Senior Product Security Engineer
Have you ever wondered what happens inside the cloud?
Based in New York, DigitalOcean is a dynamic, high-growth technology company that serves a robust and passionate community of developers, teams, and businesses around the world. We believe that today’s entrepreneurs are changing the world through software. Our mission is to empower these entrepreneurs by bringing modern app development within reach for any developer, anywhere in the world.
We want people who are passionate about making the internet a safer place for everyone.
We're looking for a Senior Product Security Engineer to solve large-scale, across-the-stack, security challenges in our products and infrastructure. Your work will make our million+ customers and tens of thousands of hypervisors more secure, and will help ensure that DigitalOcean is a respected contributor to the broader security community.
You'll report to the Director of Product & Infrastructure Security and will work with the rest of DigitalOcean to find innovative ways to make the systems we build as safe as possible. Your technical contributions could include building central systems for the rest of DigitalOcean engineering to use, developing new testing tools for internal or external deployment, supporting large transformation projects, and advising other teams on the best ways to handle new vulnerabilities.
Our customers trust us with their data and operations, and we take that responsibility seriously. Security at DO means solving incredibly complex problems at a high-scale that have real impact for our customers, our products, and for the larger internet community.
What You’ll Be Doing:
- Identify systemic problems in our environment, then shepherd developing and deploying security capabilities at scale, using languages such as Go and Ruby, and tools such as Kubernetes, Docker, and Chef.
- Partner with product teams to make sure that we deliver an excellent and secure workflow spanning development, deployment, and production monitoring.
- Participate in architecture reviews to identify risks in new systems and prioritize remediation work.
- Review & triage results coming from existing controls (e.g. bug bounties, image reviews, 3rd party contributors, etc.). Optimize these systems as necessary.
- Advise engineering teams on how to best address vulnerabilities in our environment.
- Coordinate with our SOC to improve the scope of our production monitoring.
- Participate in outreach to our engineers (e.g. developer training, office hours, internal CTFs).
What We’ll Expect From You:
- Strong communication skills, both written and verbal.
- A habit of approaching security problems with creativity and flexibility that takes the entire stack into consideration.
- Demonstrable experience securing large scale environments under very active development.
- Demonstrable experience collaborating with internal engineering teams.
- Working knowledge of modern development concepts (virtualized environments, continuous integration & delivery, containerization), network architecture, and system architecture.
- Software engineering experience (you can write robust code with good test coverage and can point to specific examples of projects you’ve successfully delivered in the past).
- Expertise with at least one of the following languages:
Go, Ruby, Python, C/C++ - Experience with appsec (Static/dynamic) and collaborating with developers to drive improvements.
Why You’ll Like Working for DigitalOcean:
- We value development. You will work with some of the smartest and most interesting people in the industry. We are a high-performance organization that is always challenging ourselves to continuously grow. We maintain a growth mindset in everything we do and invest deeply in employee development through formalized mentorship, LinkedIn Learning tracks, and other internal programs. We also provide all employees with reimbursement for relevant conferences, training, and education.
- We care about your physical, financial and mental well-being. We offer competitive health, dental, and vision benefits for employees and their dependents, a monthly gym reimbursement to support your physical health, and a commute or internet allowance to make your trips to your office or your desk easier. We offer generous parental leave with transition time built-in upon return to work. We offer competitive compensation and a 401k plan with up to a 4% employer match.
- We support our remote employee experience. While we have great office spaces in NYC, Cambridge and Palo Alto, we’re very distributed—we use a number of communication tools to connect across the company—and all remote employees have the opportunity to visit our offices and meet their teams face-to-face at team offsites. We also have an annual company offsite, Shark Week, to get quality in-person time with the entire company at least once a year. We also allow employees to outfit their workstations to meet their needs—whether remote or in office.
- We value diversity and inclusivity. We are an equal opportunity employer and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Department: Security #LI-Remote
Want to learn more about our Security team? Click here!
Want an inside look into life at DO? Click here to hear from our employees!