Перейти к основному содержимому
CrowdStrike
CrowdStrike

Engineer II, Software Assurance, Product Security (Remote)

УдалённоUnited States только
Опубликовано
Роль
Безопасность
Опыт
Мидл
Зарплата не указана
Проверьте доступность

Доступно для: US only. Укажите, откуда вы работаете, чтобы проверить доступность.

Коротко по делу

Mid-level (Engineer II) product security role focused on securing the open-source software supply chain and hardening GitHub organizations. Must have GitHub administration and GitHub Actions experience, SCA/dependency risk mitigation knowledge, Linux configuration skills, and proficiency in scripting (Python, Go, Shell, or JavaScript). Remote / flexible.

Ключевые навыки

GitHubGitHub Actions

Обязательные навыки

BitbucketGitLabArtifactoryS3LinuxPythonGoShellJavaScriptSoftware composition analysis (SCA)Dependency management

Желательные навыки

LogScaleSplunkDataDogPrometheusJenkinsArgo CD

Чем предстоит заниматься

  • Assess risk and provide security guidance to engineers on open-source software usage and repository configurations.
  • Implement and maintain controls and processes to secure public and private GitHub organizations, including repository guardrails, secret scanning and branch protection.
  • Harden open-source code usage, development, ingestion, and distribution across the enterprise.
  • Investigate open-source dependencies and third-party packages to mitigate supply chain risks (typosquatting, dependency confusion).
  • Create tooling and automations to detect malicious packages and close known gaps in open-source security workflows.

Что требуется

  • Experience working in an engineering role implementing, supporting, and monitoring software security systems.
  • Strong working experience with GitHub, including repository administration, GitHub Actions, branch protection rules, and access management.
  • Familiarity with other source control management tools (e.g., BitBucket, GitLab).
  • Familiarity with artifact storage tools like Artifactory and S3.
  • Experience identifying and mitigating open-source risks (SCA, dependency management, licensing risks).
  • Experience working with and securing configurations of Linux and/or other Unix-like variants.
  • Proficiency in one or more scripting languages such as Python, Golang, Shell, or JavaScript.
  • Domain knowledge of the software development lifecycle (SDLC), secure coding practices, code reviews, and source control security.

Преимущества

  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees

American cybersecurity technology company

CybersecurityКрупнаяcrowdstrike.com

Что говорят о компании

3.8/ 5

  • Employees appreciate the company's strong focus on cybersecurity and its mission to protect organizations.
  • Many reviews highlight a collaborative and supportive work culture.
  • Some employees express concerns about management practices and communication.
Зарплата не указана