Security Architect

Remote | San Francisco Bay Area preferred

Level Home

Keep your home design & keys with Level's invisible smart locks. Featuring unparalleled craftsmanship & a discreet, reliable, & secure solution for your…

View company page

About the company:
 
Founded by ex-Apple Product and Engineering leaders, Level is redefining the smart home with technology that is simple, intuitive, useful, and invisible. We recently raised $100M in funding, and we're looking to build an internal Security function.
 
At Level, we take a unique approach to designing products - one that shifts focus from what we make to how we make it and who we make it for. It’s an approach that results in elegant and unique solutions, raising the bar for the entire smart home ecosystem.
 
It’s also an approach that has led to our partnerships with AppleAmazon (including Ring integration), Walmart, and other industry leaders – assuring that our products provide solutions that align with the technology choices and preferences of our customers.
 
 
About the role:
 
We are seeking a DevSecOps Architect, and/or hands-on Security Manager to build and maintain a prioritized security roadmap to address security gaps and improve security practices.

 

Responsibilities:

  • Take ownership of security tools to build tracking and reporting capabilities to mitigate or eliminate risks
  • Build Threat Models and analyze security weaknesses in infrastructure deployments, pipelines and tech stack
  • Review vulnerability reports, deployments, misconfigurations and tool findings for compliance against ISO/SOC 2
  • Analyze security incidents from MDR/IDS/IPS  to identify root causes, trends, and patterns and propose improvements or mitigating measures based on findings
  • Define and maintain a security reference architecture that provides best practices and design guidance, roadmaps, and key security considerations for all major domains (i.e., IAM, privacy, cloud platforms, infrastructure, applications, database, etc.)
  • Help define and maintain security guidelines and corporate standards
  • Manage projects related to security tasks and issues on a day to day basis
  • Work with DevOps and Engineering teams to build and improve security posture
  • Work with Legal and Audit teams to define technical and regulatory requirements for security tools
  • Provide guidance and training to diverse groups and senior leaders within the organization and evangelize DevSecOps and shift left philosophy

 

Required qualifications:

  • Experience working in production environments or environments closely associated with production or devops teams.
  • Working knowledge of common and industry-standard cloud-native/cloud-friendly authentication mechanisms (OAuth, IDP, Okta etc)
  • Experience implementing strong security in cloud native technologies (Kubernetes, APIs, Microservices), using Infrastructure-as-Code and Compliance-as-Code
  • Hands on experience in rolling our MDR, SIEM, vulnerability scanning and data loss prevention tools
  • Experience writing IaC (Infrastructure as code) as part of a DevOps or DevSecOps in a multi-cloud environment
  • Hands on experience in monitoring and securing cloud services (AWS, GCP) and APIs 
  • Working knowledge of compliance requirements and regulations and managing audit vendors
  • Familiarity with setting up security incident response centers (SOC)
  • Experience implementing, optimizing and troubleshooting the following tools/ecosystems: 
    • Terraform, Hashicorp Vault
    • AWS SSO or Okta
    • AWS GuardDuty, WAF
    • Nessus /Tenable, Crowdstrike
    • Alertlogic / McAfee / MDR solutions
    • VPN / Palo Alto / Prisma/ ZScaler
    • SumoLogic or Splunk
    • Checkmarx / Veracode/ Sonarqube
    • Datadog / New Relic
    • Prometheus, Open Telemetry
    • SOC 2 / ISO2700x

 

 It would be great if you also possess:

  • CISSP and/or CISM certifications
 
 
 
More about Level Home:
 
When we look around our homes today, we see opportunity. We see “smart” products that lack utility and connected devices that push us further apart. We see consumers with high expectations, current standards set too low, and products that simply fail to deliver.
 
Level Home Inc. is re-inventing the standard. We’re redefining “smart”, to center around thoughtfulness, practicality, and the people who make the problem worth solving. We approach product design with a blank slate, zero assumptions, and an open-mind, because the way a problem is defined sets the stage for its solution. We couple deep expertise with unbridled curiosity, because to us “smart” means simple, intuitive, and useful.
 
We start with empathy, take new perspectives, and challenge existing standards. People are at the heart of what we do, and respecting their style, choices, and preferences is the first step to uncovering a thoughtful solution that truly improves their daily lives. After all, we’re not just designing products for a house, we are designing them for the people who make it a home.
 
Level Home Inc. is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, disability or genetic information, sex, sexual orientation, gender identity, or national origin.
 
A note to Recruitment Agencies: Please don’t reach out to Level employees or leaders about our roles -- we’ve got Recruiting covered. We don’t accept unsolicited agency resumes and we are not responsible for any fees related to unsolicited resumes. Thank you for your understanding.
Apply now Apply later
  • Share this job via
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: APIs AWS Checkmarx CISM CISSP Cloud Compliance CrowdStrike DevOps DevSecOps GCP IAM IDS Incident response IPS ISO 27000 Kubernetes Microservices Monitoring Nessus Okta Privacy Prometheus SIEM SOC SOC 2 SonarQube Splunk SSO Terraform Veracode VPN

Perks/benefits: Startup environment

Regions: Remote/Anywhere North America
Country: United States
Job stats:  21  3  0
Category: Architecture Jobs

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.