This job post is closed and the position is probably filled. Please do not apply.
π€ Automatically closed by a robot after apply link
was detected as broken.
Description:
The Staff Product Security Engineer will collaborate with various stakeholders to enhance the security of the cloud infrastructure, improve the secdevops function, and conduct secure design reviews for products.
They will work closely with engineers in different areas of the Pinecone infrastructure to promote a culture of strong security ownership among engineers.
The role involves identifying security risks, developing solutions, and setting standards to mitigate risks to customers and their data.
As Pinecone expands, this position will eventually lead the Product Security Engineering department and serve as a backup for the head of security.
Requirements:
Strong experience in administering and securing at least one cloud environment (Google Cloud Platform, AWS, Azure).
Clear understanding of cloud computing services, deployment architecture, and infrastructure as code.
Proficiency in performing threat modeling and design reviews for new technologies or product features.
Ability to effectively communicate ideas to senior staff members.
Experience in implementing SecDevOps practices.
Familiarity with containers (Kubernetes/Docker) and service mesh (istio, linkerd).
Knowledge of software vulnerabilities, CVEs, and system package remediations.
Proficiency in one or more programming languages.
Extensive experience with information security standards and methodologies.
Strong problem-solving skills and organizational abilities.
Benefits:
Opportunity to solve challenging security problems in cloud, code, and system design.
Collaboration with teams to implement security recommendations.
Advocacy for scalable solutions that meet business and customer needs.
Building security controls to detect, prevent, and correct vulnerabilities.
Potential for growth to lead the Product Security Engineering department.
Exposure to machine learning applications and familiarity with industry standards like SOC2, NIST, and ISO.
Possibility of obtaining CISSP certification.
Experience with web server/client architecture and implementation.