Jobs and Careers
MI
Senior Product Security Engineer
MirantisCzechiafull_timeVerifiedPosted 31 Oct 2025
About the role
<h3>Company Description</h3><p><strong>About Mirantis</strong></p><p>Mirantis is the Kubernetes-native AI infrastructure company, enabling organizations to build and operate scalable, secure, and sovereign infrastructure for modern AI, machine learning, and data-intensive applications. By combining open source innovation with deep expertise in Kubernetes orchestration, Mirantis empowers platform engineering teams to deliver composable, production-ready developer platforms across any environment—on-premises, in the cloud, at the edge, or in sovereign data centers. As enterprises navigate the growing complexity of AI-driven workloads, Mirantis delivers the automation, GPU orchestration, and policy-driven control needed to manage infrastructure with confidence and agility. Committed to open standards and freedom from lock-in, Mirantis ensures that customers retain full control of their infrastructure strategy.</p><p> </p><h3>Job Description</h3><p>Mirantis is seeking a <strong>Senior Product Security Engineer</strong> to help secure our portfolio of products and services, including enterprise software and critical infrastructure. This role is part of our growing<strong> Product Security program</strong> and will play a key role in implementing security controls, driving remediation efforts, supporting compliance initiatives, and partnering with engineering teams to ensure a secure software development lifecycle.</p><p>As a Senior Product Security Engineer, you will work closely with engineering, security operations, and compliance teams to reduce risk across Mirantis products. You will have the opportunity to shape security strategy, automate controls, and ensure security is embedded into every stage of product development and operations.</p><p><strong>Key Responsibilities</strong></p><ul><li><p><strong>Secure Products & Infrastructure:</strong><br/>
- Design, implement, and maintain security controls across applications, infrastructure, and CI/CD pipelines to align with internal security standards and regulatory frameworks (e.g., SOC 2, ISO 27001).<br/>
- Drive adoption of modern security tooling and practices including SAST, DAST, container image scanning, Infrastructure as Code (IaC) security, and dependency analysis.</p></li><li><p><strong>Offensive Security & Vulnerability Management:</strong><br/>
- Lead vulnerability assessments, application security reviews, and penetration tests.<br/>
- Triage and prioritize findings, collaborating with product and engineering teams to drive timely and measurable remediation.<br/>
- Proactively identify and exploit vulnerabilities to strengthen product security posture.</p></li><li><p><strong>Incident Response Support:</strong><br/>
- Partner with Security Operations and Engineering to investigate application and infrastructure vulnerabilities. Contribute to root cause analysis, remediation plans, and long-term risk reduction.</p></li><li><p><strong>Compliance & Assurance:</strong><br/>
- Support security reviews, audits, and compliance initiatives through documentation, evidence collection, and coordination with external auditors or vendors.</p></li><li><p><strong>Cross-Product Security Coverage:</strong><br/>
- Build and maintain security expertise across multiple Mirantis products to strengthen team resilience, provide flexible coverage, and help shape a scalable, sustainable Product Security program.</p></li><li><p><strong>Security Advocacy & Enablement:</strong><br/>
- Champion secure design and development practices, provide actionable guidance during security reviews, and drive security automation efforts across the SDLC.</p></li></ul><h3>Qualifications</h3><ul><li><p>5+ years of experience in product security, application security, or a related security engineering role.</p></li><li><p>Strong understanding of common vulnerabilities (e.g., OWASP Top 10, SANS Top 25) and secure development best practices.</p></li><li><p>Demonstrated experience performing offensive security activities such as manual penetration testing, threat modeling, and exploitation of vulnerabilities.</p></li><li><p>Hands-on experience with security testing and automation, including:<br/>
</p><ul><li><p><strong>SAST/DAST tooling and pipelines</strong><br/>
</p></li><li><p><strong>Container image scanning</strong> (e.g., Trivy, Grype, Anchore)<br/>
</p></li><li><p><strong>IaC security (</strong>e.g., Terraform, Helm, Kics, Checkov)<br/>
</p></li><li><p><strong>Dependency and supply chain security tooling</strong><br/>
</p></li></ul></li><li><p>Familiarity with vulnerability scanning and management tools, application security testing, and manual review techniques.<br/>
</p></li><li><p>Experience with containerized environments, Kubernetes, and cloud platforms.<br/>
</p></li><li><p>Proven ability to integrate security controls into CI/CD pipelines and automate security testing as part of the SDLC.<br/>
</p></li><li><p>Excellent collaboration and communication skills, wit
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s