Mirantis

Strategic open source infrastructure for containers and virtual machines.

Senior Product Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteTeam 501-1,000H1B SponsorCompany SiteLinkedIn

Location

Oregon

Posted

10 days ago

Salary

Not specified

5 yrs expEnglishCloudKubernetesPythonSDLCTerraformGo

Job Description

• Secure Products & Infrastructure: Design, implement, and maintain security controls across applications, infrastructure, and CI/CD pipelines. • Embed security requirements aligned with SOC 2, ISO 27001, and internal standards. • Drive adoption and operationalization of SAST, DAST, container scanning, IaC security, and dependency analysis tooling. • Integrate automated security testing into the SDLC to enable secure-by-design development. • Offensive Security & Vulnerability Management: Lead application security reviews, threat modeling, vulnerability assessments, and penetration testing. • Validate and prioritize findings based on exploitability and business impact. • Partner with engineering teams to ensure timely, measurable remediation. • Proactively identify and demonstrate security weaknesses to improve overall product resilience. • Incident Response & Risk Reduction: Support investigation of product and infrastructure security incidents. • Contribute to root cause analysis and durable remediation strategies. • Identify systemic control gaps and implement long-term risk mitigation measures. • Compliance & Assurance: Support product-level security reviews and audit activities. • Coordinate evidence collection and control validation for SOC 2, ISO 27001, and enterprise requirements. • Translate compliance requirements into actionable engineering controls. • Cross-Product Security Leadership: Develop and maintain security expertise across multiple Mirantis products. • Standardize security practices and tooling across teams. • Strengthen program scalability and reduce single-point-of-failure risk. • Security Advocacy & Enablement: Champion secure design principles and modern application security practices. • Provide actionable guidance during architecture and code reviews. • Drive continuous improvement and automation across the SDLC.

Job Requirements

  • 5+ years of experience in product security, application security, or security engineering.
  • Strong knowledge of common vulnerabilities (OWASP Top 10, SANS Top 25) and secure development practices.
  • Demonstrated experience with manual penetration testing, threat modeling, and exploitation techniques.
  • Hands-on experience with security tooling and automation, including: SAST / DAST tooling and CI/CD integration
  • Container image scanning (e.g., Trivy, Grype, Anchore)
  • IaC security (e.g., Terraform, Helm, KICS, Checkov)
  • Dependency and software supply chain security tools
  • Experience with vulnerability management platforms and remediation workflows.
  • Experience working with containerized environments, Kubernetes, and cloud platforms.
  • Proven ability to integrate and automate security controls within CI/CD pipelines.
  • Strong collaboration and communication skills across engineering and product teams.
  • Experience supporting SOC 2, ISO 27001, or similar compliance frameworks.
  • Relevant certifications (OSCP, OSEP, OSWE, GPEN, GWEB, GWAPT, GCSA) strongly preferred.
  • Proficiency in scripting or programming (Go, Python, or similar) is a plus.

Benefits

  • Competitive compensation package
  • Strong benefits plan

Related Categories

Related Job Pages

More Security Engineer Jobs

Information Security GRC Intern

Calix

To enable broadband service providers of all sizes to simplify, innovate and grow.

Security Engineer10 days ago
InternshipRemoteTeam 1,001-5,000Since 2000H1B Sponsor

GRC Intern supporting compliance and risk management at Calix

United States
$18 - $29 / hour

Senior IT and Security Manager

Bird

On a mission to provide eco-friendly transportation for everyone. Safety and compliance first in 450+ cities. NYSE: BRDS

Security Engineer10 days ago
Full TimeRemoteTeam 201-500Since 2017H1B Sponsor

Senior Manager of IT and Security at Bird leading IT systems development

Jamf
United States
Security Engineer10 days ago
Full TimeRemoteTeam 501-1,000Since 2010H1B No Sponsor

Hands-on information security leader driving cybersecurity at Outset Medical

AWSCloudCyber Security
United States
$185K - $251K / year

Senior Manager – Offensive Security

Twilio

Build the future of communications.

Security Engineer10 days ago
Full TimeRemoteTeam 5,001-10,000H1B Sponsor

Senior Manager of Offensive Security leading ethical hacking and penetration testing efforts at Twilio

AWSAzureCloudCyber SecurityGoogle Cloud PlatformKubernetesPythonSDLCGo
California + 5 moreAll locations: California, Connecticut, New Jersey, New York, Pennsylvania, Washington
$188.2K - $276.7K / year