[Remote] Senior Product Security Engineer, Secure Design

🌍 Remote, USA 🎯 Full-time πŸ• Posted Recently

Job Description

Note: The job is a remote job and is open to candidates in USA. DigitalOcean is a cutting-edge technology company focused on simplifying cloud solutions for builders. They are seeking a Senior Product Security Engineer to assess security risks of new products and features, collaborate with teams to guide secure architecture design, and promote a security culture within the organization. Responsibilities β€’ Threat model application designs and solutions and provide security risk assessments (70%) β€’ Provide deep technical expertise in software and network architecture during holistic assessments of security layers across infrastructure, application, people, and process β€’ Collaborate with product managers, designers, and engineers to threat model and architect secure and resilient systems β€’ Identify the trade-offs of different solutions and recommend the efficient design to achieve both functional goals and security requirements β€’ Provide hands-on remediation guidance to development teams β€’ Cultivate and promote a security culture (20%) β€’ Champion an internal security culture (developer training, internal CTFs, etc.) β€’ Mentor software engineering teams in security best practices β€’ Help oversee our vulnerability management program (we call it security debt) β€’ Help DigitalOcean engineers understand how security events impact them. Do they need to worry about the next Log4j CVE? How does RetBleed impact DigitalOcean’s fleet? β€’ Build security tooling and automations to help scale the Product Security team's practices (10%) β€’ Use software architecture and coding patterns to reduce the impact of security issues β€’ Drive architecture, patterns, and processes across engineering that make security the easiest path β€’ Integrate custom security tooling into engineering workflows Skills β€’ Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities β€’ Ability to clearly communicate security topics and vulnerability classes (e.g. OWASP Top Ten) and ability to provide actionable direction to product teams β€’ A record of partnering with internal engineering teams to tackle security problems across an entire stack with empathy and creativity. Engineering teams are our partners, not our adversaries β€’ Working knowledge of modern development concepts (virtualized environments, containerization, continuous integration + delivery) β€’ 3+ years experience guiding software teams on secure architecture design β€’ Experience building or reviewing threat models and ability to craft malicious user, attacker, and abuse/misuse cases β€’ Working knowledge of hardware and software supply chain security β€’ Familiarity with object oriented and functional programming concepts, particularly with languages such as Go, JavaScript, Rust, or C Benefits β€’ Reimbursement for relevant conferences, training, and education β€’ Access to LinkedIn Learning's 10,000+ courses β€’ Employee Assistance Program β€’ Local Employee Meetups β€’ Flexible time off policy β€’ Bonus based on company and individual performance β€’ Equity compensation including equity grants upon hire and the option to participate in our Employee Stock Purchase Program Company Overview β€’ DigitalOcean provides a cloud platform to deploy, manage, and scale applications of any size. It was founded in 2012, and is headquartered in New York, New York, USA, with a workforce of 1001-5000 employees. Its website is Company H1B Sponsorship β€’ DigitalOcean has a track record of offering H1B sponsorships, with 27 in 2025, 8 in 2024, 9 in 2023, 22 in 2022, 11 in 2021, 2 in 2020. Please note that this does not guarantee sponsorship for this specific role. Apply tot his job

Ready to Apply?

Don't miss out on this amazing opportunity!

πŸš€ Apply Now

Similar Jobs

Recent Jobs

You May Also Like