Role overview

Senior Application Security Engineer

Requirements and responsibilities

Readable role content extracted into sections for faster review.

Details

  • Core Product Security: Perform deep-dive security reviews of our core Go-based applications and Kubernetes controllers, as well as the frontend user interface. With a targeted focus on avoiding privilege escalation within our multi-tenant architecture.
  • Threat Modeling: Lead the threat modeling process for new features, proactively identifying risks associated with shared GPU resources and multi-cloud environments.
  • Automated Security: "Shift left" by continuing to integrate security checks into our CI and developer workflows. Optimizing these checks for speed, ensuring security never becomes a bottleneck for engineering velocity. Separately, you will manage automated and manual scanning of our entire product stack.
  • Vulnerability Management: Own the lifecycle of security vulnerabilities from discovery to remediation. You will triage both external and internal reports, drive the resolution of critical issues across the engineering organization, and communicate effectively across stakeholders.
  • Feature Development: Everyone at the organization contributes to both the ideas and development of new features. Many of which are directly related to security topics such as container breakouts and isolation, pushing the envelope of what’s possible in constrained environments.
  • Developer training: Make complex topics easier to understand for all engineers, including new attack vectors and secure coding concepts.

This role could be a fit for you if you bring:

  • Experience: You have 5+ years in Application Security or Product Security, with a strong focus on containerized environments.
  • Kubernetes Depth: You have a deep understanding of Kubernetes architecture, RBAC, and container runtime security. You understand the specific risks of multi-tenancy.
  • Code Proficiency: You are comfortable reading and writing Go, which is the language of our core product. You can spot a vulnerability in a PR without relying solely on automated tools.
  • Modern Tech Mindset: You thrive in fast-paced cutting-edge environments. You are excited to solve novel problems related to AI and multi-tenant infrastructure.
  • Cognitive Flexibility: You view feedback as a learning mechanism, not a critique, and are willing to understand the unique needs and concerns of our customers.

Bonus points for:

  • Certifications: CKS (Certified Kubernetes Security Specialist) or OSCP.
  • AI/GPU Context: Experience securing AI workloads or GPU cloud infrastructure.
  • Automation Skills: Experience writing custom security tooling or automation scripts in Python or Go.
  • Documentation: A willingness to contribute to our public-facing security documentation and "Trust Center" to help our customers navigate compliance.

We offer the following benefits:

  • Competitive Salary: We offer a competitive compensation package, including equity.
  • Platinum-Level Insurance: Health, dental, vision, and life Insurance, including plans for you and eligible dependents (benefits vary depending on country).
  • Flexible Working Schedule: You have a doctor’s appointment or need to head to the supermarket to get groceries at 2pm? We won’t have an issue with that. To us, results matter more than clocking in and out at the same time every day.
  • Workplace Flexibility: We’re very flexible about where you work. We know things can change in life and we’re happy to adjust the work environment for you along the way.
Similar roles

Keep a backup shortlist.

Browse stack
FocusSenior Engineer SecurityRole area
Seniority signalSeniorCandidate level
StackKubernetes, Python, SalesforcePrimary skills
Location3 accepted countriesEligibility

Stack

Use these tags to compare similar remote roles.

Location eligibility

Candidates should apply only when their profile country is listed here.

Your profileCountry not setSign in to check your country against this role.

Hiring flow

WithMira shows the role, then sends candidates to the company application.

1Check role fit, stack, and location eligibility in WithMira.
2Open the company application page from the tracked apply link.
3Save the role or subscribe for similar opportunities before leaving.
Apply on company siteCompany siteOpen link