programs, policies, and compliance initiatives • Establish and guide vendor risk and third-party risk programs • Deliver regular executive reporting on security posture, risk trends, and program progress • Partner with IT, architecture, and business leaders to embed security into operations • Stay ahead of emerging threats, technologies, and regulatory requirements

Mexico
$500K - $550K / year