Перейти к основному содержимому
Quora

Senior Infrastructure Security Software Engineer

УдалённоCanada только· UTC-8…UTC-5
Опубликовано
Роль
Безопасность
Опыт
Синьор
Занятость
Полная занятость
$172.3k–$249.6k/yr
Проверьте доступность

Доступно для: CA only · UTC-8…UTC-5. Укажите, откуда вы работаете, чтобы проверить доступность.

Коротко по делу

Senior Software Engineer with expertise in Cloud Infrastructure Security (AWS, Terraform, IAM, VPC) or Automation/Secure Development Practices (CI/CD, SAST, DAST) or Linux/System Security (containers, LSM, OSQuery, eBPF). Must be outcome-focused, detail-oriented, and able to right-size solutions. Product Security is a plus.

Ключевые навыки

Cloud Infrastructure SecurityAutomationLinux/System Security

Обязательные навыки

AWSTerraformCloudFormationIAM policiesnetwork segmentationVPC designmonitoringloggingSASTDASTdependency scanningLinuxcontainer securityPOSIX CapabilitiesSECCOMPLSMOSQueryeBPFsecure coding practicesCI/CDsecure code delivery

Желательные навыки

Kubernetesserverless architecturessecure web applicationssecure APIsOWASP Top 10XSSCSRFSQL injection

Чем предстоит заниматься

  • Partner with engineering teams to review cloud and compute architecture design changes
  • Establish threat models for cloud and compute paved roads to identify security risks
  • Develop or adopt open-source tools to monitor and harden our cloud Infrastructure, harden our OS, develop security logging pipelines and detect intrusions
  • Apply your expert knowledge of security best practices for AWS and Kubernetes to inform remediations and the team's control roadmap
  • Drive the definition and implementation of security policies and monitor in conformance to the policies
  • Write code for automations that support security requirements like threat detection, incident containment, and network access management.
  • Conduct initial incident triage; determine scope, urgency, and potential impact of security incidents; participate in the incident response process

Что требуется

  • be a capable software engineer while also spiking in at least one of the following domain expertise:
  • Sweat The Right Details: you thrive in understanding the details but will also know to ruthlessly prioritize the critical issues.
  • Right-Size The Solution: you recognize guidelines and framework do not always fit the problem and know how to adjust the solution for scalability not always at-scale.
  • Ownership: you are outcome focused and can deftly navigate obstacles, decompose complexities, manage your time and can communicate your vision to peers and management.
  • Cloud Infrastructure Security: You have hands-on experience securing large-scale cloud environments, particularly with AWS. You are passionate about building secure infrastructure-as-code (IaC) pipelines using tools like Terraform or CloudFormation. You understand IAM policies, network segmentation, and VPC design and have a thorough grasp of monitoring and logging in cloud-native environments. You are skilled in identifying misconfigurations, mitigating risks, and driving remediation processes.
  • Automation and Secure Development Practices: You believe in "security as code" and are skilled at automating security processes. You can develop and integrate security tools into CI/CD pipelines to ensure secure code delivery. Tools like SAST, DAST, and dependency scanning are part of your daily toolkit, and you have experience integrating them into workflows to catch vulnerabilities early. You also advocate for secure coding practices and are skilled at mentoring teams to write resilient, secure applications.
  • Linux/System Security: You are well versed in AWS infrastructure security but also are passionate about scalability, reliability and operational rigor. Beyond that, you know that root does not mean root and are passionate about container security, POSIX Capabilities, SECCOMP and have a favorite flavor of LSM. In your spare time, you love playing around with OSQuery and eBPF.
  • Product Security (nice-to-have): Not a requirement, but a real plus: experience building secure web applications and APIs, with a working grasp of the OWASP Top 10 and common vulnerabilities such as XSS, CSRF, and SQL injection. It complements the infrastructure security focus of this role and helps when partnering with product teams.
  • Successful candidates must have availability for meetings and impromptu communication during Quora's “coordination hours https://quora.com/coordination_hours" (Mon-Fri: 9am-3pm Pacific Time).

Преимущества

  • medical/dental/vision coverage
  • equity refreshers
  • remote work reimbursement
  • paid time off
  • employee assistance programs
  • and more
TechnologyКрупнаяquora.com
$172.3k–$249.6k/yr