Veeam Software

Product & Application Security Engineer

Veeam Software

full-time

Posted on:

Location Type: Remote

Location: CaliforniaUnited States

Visit company website

Explore more

AI Apply
Apply

Salary

💰 $172,400 - $320,100 per year

About the role

  • Design & Architecture: You will be the primary security voice in design reviews. You will perform threat modeling on new features, identifying architectural risks before a single line of code is written.
  • Code-Level Security: You will actively review Pull Requests and conduct deep-dive code audits. You won't just run scanners; you will manually analyze logic in our code to find complex flaws that automated tools miss.
  • Vulnerability Remediation: Unlike traditional security roles that only "report" bugs, you will help fix them. You will triage findings from our tooling and write production-ready patches to resolve vulnerabilities.
  • Secure Software Supply Chain: You will oversee the integrity of our build dependencies, ensuring that the open-source libraries we import (and the tools we use to build them) are secure.
  • Triage and fix security alerts from tools like Grype, Cycode, and Wiz.
  • Implement code fixes for security tech-debt across our stack.
  • Conduct Threat Modeling sessions for upcoming epics and features in our two-week sprint cycles.
  • Serve as a Subject Matter Expert on Kubernetes security primitives (RBAC, unprivileged containers, network policies) for the engineering team, owning metrics and definition of success, share best practices through workshops, reviews, and documentation.
  • Lead audits, incidents, and compliance reviews representing the engineering team with the wider security community in Veeam.

Requirements

  • Developer DNA: You are a competent developer in Go (Golang) and have exposure to modern frontend frameworks like Vue.js.
  • Kubernetes Native: You’ve worked extensively with Kubernetes and understand its security primitives.
  • Shift-Left Mindset: You have experience integrating security into the early stages of the Software Development Life Cycle.
  • Tooling Familiarity: Experience with modern AppSec and Supply Chain tools (specifically Grype, Cycode, and Wiz) is a strong plus.
  • Pragmatism: You can balance theoretical security perfection with the practical reality of shipping software on a continuously frequent basis.
Benefits
  • Unlimited paid time off, plus 3 global VeeaMe Days for self-care
  • Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
  • Medical, dental, and vision coverage from day one
  • Mental health support, therapy sessions, and digital wellness tools via SupportLinc EAP
  • 401(k) retirement plan with matching contributions up to annual limits
  • Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
  • AirVet: 24/7 virtual veterinary care at no cost
  • Legal services, identity protection, and supplemental health insurance options
  • Tax-advantaged spending accounts for healthcare, dependent care, and commuting
  • Professional training and education, including courses and workshops, internal meetups, and unlimited access to our online learning platforms (LinkedIn Learning, Athena, O’Reilly) and mentoring through our MentorLab program
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
GoGolangVue.jsThreat ModelingCode AuditsVulnerability RemediationSecure Software Supply ChainSecurity Tech-DebtKubernetesRBAC
Soft Skills
PragmatismLeadershipCommunicationCollaborationProblem Solving