Staff Product Security Engineer
DDNAbout the role
Overview
This is an incredible opportunity to be part of a company that has been at the forefront of AI and high-performance data storage innovation for over two decades. DataDirect Networks (DDN) is a global market leader renowned for powering many of the world's most demanding AI data centers, in industries ranging from life sciences and healthcare to financial services, autonomous cars, Government, academia, research and manufacturing.
"DDN's A3I solutions are transforming the landscape of AI infrastructure." – IDC
“The real differentiator is DDN. I never hesitate to recommend DDN. DDN is the de facto name for AI Storage in high performance environments” - Marc Hamilton, VP, Solutions Architecture & Engineering | NVIDIA
DDN is the global leader in AI and multi-cloud data management at scale. Our cutting-edge data intelligence platform is designed to accelerate AI workloads, enabling organizations to extract maximum value from their data. With a proven track record of performance, reliability, and scalability, DDN empowers businesses to tackle the most challenging AI and data-intensive workloads with confidence.
Our success is driven by our unwavering commitment to innovation, customer-centricity, and a team of passionate professionals who bring their expertise and dedication to every project. This is a chance to make a significant impact at a company that is shaping the future of AI and data management.
Our commitment to innovation, customer success, and market leadership makes this an exciting and rewarding role for a driven professional looking to make a lasting impact in the world of AI and data storage.
Job Description
As a Staff Product Security Engineer – Infinia, you’ll play a foundational role in how we build and secure one of our most critical products. This is a high-impact, hands-on engineering role focused on embedding security into our development lifecycle, tooling, and infrastructure — without slowing product velocity.
You’ll work closely with DevOps, Engineering, and Compliance partners to drive vulnerability remediation, threat modeling, and secure-by-default architecture. You’ll also lead efforts to integrate automated security checks (SCA, SAST, DAST, secrets detection) into our CI/CD workflows and influence engineering culture with scalable, developer-friendly practices.
Key Responsibilities
Security Integration & Engineering Partnership
- Lead vulnerability triage and remediation with engineering and DevOps teams
- Integrate and manage security tooling (SCA, SAST, DAST, secrets detection) in CI/CD pipelines
- Collaborate with DevOps to embed security controls with smooth pipeline operations.
- Conduct threat modeling and secure design reviews for high-impact features
Technical Leadership & Enablement
- Develop automated workflows for vulnerability tracking, ticketing, and alerting
- Author security best practices, code hardening guides, and internal playbooks
- Act as a senior security voice during architecture reviews and design discussions
- Contribute to onboarding and enablement of security-minded engineering habits
Forward Planning & Operational Security
- Support customer security assessments and internal reviews
- Guide adoption of security baselines aligned to CIS/NIST frameworks
- Influence product roadmap decisions with a security-first mindset
Required Qualifications
- 8+ years in product/application security or secure software development
- Proven experience with SAST/SCA tooling and secure CI/CD pipelines
- Strong understanding of secure design principles (authN/authZ, input validation, etc.)
- Familiarity with cloud infrastructure (AWS/GCP), containers, and modern DevOps workflows
- Excellent collaboration skills across engineering, DevOps, and product
Preferred Qualifications
- Familiarity with tools like Trivy, Semgrep, tfsec, Checkov
- Experience with IaC security, Kubernetes hardening, or pipeline guardrails
- Exposure to frameworks like NIST 800-53, CIS Benchmarks, or OWASP SAMM
- Participation in secure coding education or developer security programs
This position requires participation in an on-call rotation to provide after-hours support as needed.
Success Metrics – First 30 Days
- Review and validate existing security tool integrations
- Shadow vulnerability remediation workflows
- Deliver recommendations for improving CI/CD security checks
- Identify priority areas for hardening and developer guidance<
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s