Sr. Security Engineer
United States (Remote)
HashiCorp is a fast-growing company that solves development, operations, and security challenges in infrastructure so organizations can focus on business-critical tasks. We build products to give organizations a consistent way to manage their move to cloud-based IT infrastructures for running their applications. Our products enable companies large and small to mix and match AWS, Microsoft Azure, Google Cloud, and other clouds as well as on-premises environments, easing their ability to deliver new applications for their business.
About the Role
We are looking for Product Security Engineers to help scale our product security function, which works closely with engineering & product management to ensure that security is appropriately addressed across the HashiCorp suite of cloud and self-managed products. This role will report to our Director of Product Security.
Security at HashiCorp is a remote team. While prior experience working remotely isn't required, we are looking for team members who perform well given a high level of independence and autonomy.
In this role, your responsibilities will include:
- Contribute to secure architecture and design of HashiCorp products, with a specific focus on the HashiCorp Cloud Platform.
- Work across various product and engineering teams to prioritize security features and bugs, and ensure implementation and mitigations.
- Monitor threats and vulnerabilities impacting HashiCorp products and services; triage reported vulnerabilities, identify mitigations and assess/communicate associated risk.
- Plan & execute security assessments (dynamic testing, static testing, code review, etc) and threat modeling of HashiCorp’s products, services, and associated cloud infrastructure.
- Build and implement security solutions across the product life-cycle, such as standalone security tools, CI/CD pipeline integrations, product security features/fixes, etc.
- Act as SME on multiple information security areas (e.g. security architecture, application security, threat modeling etc.)
- Assist in execution of 3rd-party audits, penetration tests, and bug bounty programs.
- Contribute to the creation and delivery of security training.
- Research emerging attack vectors and techniques.
We are looking for talented self-starters with solid security experience. We will consider experienced engineers with less security-specific experience but the desire to learn!
You may be a good fit if you have knowledge and experience around:
- Product / service architectures in modern cloud environments (IaaS, SaaS, PaaS).
- Amazon Web Services (AWS), Microsoft Azure, and/or Google Cloud Platform (GCP).
- Modern engineering practices, processes, and tools, particularly related to the Go programming language and ecosystem.
- Secure development practices, and integration into broader engineering activities.
- Secure operations practices, specifically with reference to cloud environments.
- Application and infrastructure security testing methodologies and tools.
- Security design / architecture and threat modeling.
- Vulnerabilities (old and new), and options for defense / mitigation.
- Product vulnerability management lifecycle.
- Security audits, penetration tests, and/or bug bounty programs.
- Cryptography and cryptographic libraries.
About the Application Process
Please note, as communication is a critical aspect of how we work, a cover letter is a great way to provide a sample of how you communicate. In your cover letter, describe why you're interested in working at HashiCorp, and what draws you to this role in particular.
HashiCorp embraces diversity and equal opportunity. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. We believe the more inclusive we are, the better our company will be.
Explore more Information Security career opportunities
- Open Senior Information Security Engineer jobs
- Open IT Security Engineer jobs
- Open Cyber Security Engineer jobs
- Open Staff Security Engineer jobs
- Open Senior Incident Response Analyst jobs
- Open Senior Information Security Analyst jobs
- Open Azure Security Engineer jobs
- Open Vulnerability Analyst jobs
- Open Personnel Security Officer jobs
- Open Security Operations Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Infrastructure Security Engineer jobs
- Open Cyber Security Analyst jobs
- Open Infrastructure Security Engineer jobs
- Open Cybersecurity Analyst jobs
- Open Senior Penetration Tester jobs
- Open Information Security Architect jobs
- Open Information Security Officer jobs
- Open Threat Intelligence Response Analyst jobs
- Open Sr. Product Security Engineer jobs
- Open SOC Analyst jobs
- Open Cybersecurity Engineer jobs
- Open Security Officer 3 jobs
- Open Privacy Manager jobs
- Open Sr. Software Engineer - Detection Engineering jobs
- Open DevOps-related jobs
- Open PCI-related jobs
- Open Threat intelligence-related jobs
- Open OWASP-related jobs
- Open Clearance-related jobs
- Open Machine Learning-related jobs
- Open IDS-related jobs
- Open CEH-related jobs
- Open Encryption-related jobs
- Open Open Source-related jobs
- Open Splunk-related jobs
- Open Forensics-related jobs
- Open Ruby-related jobs
- Open Intrusion detection-related jobs
- Open Security assessments-related jobs
- Open OSCP-related jobs
- Open Threat detection-related jobs
- Open Docker-related jobs
- Open GDPR-related jobs
- Open DevSecOps-related jobs
- Open HIPAA-related jobs
- Open IPS-related jobs
- Open TCP/IP-related jobs
- Open Unix-related jobs