Job Closed

This listing is no longer active.

Mirantis logo
Mirantis

Strategic open source infrastructure for containers and virtual machines.

Senior Product Security Engineer

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 501-1,000H1B SponsorCompany SiteLinkedIn

Location

Oregon

Posted

101 days ago

Salary

0

Seniority

Senior

Job Description

Senior Product Security Engineer

Mirantis

• Secure Products & Infrastructure: Design, implement, and maintain security controls across applications, infrastructure, and CI/CD pipelines. • Embed security requirements aligned with SOC 2, ISO 27001, and internal standards. • Drive adoption and operationalization of SAST, DAST, container scanning, IaC security, and dependency analysis tooling. • Integrate automated security testing into the SDLC to enable secure-by-design development. • Offensive Security & Vulnerability Management: Lead application security reviews, threat modeling, vulnerability assessments, and penetration testing. • Validate and prioritize findings based on exploitability and business impact. • Partner with engineering teams to ensure timely, measurable remediation. • Proactively identify and demonstrate security weaknesses to improve overall product resilience. • Incident Response & Risk Reduction: Support investigation of product and infrastructure security incidents. • Contribute to root cause analysis and durable remediation strategies. • Identify systemic control gaps and implement long-term risk mitigation measures. • Compliance & Assurance: Support product-level security reviews and audit activities. • Coordinate evidence collection and control validation for SOC 2, ISO 27001, and enterprise requirements. • Translate compliance requirements into actionable engineering controls. • Cross-Product Security Leadership: Develop and maintain security expertise across multiple Mirantis products. • Standardize security practices and tooling across teams. • Strengthen program scalability and reduce single-point-of-failure risk. • Security Advocacy & Enablement: Champion secure design principles and modern application security practices. • Provide actionable guidance during architecture and code reviews. • Drive continuous improvement and automation across the SDLC.

Job Requirements

  • 5+ years of experience in product security, application security, or security engineering.
  • Strong knowledge of common vulnerabilities (OWASP Top 10, SANS Top 25) and secure development practices.
  • Demonstrated experience with manual penetration testing, threat modeling, and exploitation techniques.
  • Hands-on experience with security tooling and automation, including: SAST / DAST tooling and CI/CD integration
  • Container image scanning (e.g., Trivy, Grype, Anchore)
  • IaC security (e.g., Terraform, Helm, KICS, Checkov)
  • Dependency and software supply chain security tools
  • Experience with vulnerability management platforms and remediation workflows.
  • Experience working with containerized environments, Kubernetes, and cloud platforms.
  • Proven ability to integrate and automate security controls within CI/CD pipelines.
  • Strong collaboration and communication skills across engineering and product teams.
  • Experience supporting SOC 2, ISO 27001, or similar compliance frameworks.
  • Relevant certifications (OSCP, OSEP, OSWE, GPEN, GWEB, GWAPT, GCSA) strongly preferred.
  • Proficiency in scripting or programming (Go, Python, or similar) is a plus.

Benefits

  • Competitive compensation package
  • Strong benefits plan

Related Categories

Related Job Pages

More Security Engineer Jobs

Calix logo

Information Security GRC Intern

Calix

To enable broadband service providers of all sizes to simplify, innovate and grow.

Security Engineer101 days ago
OtherRemoteTeam 1,001-5,000Since 2000H1B Sponsor

• Assist in reviewing and updating security controls and documentation aligned with key security and compliance frameworks. • Assist with control gap assessments and documenting mitigation strategies. • Help prepare for security audits by collecting evidence to ensure compliance with industry standards. • Assist in maintaining GRC documentation, including security policies and standards. • Support vendor security risk assessments to ensure third-party compliance with company security standards. • Assist the team in building and maintaining metrics dashboards and reports. • Work with various business units to ensure controls are adequate, appropriate, and effective.

United States
$18 - $29 / hour
Job Closed
Full TimeRemoteTeam 10,001+H1B Sponsor

• Lead incident response and internal investigations through their full lifecycle, acting as a central point of coordination • Coordinate Digital Forensics and Incident Response (DFIR) activities with security teams, leadership, and external authorities when required • Aggregate and analyze security logs from multiple sources, producing clear and actionable reports for stakeholders • Develop and evolve the team vision aligned with company strategy for incident detection and response • Manage team capacity and priorities to ensure effective use of resources and timely resolution of incidents • Represent the SOC and DFIR team with internal partners across Security Operations and Security Risk Management • Foster a culture of trust , open communication, and collaborative problem-solving • Support team growth by identifying skill gaps, anticipating future needs, and proposing relevant training

Canada
Job Closed
Bird logo

Senior IT and Security Manager

Bird

On a mission to provide eco-friendly transportation for everyone. Safety and compliance first in 450+ cities. NYSE: BRDS

Security Engineer101 days ago
OtherRemoteTeam 201-500Since 2017H1B Sponsor

• Lead high-performing IT team through recruitment, training, mentoring, and leadership. • Develop and execute a comprehensive IT strategy aligned with business objectives. • Provide visionary leadership, fostering innovation and continuous improvement. • Support and manage vendors through security audits required for PCI, SOC2, and.or ISO27001, and SOX • Collaborate with cross-functional teams to identify business needs and opportunities. • Establish and enforce infosec policies, procedures, and best practices. • Assess, manage, and mitigate security risks; swiftly resolve incidents. • Conduct security audits to ensure compliance with regulations and standards. • Oversee IT infrastructure, ensuring scalability, availability, and performance. • Manage vendor relationships, negotiate tech contracts. • Support team growth and development; promote collaborative and inclusive culture.

United States
Job Closed
OtherRemoteTeam 501-1,000Since 2010H1B No Sponsor

• Serve as the Security Lead and Subject Matter Expert (SME) for all environments, including cloud infrastructure, and on-premises systems. • Continuously assess and evolve the organization’s security posture—driving program maturity through strategic assessments, road mapping, stakeholder alignment, and project execution. • Monitor the external threat landscape to identify emerging attack vectors, vulnerabilities, and adversary tactics—translating threat intelligence into actionable insights that inform security strategy, initiatives and controls. • Ensure security practices and controls align with regulatory requirements, including FDA and HIPAA, and fulfill the requirements and obligations of the HIPAA security officer. • Support commercial functions by responding to customer cybersecurity due diligence questionnaires and security assessments—articulating Outset’s security posture, controls, and compliance practices directly to Customers. • Lead the vendor security risk assessment process—evaluating third-party partners for compliance with Outset’s security standards, identifying potential risks, and ensuring appropriate controls are in place. • Conduct technical evaluations of system architecture with a focus on security design and compliance, leveraging frameworks such as NIST CSF and NIST SP 800-53. • Provide strategic leadership in identifying, assessing, and mitigating information security risks; ensure alignment with internal policies and external standards. • Monitor emerging threats and lead the organization’s response to security incidents, serving as the primary control point and convening the Incident Response Team to investigate, contain, and resolve events. • Develop, maintain, and enforce enterprise cybersecurity policies, standards, and procedures, ensuring alignment with regulatory requirements, industry frameworks, and organizational risk tolerance. • Influence technology and architecture decisions as a key member of the IT leadership team.

United States
$185K - $251K / year
Job Closed