Build a program that ties application security, container security, and cloud security together
Change the application framework to make security the easiest path
Provide tools and information to ensure developers can effectively peer review code themselves
Encourage developers to continuously think about security using gamification and by surfacing results in the pipeline
Analyze vulnerabilities, assess business impact and risk, implement fixes, and prioritize remediation
Create automations and tooling using scripting languages (Python, Go, Ruby, JavaScript, etc)
Collaborate closely with application, platform, and infrastructure security engineers and partner with product teams to design maintainable, resilient security solutions
Work with infrastructure-as-code, Kubernetes, and role-based access controls to improve Carta’s security posture
Lead security ownership programs, research new solutions, and influence developer security practices
Requirements
5+ years of experience in applying an engineering-driven approach to solving infrastructure and platform security problems at scale
Thrive in environments with autonomy, confidently driving security improvements from idea to implementation
Ability to analyze vulnerabilities that currently affect Carta’s infrastructure/platform, assess business impact and risk, implement effective fixes, and prioritize remediation based on severity and exploitability
Create automations in higher level scripting languages (Python, Go, Ruby, Javascript, etc)
Bonus points if you have experience in securing containerized environments, with practical skills in Docker and Kubernetes
Experience with infrastructure-as-code, Kubernetes, and role-based access
Eligible to work in the United States (Carta uses E-Verify)
Benefits
Market competitive salary
Equity for all full time roles
Exceptional benefits
Commission plans for applicable roles
ATS Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.