Tech Stack
AndroidAWSDistributed SystemsGoGoogle Cloud PlatformiOSKubernetesLinuxOpen SourcePythonTerraform
About the role
- Build and maintain infrastructure, software, and automation to monitor and mitigate attacks and vulnerabilities across JumpCloud products and services
- Lead the design and maintenance of infrastructure, including custom software and vendor integrations, to meet advanced security needs for Product and Infrastructure Security
- Develop and implement policy enforcement automation and comprehensive reporting systems
- Set up data ingestion for the SIEM or other tooling as needed
- Collaborate with DevOps, Developer Enablement, SecOps, GRC, and other engineering partners globally to embed security best practices and establish guardrails for developers
- Conduct and oversee threat model reviews of product features and architectures, providing strategic guidance
- Mentor and guide service/feature teams in secure software design principles
- Help lead a team responsible for ensuring JumpCloud products' integrity and keeping JumpCloud users safe
Requirements
- 7-10 years of experience in the field of security engineering with an extensive background and experience in software development and architecture
- Substantial production experience with AWS or GCP, including networking, securing workloads, and IAM management
- Proficient in writing Golang (most Security team tooling is written in Go); familiarity with Python scripts
- Extensive experience in Terraform (HCL) and Kubernetes, including containerization technologies
- Proficiency with CI/CD tools, particularly GitHub Actions (Spacelift for IaC is a bonus)
- Exceptional written and oral communication skills
- Proven ability to lead cross functional projects and teams
- Expertise in one of: Product Security (threat modeling and secure architecture design/review); Authentication protocols (SAML, OAuth, LDAP, etc.); Mobile application security (iOS and Android)
- Bonus: Open Policy Agent (OPA), open source security tools, data pipeline tooling, certificate infrastructure, distributed systems, working on core OS (Windows, Mac, Linux) APIs
- Available for on-call (after hours) duties for internal tools/services the DevSecOps team owns
- Willing to support the Security Operations team during incidents with ad-hoc queries and forensics
- Must be located in and authorized to work in the USA (located within one of the 50 U.S. States)