North AmericaFull TimeEngineering
Remotely
gorustkubernetessastdastfuzzingsbom
Job Description
📋 Description
- Lead threat modeling and secure design reviews for new product features across C++ engine, Go
- Own and tune application security testing (SAST, SCA, secret scanning, DAST) across C++, Go, and
- Build fuzzing harnesses for the core engine and run them continuously with sanitizers to surface
- Drive deep secure code review in systems languages and reduce vulnerabilities across engineering.
- Operate product security incident response (PSIRT) and coordinated vulnerability disclosure.
- Strengthen software supply chain with dependencies hygiene and build provenance.
🎯 Requirements
- 7+ years in application/product security or adjacent fields.
- Ability to review/rationalize code in C++ or Rust (Go is valuable) with focus on memory safety and
- Comfort with memory-unsafe code and fuzzing/sanitizer experience is a plus.
- Proficiency with AppSec toolchain (SAST, SCA, secret scanning, DAST) and risk-based prioritization.
- Experience leading threat modeling and secure design reviews for non-trivial systems.
- Knowledge of software supply-chain security (SBOMs, signing, SLSA) and secure CI/CD.
🎁 Benefits