Product Security Engineer, Server
$106,000–$209,000 year
On-siteNew York City, New York, United States
Job Summary
Lead security strategy and drive improvement for program areas including fuzzing, threat modeling, secrets management, and container security. Support engineering teams with risk analysis and proof of concept during security incident response. Partner closely to design and implement security controls across software and systems, while researching new attacks and performing assessments like architecture reviews, code reviews, and penetration testing. Serve as a security subject matter expert for the tech stack, educating the engineering org through CTFs, lunch-and-learns, and mentorship. Define architecture, patterns, and processes that make security the easiest path for Server Engineering.
Required Qualifications
- 3 years of experience in application security, software security, or product security
- Demonstrated experience in C++ programming, performing security assessments on low-level codebases, and implementing remediation strategies for memory-related security flaws such as buffer overflows and memory leaks
- Scripting experience and ability to contribute code back to our environments
- Comfortable leading threat modeling and being a security ambassador to other engineering teams
- Communicate complex technical issues in a simple manner that builds trust with a variety of audiences
- A strong sense of ownership and delivery
- Can facilitate a conversation rather than dominate it
- Skilled at providing collaborative, actionable feedback, not just a list of flaws
Desired Qualifications
- Subject matter expertise in database security, or data security
- Knowledge of database engines, database internals, or applied cryptography
- Experience contributing or partnering with security researchers to identify vulnerabilities that eventually are published CVEs or administrative responsibilities of a CNA
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.