
Senior Security Analyst
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in Washington.
• Conduct threat modeling for application designs and solutions while providing security risk assessments.
• Offer technical expertise in software and network architecture across infrastructure, applications, personnel, and processes.
• Work collaboratively with product managers, designers, and engineers to threat model and design secure, resilient systems.
• Identify trade-offs in solutions and suggest efficient designs that fulfill both functional and security requirements.
• Provide practical remediation guidance to development teams.
• Promote an internal security culture through developer training and internal Capture The Flag (CTF) events.
• Mentor software engineering teams on best practices in security.
• Assist in overseeing the vulnerability management program.
• Help engineers grasp the implications of security incidents and vulnerabilities.
• Develop security tools and automation to enhance Product Security practices.
• Foster the adoption of security-focused architecture, patterns, and processes throughout engineering.
• Integrate custom security tools into engineering workflows.
• Report to the Manager of Secure Design and collaborate with security teams at DigitalOcean.
• Proven experience in driving architectural changes or managing complex cross-team initiatives to address security vulnerabilities.
• Strong ability to communicate security topics and vulnerability classifications clearly, including the OWASP Top Ten.
• Capability to provide actionable guidance to product teams.
• Experience working alongside internal engineering teams to resolve security issues across the entire technology stack.
• Proficient understanding of virtualized environments, containerization, and continuous integration and delivery methodologies.
• A minimum of 3 years of experience advising software teams on secure architecture design is preferred.
• Familiarity with creating or reviewing threat models and developing malicious user, attacker, and abuse/misuse scenarios is preferred.
• Knowledge of hardware and software supply chain security is preferred.
• Familiarity with object-oriented and functional programming concepts, particularly in Go, JavaScript, Rust, or C, is preferred.
• Reimbursement for relevant conferences, training, and educational opportunities.
• Access to LinkedIn Learning with over 10,000 courses available.
• Employee Assistance Program.
• Local employee meetups.
• Flexible time-off policy.
• Eligibility for bonuses based on individual and company performance.
• Equity compensation, including equity grants upon hire.
• Employee Stock Purchase Program.
• Competitive benefits that vary according to local regulations and preferences.
DigitalOcean
Ascension
Arbiter
Selbetti Tecnologia
Get handpicked remote jobs straight to your inbox weekly.