We're looking for a Product Security Engineer to focus on hands-on design and implementation of security-related software, embedding automated controls into CI/CD pipelines, and collaborating with internal teams to meet/exceed CMMC Level 2 requirements.
Requirements
- 5+ years in software or security engineering, with at least 3+ years in security-focused roles
- Experience with secure cloud systems (AWS), CI/CD security, and compliance efforts (e.g., NIST, CMMC, or FedRAMP)
- Proficiency in container security (Docker/Kubernetes), security tools (e.g., Trivy, Snyk, Falco, OPA), and programming languages for tooling (Python, Rust)
- Understanding of modern attacks and defenses
- Security Acumen: Knowledge of common threats (e.g., injection, lateral movement), controls (NIST 800-53 mappings), DevSecOps practices, SBOMs, zero-trust principles, and SIEM-integrated logging
Benefits
- Generous Paid Time Off
- 401(k) Plan
- Health and Wellness Reimbursement Program
- Employee Stock Purchase Program (ESPP)
- Family Leave
- Fitness Reimbursement
- Employee Referral Program
- Healthy Snacks & Beverages in Every Office