Salary
💰 $120,000 - $235,750 per year
Tech Stack
AngularAWSCloudDockerGoJenkinsKubernetesPythonReactSDLC
About the role
- Design and develop front-end applications and interactive workflows (dashboards, checklists, attestations) that present security and compliance data
- Work with Figma and stakeholders to design, prototype, and validate UX flows, translating complex compliance requirements into simple, user-friendly experiences
- Develop backend services that ingest data from version control, CI/CD pipelines, SBOMs generation platforms, and container registries to surface security and compliance risks
- Design and build agent-based security tooling to monitor and evaluate secure development practices across SDLC workflows
- Improve the precision of alerts and reduce noise through context-aware signal processing and risk-based prioritization
- Partner with DevSecOps, Legal, and Engineering teams to align OSS governance and enforce security guardrails
- Contribute to the development of metrics, dashboards, and reports to drive adoption and track improvements in SDLC security posture
- Develop services and agents that detect insecure coding patterns, track OSS consumption, and drive early remediation workflows across the development ecosystem
- Embed continuous security across modern DevSecOps practices and ensure release readiness through visibility, automation, and intelligence
Requirements
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience)
- 3+ years of experience in software engineering or platform security, ideally supporting developer productivity or automation tooling
- Strong front-end engineering skills in React, Angular, or similar modern UI frameworks
- Proficiency in Python and/or Go to build backend services and platform agents
- Familiarity with GitHub, GitLab, or Jenkins-based CI/CD environments and secure coding practices
- Experience building or integrating secret scanning, OSS vulnerability scanning (e.g., SCA tools), and code quality tooling
- Understanding of container security fundamentals and cloud-native architectures (Docker, Kubernetes, AWS)
- Strong written and verbal communication skills for collaborating with collaborators across engineering, security, and compliance