Skip to main content
CrowdStrike
CrowdStrike

Engineer II, Software Assurance, Product Security (Remote)

RemoteUnited States only
Published
Role
Security
Experience
Mid
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Mid-level (Engineer II) product security role focused on securing the open-source software supply chain and hardening GitHub organizations. Must have GitHub administration and GitHub Actions experience, SCA/dependency risk mitigation knowledge, Linux configuration skills, and proficiency in scripting (Python, Go, Shell, or JavaScript). Remote / flexible.

Core skills

GitHubGitHub Actions

Required skills

BitbucketGitLabArtifactoryS3LinuxPythonGoShellJavaScriptSoftware composition analysis (SCA)Dependency management

Optional skills

LogScaleSplunkDataDogPrometheusJenkinsArgo CD

What you'll do

  • Assess risk and provide security guidance to engineers on open-source software usage and repository configurations.
  • Implement and maintain controls and processes to secure public and private GitHub organizations, including repository guardrails, secret scanning and branch protection.
  • Harden open-source code usage, development, ingestion, and distribution across the enterprise.
  • Investigate open-source dependencies and third-party packages to mitigate supply chain risks (typosquatting, dependency confusion).
  • Create tooling and automations to detect malicious packages and close known gaps in open-source security workflows.

What they require

  • Experience working in an engineering role implementing, supporting, and monitoring software security systems.
  • Strong working experience with GitHub, including repository administration, GitHub Actions, branch protection rules, and access management.
  • Familiarity with other source control management tools (e.g., BitBucket, GitLab).
  • Familiarity with artifact storage tools like Artifactory and S3.
  • Experience identifying and mitigating open-source risks (SCA, dependency management, licensing risks).
  • Experience working with and securing configurations of Linux and/or other Unix-like variants.
  • Proficiency in one or more scripting languages such as Python, Golang, Shell, or JavaScript.
  • Domain knowledge of the software development lifecycle (SDLC), secure coding practices, code reviews, and source control security.

Benefits

  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees

American cybersecurity technology company

CybersecurityEnterprisecrowdstrike.com
Salary not disclosed