Product Security Engineer

Found in: beBee jobs US - 7 days ago


New York, New York, United States Hex Full time

===

Excerpt: Design and implement scalable security infrastructure and help build a culture of security for a rapidly growing team.

Status: Open

===

About the role

Don't you wish the security practice at your company was more modern, effective and not chasing its tail? Are you excited by the idea of tackling novel security problems while empowering a delightful experience for end users? If that energy isn't appreciated where you currently work, join us in developing a proactive, technology-forward product-security discipline, dedicated to eliminating vulnerabilities in application and infrastructure before they even occur. You'll own the SSDLC and ensure effective security measures are embedded throughout. You'll be building systems and occasionally building/buying tools that help all of Engineering truly shift left, so you can spend less time chasing vulnerabilities and more time on meaningful security engagement.

Additionally, this role includes practicing embedded security within Eng teams, teaching them to think through, prevent, and mitigate common security issues all on their own: everything from creating guardrails to implementing AuthN / AuthZ correctly to creating secure and resilient infrastructure as code. The security culture you help create permeates the entire company and has longevity, even when you're not in the room, because you will help a top-tier Eng team level up. Your work will inform the company's security roadmap, starting with delivering pieces of a high-speed, automated, and self-service security strategy.

So far the security projects we've worked on have been about:

  • Hardening our Kubernetes deployments
  • Running and evolving our Bug Bounty Program
  • Streamlining our product authorization model
  • Optimizing access control company-wide
  • Automating vulnerability management

About you

Must have's:

  • 5+ years of product-security experience: 4 years in appsec, 1 in cloudsec
  • You write code and are fond of creating your own automation
  • Deep understanding of software-security principles and a good understanding of cloud-infrastructure security principles
  • Hands-on experience with many of the core infrastructure products that Hex is run on, including Kubernetes, AWS, and Terraform
  • You perform code reviews regularly
  • Proficient at threat modeling and keeping the models updated
  • Able to break down a landscape of scattered security problems, whether complex, simple and/or varies, and group them into logical, achievable components to get the most bang for the buck during quarterly and annual planning
  • Possess an instinct for strategic thinking and aligning with business and product goals, while keeping a healthy balance of velocity and security excellence.
  • Excel at working with several different engineering teams and codebases, and at communicating with engineers and non-technical partners across many different backgrounds, demonstrating curiosity about how their work contributes to Hex's success.

Nice to have's:

  • Experience scaling and optimizing a bug-bounty program with a good signal:noise ratio
  • Involvement with your Security Community
  • Interest in the data space, and a love of shipping great products and building tools that empower engineers and users to do more.
  • Curious and willing to dive into the bigger picture of building a company, including go-to-market, customer development, people, and marketing.

Our Engineering team

We're a group of engineers who are forging new ground together and love partnering with Security on our journey to pull ahead of our competition. You can read about how we think through problems as well as how we learn from mistakes on our blog here:

  • How we took down production...
  • Beyond Linear Notebooks
  • A pragmatic approach to live collaboration

Our Tech Stack

runs on AWS:

  • EKS
  • RDS (Postgres)
  • EC2
  • S3

uses:

  • TypeORM
  • Apollo GraphQL
  • React
  • Redux
  • ... and more

is written in:

  • TypeScript
  • Python
  • Node
  • Terraform

  • Engineering Production Support

    Found in: beBee jobs US - 2 days ago


    New York, New York, United States BAE Systems Full time

    Job Description BAE Systems is hiring a Mechanical Engineer in York, PA on First Shift to provide Engineering Production Support (EPS) for the AMPV combat vehicle program. This individual will serve as an interface between manufacturing, design and production engineering for analyzing and solving problems related to the design and fabrication of mechanical...

  • Engineering Production Support

    Found in: beBee jobs US - 2 weeks ago


    New York, New York, United States BAE Systems Full time

    Job Description BAE Systems is hiring a Mechanical Engineer in York, PA on First Shift to provide Engineering Production Support (EPS) for the AMPV combat vehicle program. This individual will serve as an interface between manufacturing, design and production engineering for analyzing and solving problems related to the design and fabrication of mechanical...

  • Senior Security Engineer, Application Security

    Found in: beBee jobs US - 1 week ago


    New York, New York, United States Grow Therapy Full time

    What You'll Be Doing:We are looking for a Senior Security Engineer to help us establish the Application Security vertical of Grow Therapy, and who will help build a secure product platform for Grow. You'll be the first hire in this area, and will report directly to our Head of Security Your responsibilities will include: Identify and implement improvements...

  • Senior Security Engineer, Application Security

    Found in: beBee jobs US - 6 days ago


    New York, New York, United States tapwage Full time

    About us:Grow Therapy is on a mission to serve as the trusted partner for therapists growing their practice, and patients accessing high-quality care. Powered by technology, we are a three-sided marketplace that empowers providers, augments insurance payors, and serves patients. Following the mass increase in depression and anxiety, the need for...

  • Application Security Engineer

    Found in: beBee jobs US - 2 weeks ago


    New York, New York, United States OPT Nation Full time

    In this role you will work closely with development teams across platform engineering to ensure our applications are secure. We are looking for a skilled application security engineer to analyze software designs and implementations from a security perspective and identify and resolve security issues. You will perform security analysis and implement controls...

  • Lead Security Engineer

    Found in: beBee jobs US - 6 days ago


    New York, New York, United States dYdX Full time

    (Location: New York, NY - Hybrid)At dYdX you'll have an opportunity to build state-of-the-art decentralized technologies that will redefine global financial markets. By joining us at this stage in our growth, you will help make fundamental decisions that will shape the course of dYdX. → Learn more about working at dYdXABOUT dYdX:We've built the world's...

