About the Role
We are seeking an experienced security professional to lead product security initiatives, integrate secure practices into the development lifecycle, and help maintain the integrity of our platform.
Responsibilities
- Lead security assessments across the product stack
- Identify and mitigate potential vulnerabilities in software design
- Collaborate with engineering teams to implement secure coding standards
- Perform regular code reviews with a focus on security
- Develop and maintain security testing procedures
- Respond to security incidents and coordinate resolution efforts
- Advise on secure architecture for new features and services
- Integrate security tools into CI/CD pipelines
- Monitor emerging threats and adjust defenses accordingly
- Create documentation for security policies and controls
- Support compliance with data protection regulations
- Conduct internal security training sessions for developers
- Evaluate third-party components for security risks
- Improve authentication and authorization mechanisms
- Assist in penetration testing coordination
- Maintain up-to-date knowledge of security trends
- Work closely with product managers on security requirements
- Ensure secure handling of customer data
- Contribute to threat modeling exercises
- Promote a culture of security awareness across teams
Nice to Have
- Experience with open-source software development
- Knowledge of containerization and orchestration security (Docker, Kubernetes)
- Familiarity with infrastructure as code security practices
- Previous work in developer tools or automation platforms
- Contributions to security communities or public disclosures
- Certifications such as CISSP, OSCP, or CISM
Compensation
Competitive salary based on experience and location
Work Arrangement
Remote
Team
Distributed team focused on building an open-source automation platform
Our Tech Stack
- We build on Node.js and TypeScript, with a focus on extensibility and integration capabilities
- Our infrastructure uses Docker and Kubernetes, hosted across multiple cloud providers
- Security tools are integrated into GitHub Actions and automated testing pipelines
Culture & Values
- We value transparency, ownership, and continuous learning
- Team members are encouraged to propose and lead security improvements
- We operate with minimal hierarchy and emphasize trust and accountability
Available for select locations