Senior Infrastructure Security Software Engineer
New
Q
QuoraSoftware Engineering
This position can be performed remotely from anywhere in Canada or the United States., Mon-Fri: 9am-3pm Pacific TimeFull-TimeSenior
SalaryUS candidates only: $172,279 - $249,640 USD + equity + benefits. Toronto/Vancouver: $221,209 - $256,433 CAD + equity + benefits. Other Canada: $206,461 - $239,337 CAD + equity + benefits.
Apply NowOpens the employer's application page
Job Details
- Required Skills
- AWSKubernetesCI/CDTerraformCloudFormation
Requirements
- Proven experience as a capable software engineer.
- Hands-on experience securing large-scale cloud environments, particularly with AWS.
- Experience building secure infrastructure-as-code (IaC) pipelines using Terraform or CloudFormation.
- Strong grasp of IAM policies, network segmentation, and VPC design.
- Understanding of security in Kubernetes clusters or serverless architectures.
- Expertise in automating security processes and integrating tools like SAST, DAST, and dependency scanning into CI/CD pipelines.
- Knowledge of Linux system security, including container security, POSIX Capabilities, and SECCOMP.
- Experience with OSQuery and eBPF.
- Excellent communication and collaboration skills for working across teams.
- Ability to work during coordination hours (Mon-Fri, 9am-3pm PT).
Responsibilities
- Partner with engineering teams to review cloud and compute architecture design changes.
- Establish threat models for cloud and compute paved roads to identify security risks.
- Develop or adopt open-source tools to monitor and harden our cloud Infrastructure, harden our OS, develop security logging pipelines and detect intrusions.
- Apply your expert knowledge of security best practices for AWS and Kubernetes to inform remediations and the team's control roadmap.
- Drive the definition and implementation of security policies and monitor in conformance to the policies.
- Write code for automations that support security requirements like threat detection, incident containment, and network access management.
- Conduct initial incident triage; determine scope, urgency, and potential impact of security incidents; participate in the incident response process.
View Full Description & ApplyYou'll be redirected to the employer's site