Jobs and Careers
PA

Security Engineer 4

PagerDuty
Remote (USA), United StatesRemotefull_timeVerifiedPosted 13 Dec 2024

About the role

PagerDuty empowers teams of all kinds to do the critical work that moves business forward through the PagerDuty Operations Cloud.

Visit our careers site to explore life at PagerDuty, discover opportunities, and sign-up for job alerts!

PagerDuty is seeking a Senior Security Engineer to join our diverse, customer-focused team! As a Senior Security Engineer, you will be a key contributor in leading security initiatives for PagerDuty’s SaaS offerings, focusing on application security through architecture reviews, threat modeling sessions, and defining secure-by-design product standards and protections that support PagerDuty’s security mission. Since we own and operate what we build, you’ll collaborate closely with engineers across many product development teams. You will work closely with our internal development teams to ensure we deliver secure, highly reliable, and scalable solutions to our customers. 

This is an exciting opportunity to build security solutions that make developers and customers happy. The ideal candidate will come from a large enterprise environment focused on establishing security standards, coordinating with product development teams, and developing strategies for secure-by-default architectures and tooling. Things that make you smile: secure product architectures, providing an engaging Developer Experience for security adoption, and cute animal memes.

KEY RESPONSIBILITIES  

  • Embrace the role of hands-on technical lead in defining product security standards and guiding platform protections.
  • Establish criteria and conduct comprehensive security reviews throughout all stages of  product development to identify and address security risks.
  • Perform regular threat assessments, coordinate with third-party testers for penetration testing, and conduct internal penetration testing to identify and mitigate security risks.
  • Mentor and guide team members to ensure product and business objectives are prioritized in project implementations, fostering a strong documentation culture with project charters and design documents. 
  • Work with loosely defined requirements where you exercise your analytical skills to clarify questions, share your approach, and collaborate with the team to design and implement effective security frameworks. Maintain a strong appetite for challenging problems with a high degree of ownership.
  • Participate in the team’s On-Call rotation, triaging and addressing security issues as they arise, and implement measures to prevent future occurrences.
  • Enable service team security implementations by developing security-as-code constructs, including infrastructure-as-code (IaC) modules, libraries and frontend components, while creating and maintaining developer-focused documentation to promote easy adoption.
  • Establish and uphold baseline standards and hardened configurations for platform components.
  • Continuously enhance security frameworks by focusing on product security standards and software supply chain protections, tailored for application security in cloud-native, microservices environments.

BASIC QUALIFICATIONS

  • 5+ years of experience as a Security Engineer focused on product and application security in a cloud-native, microservices environment, preferably within AWS.
  • Demonstrated experience with security standards and patterns for APIs, microservices, and serverless architectures, including best practices for secure SDLC integration and development.
  • Familiarity with cloud-native product technologies including:
    • Vulnerability detection (e.g., Qualys/Nessus, Wiz, Snyk)
    • SIEM (e.g., SumoLogic, LogRythm, or Splunk)
    • Container Security (e.g., Kubernetes, EKS)
    • CI/CD Discipline (e.g., CircleCI, Buildkite, Helm, Terraform, Chef)
    • Security Incident Response & Risk Management
  • 4 years of experience and proficiency in at least one programming language and framework (e.g., Python, Bash, Phoenix/Elixir, Java, Ruby on Rails). 
  • Exceptional written, oral communication, and interpersonal skills.
  • Strong organizational skills with the ability to successfully manage multiple priorities and deadlines.

PREFERRED QUALIFICATIONS

  • Strong hands-on experience in deploying secure coding practices, automation, threat modeling and application security solutions.
  • Strong understanding of modern application architectures, including microservices, containerization, and cloud-native applications. 
  • Experience with obtaining and maintaining FedRAMP authorization. 
  • Experience working at a SaaS company larger than 1,000 employees and $100M in revenue. 
  • Ability to analyze complex pr

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

PagerDuty

View company profile →