Responsibilities
- Design, implement, and manage security tools within CI/CD pipelines, including static and dynamic analysis, software composition analysis, secrets detection, container scanning, and infrastructure-as-code reviews.
- Define processes for handling, prioritizing, and resolving security findings while collaborating with development teams to maintain productivity and reduce friction.
- Implement policy-as-code and enforce pre-merge security checks tailored to risk levels across code repositories.
- Architect and deploy production cloud security systems, primarily on Google Cloud Platform, with support for future multi-cloud environments.
- Establish core security controls such as network segmentation, workload identity, secrets handling, encryption for data in transit and at rest, and least-privilege access using native and third-party tools.
- Deploy and manage cloud security posture monitoring and workload protection platforms to detect and prevent misconfigurations and threats.
- Develop and maintain secure, standardized infrastructure modules in Terraform used by all engineering teams.
- Integrate security protections directly into platform layers so secure configurations are automatic and default.
- Define and enforce secure configurations for Kubernetes, container engines, and serverless computing environments.
- Operate and refine the SIEM system and security data pipeline, setting up log sources, detection rules, and alerting processes from scratch.
- Implement code-based detection methodologies and optimize alerts to maximize actionable insights while minimizing noise.
- Create monitoring dashboards and reports that provide real-time visibility into system security posture for security and executive teams.
- Improve technical incident response capabilities, including runbook development, on-call structure, simulation exercises, and post-event analysis.
- Act as a lead responder during security incidents, coordinating actions across technical and business units.
- Manage the full lifecycle of vulnerability identification, prioritization, and remediation across applications, containers, and cloud infrastructure.
- Enforce vulnerability remediation timelines, collaborate with engineering to meet them, and report progress to leadership.
- Work closely with Engineering and Security teams to convert compliance standards like SOC 2, HIPAA, ISO 27001, FedRAMP, and NIST 800-53 into effective technical controls.
- Collaborate with Product and Engineering teams to embed security into the development lifecycle by design.
- Guide junior security and engineering staff in secure coding, threat modeling, and cloud security best practices.
- Develop and share reusable security patterns, runbooks, and components that scale with organizational growth.
Other
Applicant must be a U.S. citizen and eligible to obtain a U.S. security clearance.