Senior Product Security Engineer
$157,000–$184,000 year
Remote · United States
Job Summary
Senior Product Security Engineer who will embed in secure software pipelines, building and hardening CI/CD processes, enforcing software supply chain security (signing artifacts, SBOMs, provenance attestation), and strengthening cloud-native security (Kubernetes, IAM, policy standards) across GCP/AWS environments. Requires hands-on expertise in Go or Python, Kubernetes production experience, cloud security tooling, and a strong grasp of OWASP/NIST standards. Base salary range provided; remote-friendly with US remote options.
Required Qualifications
- 5+ years in software engineering, security engineering, or a combined role with meaningful hands-on security responsibility
- Strong proficiency in Go or Python
- Deep, hands-on experience with Kubernetes in production (cluster hardening, RBAC, network policies, admission controllers)
- Practical expertise with GCP and/or AWS: IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center, AWS Security Hub)
- Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar)
- Fluency with container security: image scanning, distroless/minimal base images, runtime security
- Experience with software supply chain security tooling and frameworks (Sigstore, SLSA, SBOM generation)
- Solid understanding of OWASP, NIST, and cloud security frameworks and how to apply them pragmatically.
Desired Qualifications
- 5+ years of experience in software engineering, security engineering, or a related role with hands-on security responsibilities
- Strong proficiency in Go or Python
- Production experience with Kubernetes (cluster hardening, RBAC, network policies, admission controllers)
- Practical experience with AWS and/or GCP (IAM, workload identity, secrets management, security services)
- Proven track record designing and securing CI/CD pipelines (GitHub Actions, Cloud Build, Tekton, or similar)
- Fluency with container security (image scanning, distroless/minimal base images, runtime security)
- Experience with software supply chain security tooling (Sigstore, SLSA, SBOM generation)
- Knowledge of OWASP, NIST, and cloud security frameworks
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.