We are looking for a hands-on security leader to shape product security across SaaS and customer-managed/on-premises platforms. Depending on experience, this position can be structured as a Principal Engineer role or an Engineering Manager role leading a small security team.
Key Responsibilities
- Define security architecture for new products, services, and features
• Lead secure design across SaaS, on-premises, cloud, Kubernetes, and container environments
• Design trusted and confidential computing capabilities, secure boot, hardware attestation, and workload isolation
• Own secrets, keys, credentials, encryption, rotation, and vault integrations
• Establish and manage secure SDLC practices, including code scanning, CI/CD security controls, artifact signing, and software supply-chain security
• Conduct architecture reviews, threat modelling, vulnerability management, and penetration testing
• Support compliance programs such as SOC 2 Type 2, ISO 27001, FIPS 140, NIST 800, and FedRAMP
• Partner with auditors, engineering, product, GRC, and customer-facing teams
• Prepare security whitepapers, design documents, and customer-facing security responses
• Contribute to security incident readiness, response processes, and program metrics
What We’re Looking For
- Strong experience in software, application, or product security
• Experience securing SaaS and on-premises/customer-managed software products
• Hands-on expertise in several areas, including:
– Cloud-native, Kubernetes, and container security
– Network security and tenant isolation
– Cryptography and secrets management
– Trusted or confidential computing
– Secure SDLC and software supply-chain security
- Experience implementing at least one major compliance framework such as SOC 2, ISO 27001, FIPS, FedRAMP, or NIST 800
• Experience managing vulnerability assessment and penetration-testing programs
• Strong technical leadership and written communication skills
• Ability to balance strong security controls with product delivery priorities
Good to Have
• Direct FedRAMP authorization experience
• Experience with GPU, HPC, or AI/ML infrastructure security
• Knowledge of TPMs, hardware attestation, SEV-SNP, TDX, or confidential computing
• Experience supporting enterprise customer security reviews and sales discussions