← Back to results

Software Engineer, Security

Join Factory as a Security Engineer to enhance the security of our platform and collaborate with engineering teams on best practices.

Location
San Francisco, CA
Compensation
Not disclosed
Level
senior
Type
full time · On-site

Posted by employer 2 years ago

First seen on Joblaze 1 week ago

Last verified on the company career page 1 day ago

Apply at Factory → Save job Scanned from factory.ai

Requirements

Experience
5+ years

Not disclosed in this posting: compensation, visa sponsorship.

Joblaze summary

In this role, the Security Engineer at Factory is responsible for developing and maintaining robust security measures for the company's cloud infrastructure and applications. Key skills include proficiency in TypeScript and Python, along with experience in Kubernetes, CI/CD, and cloud security practices. This position is ideal for a seasoned professional with over five years of experience in product security, particularly in cloud environments. The role emphasizes collaboration with engineering teams to integrate security throughout the software development lifecycle.

Joblaze insights

Quick facts

Is the Software Engineer, Security role remote?
No — this is an on-site role in San Francisco, CA.
How much experience is required?
At least 5 years of relevant experience for this Software Engineer, Security role.
Where is the role based?
Factory is hiring for this position in San Francisco, CA.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Azure, CI/CD, Docker, GCP, GDPR.
What seniority level is this role?
Factory targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Software Engineer, Security role at Factory.

From the original posting

About the Role

Factory is seeking a talented Security Engineer to join our team. In this role, you will play a critical role in developing and maintaining the security foundation of our platform. You will conduct in-depth code reviews, implement security best practices, and influence the overall security strategy. Your expertise in TypeScript, Python, Kubernetes, CI/CD, and terraform orchestration will be crucial in identifying and mitigating potential security vulnerabilities.

What you will do and achieve

  • Design, implement, and manage security measures for the protection of our cloud infrastructure, applications, and data, focusing on both preventative controls and rapid response capabilities.

  • Collaborate closely with our engineering teams to integrate security practices into the software development lifecycle, including secure coding standards, automated security testing, and secure architecture design.

  • Stay up-to-date on the latest security threats, vulnerabilities, and mitigation strategies.

  • Conduct security code reviews to identify and remediate security vulnerabilities.

  • Develop and implement automated security testing procedures to identify vulnerabilities and risks, recommending and implementing appropriate mitigation strategies.

  • Respond to security incidents and participate in incident response procedures.

  • Document security processes, procedures, and best practices.

  • Lead security awareness and training programs, empowering all team members to recognize and prevent potential security threats.

Qualifications

  • Minimum 5+ years of experience as a Security Engineer with a focus on product security, with a strong background in securing cloud-based environments (AWS, Azure, GCP) and understanding of Infrastructure as Code (IaC) security practices.

  • Strong coding skills with proficiency in TypeScript and Python.

  • Expertise in various security domains such as application security, network security, security operations, and incident response.

  • Experience with container security (Docker Security, Kubernetes Security).

  • Familiarity with a wide range of AWS services, including but not limited to VPC, EC2, Lambda, Amazon RDS, and S3.

  • In-depth knowledge of CI/CD pipeline tools and practices, ideally with experience in GitHub Actions or Jenkins.

  • Knowledgeable in security compliance frameworks and regulations (e.g., ISO 27001, SOC 2, GDPR) and experience with security assessments and third-party audits.

  • Proficiency with security tools and technologies, such as firewalls, IDS/IPS, vulnerability scanners, WAF, SIEM, and encryption solutions.

  • Demonstrated ability to influence security strategies and drive improvements within a team.

This is an in-office position (5 days/week) in San Francisco (walking distance to Caltrain)

Similar positions

Factory
Software Engineer, Product
Factory · San Francisco, CA
Factory
Software Engineer, Fullstack
Factory · San Francisco, CA
Factory
Technical Support Engineer - US
Factory · San Francisco, CA
Factory
Software Engineer, Data
Factory · San Francisco, CA
Factory
Software Engineer, Deployed
Factory · San Francisco, CA