  • Web Product Engineer

    Found in: beBee jobs US - 7 days ago


    New York, New York, United States VOLT AI Full time

    CompanyVOLT is building a new category of software & robotics products that will revolutionize the security industry and save human lives. Our solutions will be used in everyday environments to detect and mitigate risks such as mass-shootings, armed robberies, and other violent events.We are backed by some of Silicon Valley's leading investors and VC firms...

  • Principle Security Engineer

    Found in: beBee jobs US - 2 weeks ago


    New York, New York, United States Motion Recruitment Full time

    A financial startup in NYC is looking for a Principle Cybersecurity Engineer to help develop their cybersecurity program. The company has been going since 2021, and has developed a rewards program for renters in NYC by partnering with various financial companies. Their Head of Engineering has been handling cybersecurity with the help of an external service,...

  • Product Manager

    Found in: beBee jobs US - 2 weeks ago


    New York, New York, United States Polymer VCO Full time

    About the Role...Polymer is striving to delight security and compliance teams with a product that is easy to use and also automates the task of managing risk associated with data loss. A passionate early user base has allowed us to understand the market and have a pretty good idea on how to scale our growth. We're looking for people who are interested in...

  • Head of Product

    Found in: beBee jobs US - 2 weeks ago


    New York, New York, United States Reality Defender Full time

    About Reality DefenderReality Defender is a groundbreaking security platform offering comprehensive deepfake detection. A Y Combinator graduate, Comcast NBCUniversal LIFT Labs alumni, and backed by DCVC, Reality Defender's proactive deepfake and AI-generated content detection technology is developed by a leadership team with over 20 years of experience in...


  • New York, New York, United States Motion Recruitment Full time

    A SaaS company with a marketing automation product is looking for a Software Security Engineer to join their development team. The role will be helping with application development while also establishing a security presence on the team. We're looking for someone with a strong development background in Golang who is also extremely comfortable with software...

  • Product Designer

    Found in: beBee jobs US - 7 days ago


    New York, New York, United States Aptos Full time

    About the role:We are seeking an experienced and self-motivated product designer to join our team of talented developers and designers on a mission to make our products more accessible, simple, and secure.What you'll be doing:Collaborating with product and engineering to craft the experience for one of our core consumer product verticals (e.g. our...

  • Product Manager

    Found in: beBee jobs US - 7 days ago


    New York, New York, United States Nylas Full time

    Nylas is a pioneer and leading provider of productivity infrastructure solutions for modern software. Over 100,000+ developers worldwide use the Nylas platform to quickly and securely build productivity features into their applications. With Nylas, developers get unprecedented access to rich communications data from their end-users, pre-built workflows that...

  • Senior Software Security Engineer

    Found in: beBee jobs US - 7 days ago


    New York, New York, United States Motion Recruitment Full time

    A marketing automation SaaS company is looking for a Senior Software Security Engineer to work with their development team. We're looking for someone who comes from a software development background and is also comfortable working with SDLC security tooling, like SAST and web app penetration testing tooling. You'll be helping to develop our application while...

  • Senior Software Engineer, New Products

    Found in: beBee jobs US - 7 days ago


    New York, New York, United States Justworks Full time

    Who You AreAre you passionate about design and development? Do you have experience building, deploying, and maintaining large-scale, distributed applications? Are you ready to take your skills to the next level and join a team of innovative self-starters in a supportive, entrepreneurial environment?As a Senior Fullstack Software Engineer on Justworks' New...

  • Product Manager

    Found in: beBee jobs US - 7 days ago


    New York, New York, United States Nylas Full time

    Nylas is a pioneer and leading provider of productivity infrastructure solutions for modern software. Over 100,000+ developers worldwide use the Nylas platform to quickly and securely build productivity features into their applications. With Nylas, developers get unprecedented access to rich communications data from their end-users, pre-built workflows that...

  • Senior Product Manager

    Found in: beBee jobs US - 2 weeks ago


    New York, New York, United States Unit21 Full time

    About Unit21:Unit21 protects businesses against adversaries engaging in money laundering, fraud, and other sophisticated risks by offering a no-code toolset to model, detect, and remediate suspicious activity. We are backed by investments from Google, Tiger Global, ICONIQ, Diane Greene (Google / Google Cloud), Jack Dorsey (Block / Twitter), William Hockey...

  • Principal Infrastructure Engineer

    Found in: beBee jobs US - 2 weeks ago


    New York, New York, United States Paradigm Full time

    The roleAs a core member of our infrastructure team, you will build and maintain major features, through inception, design, implementation and launch, working closely with product and engineering disciplines across the company. You will spend the majority of your time on cross-functional self-contained feature teams focused on delivering value to the...

  • DevSecOps Engineer

    Found in: beBee jobs US - 7 days ago


    New York, New York, United States Knotch Full time

    About KnotchKnotch is a Content Intelligence Platform that enables brands to drive business growth through content. We build products for people who use content to drive performance. We also offer Strategic Consulting services which enable brands to achieve new levels of efficiency and effectiveness through ongoing and ad hoc support. Knotch gives marketers...

  • Software Engineer

    Found in: beBee jobs US - 2 weeks ago


    New York, New York, United States Citadel Securities Full time

    Job DescriptionAt Citadel Securities, our engineers work in small teams to turn the best ideas into high-performing and resilient technology. With short development cycles, work rapidly goes into production. As an engineer, you can create systems architectures, develop platforms and build web frameworks. You'll have access to state-of-the-art tools and apply...