Senior Software Security Engineer

Spectro CloudSan Jose, CA
Hybrid

About The Position

Spectro Cloud enables organizations globally to manage AI infrastructure at scale, offering a unified orchestration plane for full-stack AI and modern infrastructure across edge, data center, and cloud environments. The company is experiencing rapid growth, serving Global 5000 and government organizations for tasks like building AI factories, scaling edge inferencing, and managing multi-cloud Kubernetes fleets. Spectro Cloud is backed by top-tier investors. The team is a rapidly growing startup looking for a hands-on Software Security Engineer to integrate security throughout the engineering lifecycle, with a primary focus on securing their Kubernetes-based production platform. This role is for a builder who enjoys securing real systems, driving threat modeling, secure code reviews, and designing and implementing security controls to actively contribute to platform defense. The engineer will own end-to-end security across the platform and product, including vulnerability management, security architecture reviews, and incident response, focusing on vulnerabilities and misconfigurations in Kubernetes environments to ensure they are secure, compliant, and continuously monitored. The goal is to proactively improve developer velocity by shifting security left and enabling product delivery.

Requirements

  • 6+ years of experience in Software Security, Product Security, or DevSecOps
  • 2+ years in a technical leadership or mentorship role
  • Deep, hands-on expertise in Kubernetes security and cloud-native systems
  • Strong experience securing Linux, containers, and cloud platforms (AWS, GCP, or Azure)
  • Proven track record managing real-world security incidents in production environments
  • Strong programming/scripting skills (Go, Python, Bash, or similar)
  • Solid understanding of compliance frameworks (FIPS, CIS, STIG) and their practical application
  • Hands-on experience with image hardening and secure system configurations
  • Experience driving penetration testing programs and managing external vendors

Nice To Haves

  • Experience building or scaling DevSecOps programs in a startup environment
  • Familiarity with tools such as Falco, Tenable, Elastic, Trivy
  • Knowledge of service meshes, network policies, and runtime security
  • Strong background in threat modeling and secure system design
  • Relevant certifications (CKS, CISSP, CCSP, GSEC, etc.)

Responsibilities

  • Design, implement, and operate security controls for Kubernetes-based production platforms
  • Harden containers, nodes, and cluster configurations to meet production-grade security standards
  • Conduct in-depth security reviews of infrastructure using IaC practices (Terraform, Helm, GitOps)
  • Implement and automate security enforcement via scripts, policies, and tooling (e.g., OPA, Kyverno, admission controllers)
  • Perform architecture and design reviews with a focus on least privilege, defense-in-depth, and attack surface reduction
  • Advance platform security monitoring through logging, alerting, and SIEM integrations
  • Build automation (Bash, Python, Go) to scale security operations and reduce manual effort
  • Apply AI/ML techniques to detect anomalous behavior, zero-day threats, and advanced attack patterns
  • Leverage AI-driven tools for policy generation, risk scoring, and remediation prioritization
  • Develop approaches to identify configuration drift and misconfigurations across Kubernetes and IaC environments
  • Lead and evolve incident response processes; act as a primary escalation point when needed
  • Conduct blameless post-mortems and ensure timely remediation of security gaps
  • Own vulnerability management across platform, cloud, and application layers
  • Strengthen security posture through baseline standardization and operational readiness
  • Oversee secrets management, encryption strategies, and access control policies
  • Champion a “Security as Code” mindset and promote shared ownership through Security Champions programs
  • Balance startup speed with scalable, long-term security practices
  • Partner closely with engineering teams to embed security into development workflows (DevSecOps)
  • Collaborate with SRE on platform hardening, incident response, and reliability improvements
  • Clearly communicate security risks and posture to technical and executive stakeholders

Benefits

  • Compensation: $185,000-$215,000 (Base + Bonus) + Equity, based on experience
  • Comprehensive medical, dental, and vision coverage. 100% coverage for employees, 90% for dependents
  • Access to a retirement savings plan
  • Flexible time off, including 12 paid holidays
  • Catered lunches on in-office days
  • Mobile/internet reimbursement
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service