Product Security Engineer, Secure Design
DigitalOcean · Seattle, WA · 3 days ago
Hybrid$114k–$142k/yrFull-time
What You’ll Do
- Threat model application designs and solutions and provide security risk assessments (70%)
- Cultivate and promote a security culture (20%)
- Build security tooling and automations to help scale the Product Security team's practices (10%)
Required Qualifications
- Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities.
- Ability to clearly communicate security topics and vulnerability classes (e.g. OWASP Top Ten) and ability to provide actionable direction to product teams.
- Record of partnering with internal engineering teams to tackle security problems across an entire stack with empathy and creativity.
- Working knowledge of modern development concepts (virtualized environments, containerization, continuous integration + delivery).
Preferred Qualifications
- 3+ years experience guiding software teams on secure architecture design.
- Experience building or reviewing threat models and ability to craft malicious user, attacker, and abuse/misuse cases.
- Familiarity with hardware and software supply chain security.
- Familiarity with object oriented and functional programming concepts, particularly with languages such as Go, JavaScript, Rust, or C.