
Staff Security Engineer
Posted 2 hours ago

Posted 2 hours ago
This is a fully remote position, open to applicants in United States, +1 more state.
• Take ownership and expand application security across Redpanda’s C++ core streaming engine, Go cloud control plane, Console, and Rust/Go data-transform SDKs.
• Lead threat modeling sessions and conduct secure design evaluations for new product functionalities.
• Manage and optimize SAST, SCA/dependency scanning, secret scanning, and DAST for C++, Go, and Rust.
• Develop coverage-guided and protocol-aware fuzzing harnesses for the core engine and incorporate sanitizers.
• Perform secure code assessments in systems programming languages and eliminate various classes of vulnerabilities.
• Operate the PSIRT and manage coordinated vulnerability disclosures, including evaluating researcher reports, driving remediation, and publishing advisories and CVEs.
• Enhance software supply-chain security through dependency management, SBOMs, build provenance, and progress on SLSA.
• Create a security champions program alongside secure-by-default libraries, patterns, and guardrails.
• Define security requirements and influence security release gate criteria.
• Provide guidance on authentication, authorization/RBAC, encryption, audit logging, multi-tenant isolation, and the Agentic Data Plane.
• Elevate security standards through training, practical standards, collaborative engineering efforts, and AI-assisted development workflows.
• Collaborate with the Director of Information Security, infrastructure security engineer, platform engineering, and product engineering teams.
• Over 7 years of experience in application security, product security, or related fields.
• Proven experience leading AppSec initiatives end-to-end and influencing engineering teams without direct authority.
• Capability to review and analyze code in a systems programming language; proficiency in C++ or Rust is strongly preferred, with Go being advantageous.
• Strong understanding of memory safety, concurrency, use-after-free, buffer overflow, injection, and authorization vulnerabilities.
• Comfortable with the security risks associated with memory-unsafe code and willing to perform fuzz testing.
• Practical experience with SAST, SCA, secret scanning, and DAST methodologies.
• Experience in leading threat modeling and secure design reviews for complex systems.
• Working knowledge of dependencies, SBOMs, signing, SLSA, and secure CI/CD practices.
• Familiarity with AWS, GCP, or Azure security, particularly at the application layer, as well as Kubernetes security.
• Excellent written and verbal communication skills.
• Comfortable working in a globally distributed and asynchronous environment.
• Experience with fuzzing using libFuzzer, AFL++, or OSS-Fuzz, as well as sanitizers like ASan, UBSan, or MSan is a plus.
• A background in securing distributed systems, databases, or data infrastructure products is advantageous.
• Experience with PSIRT, CNA, bug bounty programs, or coordinated disclosure is a plus.
• Familiarity with compliance programs such as SOC 2, ISO 27001, HIPAA, or FedRAMP is beneficial.
• Contributions to open-source security or experience in handling vulnerabilities in public repositories is a plus.
• Salary ranges determined by role, level, and location.
• Individual base salary consideration based on job-related skills, location, experience, and relevant education or training.
• Access to the latest AI tools with a budget to utilize them.
• A people-first organization.
• A culture grounded in trust, transparency, communication, and kindness.
• A diverse, global team.
Oxfam America
Dragonfli Group
Akamai Technologies
CloudLinux
Get handpicked remote jobs straight to your inbox weekly.