Product and Application Security Engineer

Veeam SoftwareSan Jose, CA

About The Position

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands. About the Role We are looking for a Senior Security Engineer who thinks like a product architect and codes like a software engineer. At Veeam Kasten, we release market-leading Kubernetes data protection software, which makes security critical to safeguarding our customers’ environments and data. This role ensures security is embedded throughout the lifecycle, not just as a gate at the end. You will partner with engineering teams during the whiteboard phase to design secure features and dive into the codebase to find and fix vulnerabilities. Your Impact Design & Architecture: You will be the primary security voice in design reviews. You will perform threat modeling on new features, identifying architectural risks before a single line of code is written. Code-Level Security: You will actively review Pull Requests and conduct deep-dive code audits. You won't just run scanners; you will manually analyze logic in our code to find complex flaws that automated tools miss. Vulnerability Remediation: unlike traditional security roles that only "report" bugs, you will help fix them. You will triage findings from our tooling and write production-ready patches to resolve vulnerabilities. Secure Software Supply Chain: You will oversee the integrity of our build dependencies, ensuring that the open-source libraries we import (and the tools we use to build them) are secure. Why this role is different Most security roles keep you on the sidelines running scanners. This role puts you in the IDE and on the whiteboard. You will have the authority to influence product design and the capability to contribute code that makes our product safer. You will partner not only with the engineering team in Kasten but with the Product team and the wider Global Information Security teams in Veeam.

Requirements

  • Developer DNA: You are a competent developer in Go (Golang) and have exposure to modern frontend frameworks like Vue.js
  • Kubernetes Native: You’ve worked extensively with Kubernetes and understand it’s security primitives
  • Shift-Left Mindset: You have experience integrating security into the early stages of the Software Development Life Cycle
  • Tooling Familiarity: Experience with modern AppSec and Supply Chain tools (specifically Grype, Cycode, and Wiz) is a strong plus
  • Pragmatism: You can balance theoretical security perfection with the practical reality of shipping software on a continuously frequent basis

Responsibilities

  • Triage and fix security alerts from tools like Grype, Cycode, and Wiz
  • Implement code fixes for security tech-debt across our stack
  • Conduct Threat Modeling sessions for upcoming epics and features in our two-week sprint cycles
  • Serve as a Subject Matter Expert SME) on Kubernetes security primitives RBAC, unprivileged containers, network policies) for the engineering team, owning metrics and definition of success, share best practices thorough workshops, reviews, and documentation
  • Lead audits, incidents and compliance reviews representing the engineering team with the wider security community in Veeam

Benefits

  • Unlimited paid time off, 12 paid holidays, plus 4 extra global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
  • Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
  • Medical, dental, and vision coverage starting on your first day
  • Mental health support, therapy sessions, and digital wellness tools via our Employee Assistance Program
  • 401(k) retirement plan with company matching contributions
  • Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
  • AirVet: 24/7 virtual veterinary care at no cost
  • Legal services, identity protection, and supplemental health insurance options
  • Tax-advantaged spending accounts for healthcare, dependent care, and commuting
  • Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

11-50 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service