The opportunity
You believe the secure path should be the easy path. You've spent your career where security and engineering meet, and you've learned that scanners nobody reads and gates nobody can pass don't make software safer, they make engineers route around you.
What you'll do
Own security automation across our CI/CD pipelines (GitHub Actions): SAST, SCA, secrets detection, and container scanning that runs fast and flags things worth fixing.
Build security into our golden path templates for Go, Rails, and Vue.js: services, so new services start secure by default.
Harden our software supply chain: dependency management, artifact signing, SBOM generation, and provenance for what we ship.
Implement and tune infrastructure-as-code scanning (Terraform) and Kubernetes: policy enforcement, catching misconfigurations before they reach an environment.
Coordinate vulnerability exposure remediation across all of Engineering,: including code vulnerabilities, infrastructure configuration changes, and patching.
Build vulnerability management automation that routes findings to owning: teams with context, deduplicates noise, and tracks remediation without spreadsheets.
What they're looking for
- + years of professional experience in software engineering, infrastructure, or security engineering
- + years focused on application security, security automation, or DevSecOps practice
- Hands-on experience integrating security tooling into CI/CD pipelines (GitHub: Actions strongly preferred): SAST, SCA, secrets detection, container scanning
- Proficiency with AWS and its security services (IAM, GuardDuty, Security Hub,: CloudTrail); you understand cloud identity well enough to design least-privilege access, not just audit it
- Experience with Kubernetes and infrastructure-as-code (Terraform preferred),: including policy-as-code enforcement
- Proficiency in at least one programming language (Go, Python, or Ruby: preferred); you build tooling, not just configure it
- Demonstrated ability to reduce security friction for engineers, with examples: of controls teams adopted willingly
- Strong written communication; you document as you build