Security Software Engineer

RokuAustin, TX
Hybrid

About The Position

Teamwork makes the stream work. Roku is changing how the world watches TV Roku is the #1 TV streaming platform in the U.S., Canada, and Mexico, and we've set our sights on powering every television in the world. Roku pioneered streaming to the TV. Our mission is to be the TV streaming platform that connects the entire TV ecosystem. We connect consumers to the content they love, enable content publishers to build and monetize large audiences, and provide advertisers unique capabilities to engage consumers. From your first day at Roku, you'll make a valuable - and valued - contribution. We're a fast-growing public company where no one is a bystander. We offer you the opportunity to delight millions of TV streamers around the world while gaining meaningful experience across a variety of disciplines. About the team The Roku Trust Engineering team is a close-knit group of professionals with a passion for information security. Our mission is to protect our customers, partners, devices, services, infrastructure, and data. We work collaboratively, sharing insights and expertise to stay ahead of the curve. Join us, and you’ll be part of a dynamic team that thrives on challenges and celebrates victories together. About the role As a Senior Security Engineer on the Trust Cloud team, your role involves architecting, designing, and implementing end-to-end security controls to impact the global user base. A key focus is on developing automated, scalable security solutions to enhance efficiency and protect Roku. This position requires expertise in cloud devops and the tools and controls to affect cloud security at scale.

Requirements

  • Strong analytical and problem-solving skills with close attention to detail.
  • 5+ years of experience and a high level of proficiency in modern DevOps and Kubernetes administration
  • Proficiency in deploying infrastructure through Terraform
  • Experience developing and maintaining environments to be compliant with regulatory standards
  • Experience working with other teams to understand their environment and help them secure their cloud deployments
  • Evidence-based approach to problem-solving
  • A strong sense of initiative and desire to help teams work through challenges to achieve secure outcomes
  • Willingness to step outside of your comfort zone and take on distinct challenges

Nice To Haves

  • Experience with multiple clouds, particularly AWS, GCP, and Azure
  • Developed and/or implemented data tagging, data catalogs, or other data protection-related activities
  • Experience designing and administering enterprise identity and access management solutions at scale (ex, AD, EntraID, Okta, etc)
  • Experience in securely running and operating web applications, web services, and service-oriented architecture in production environments
  • A proven track record of deploying and operating Kubernetes and containers in production

Responsibilities

  • Designing and implementing scalable, automated security controls for AWS and GCP using infrastructure-as-code, configuration-as-code, and policy-as-code approaches (Terraform, etc.), and developing supporting automation in Go or Python.
  • Partnering with infrastructure, platform, and application teams to embed security into application architectures and deployment workflows as part of a robust Secure Software Development Lifecycle (SSDLC).
  • Conducting security reviews and performing threat modeling for infrastructure, platform, and application initiatives.
  • Improving IAM implementations, network configurations, DNS security, and other cloud resource management practices.
  • Designing and implementing integrations with third-party security platforms to automate vulnerability management, secret detection, and cloud posture monitoring, ensuring findings are actionable and seamlessly integrated into engineering workflows.
  • Respond to cloud security incidents and use your devops skils to help triage, contain, remediate, and report
  • Leverage AI to accelerate your learning and enhance your work products
  • Driving security initiatives end-to-end — from identifying risks to delivering solutions — with high autonomy in a fast-moving environment.
  • Designing and implementing automated security controls in CI/CD pipelines using GitLab, Terraform, and policy-as-code approaches.

Benefits

  • Roku is committed to offering a diverse range of benefits as part of our compensation package to support our employees and their families.
  • Our comprehensive benefits include global access to mental health and financial wellness support and resources.
  • Local benefits include statutory and voluntary benefits which may include healthcare (medical, dental, and vision), life, accident, disability, commuter, and retirement options (401(k)/pension).
  • Our employees can take time off work for vacation and other personal reasons to balance their evolving work and life needs.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service