Veeam

Product & Application Security Engineer

$238K–$442KFull-time · San Francisco, CA
✓ Verified live on the employer's own system · added 3 days ago
Save search

Skills & tools

SecurityLogisticsManagementDevopsRecordkeepingJavascriptCloud PlatformsGolang
Apply on company site ↗ See your fit → free

Full job description

We are looking for a Senior Security Engineer who thinks like a product architect and codes like a software engineer. At Veeam Kasten, we release market-leading Kubernetes data protection software, which makes security critical to safeguarding our customers' environments and data. This role ensures security is embedded throughout the lifecycle, not just as a gate at the end.

You will partner with engineering teams during the whiteboard phase to design secure features and dive into the codebase to find and fix vulnerabilities.

- Design & Architecture: You will be the primary security voice in design reviews. You will perform threat modeling on new features, identifying architectural risks before a single line of code is written - Code-Level Security: You will actively review Pull Requests and conduct deep-dive code audits. You won't just run scanners; you will manually analyze logic in our code to find complex flaws that automated tools miss - Vulnerability Remediation: unlike traditional security roles that only "report" bugs, you will help fix them.

You will triage findings from our tooling and write production-ready patches to resolve vulnerabilities - Secure Software Supply Chain: You will oversee the integrity of our build dependencies, ensuring that the open-source libraries we import (and the tools we use to build them) are secure

- Triage and fix security alerts from tools like Grype, Cycode, and Wiz - Implement code fixes for security tech-debt across our stack - Conduct Threat Modeling sessions for upcoming epics and features in our two-week sprint cycles - Serve as a Subject Matter Expert on Kubernetes security primitives (RBAC, unprivileged containers, network policies) for the engineering team, owning metrics and definition of success, share best practices through workshops, reviews, and documentation - Lead audits, incidents, and compliance reviews representing the engineering team with the wider security community in Veeam

Core: Go, Vue.js, Docker, Kubernetes Security Tooling: Grype, Syft, Checkmarx, Cycode, Wiz Environment: Public Cloud (Azure/AWS/GCP), On-Prem K8s distributions (OpenShift, Tanzu)

- Developer DNA: You are a competent developer in Go (Golang) and have exposure to modern frontend frameworks like Vue.js. - Kubernetes Native: Youʼve worked extensively with Kubernetes and understand itʼs security primitives. - Shift-Left Mindset: You have experience integrating security into the early stages of the Software Development Life Cycle. - Tooling Familiarity: Experience with modern AppSec and Supply Chain tools (specifically Grype, Cycode, and Wiz) is a strong plus. - Pragmatism: You can balance theoretical security perfection with the practical reality of shipping software on a continuously frequent basis.

More jobs at Veeam

Similar jobs near San Francisco, CA

Tell me when more Senior Software Engineer, Security jobs post near San Francisco, CA - US We re-check every listing against the employer’s own board — no résumé needed.

Search Product & Application Security Engineer jobs near San Francisco, CA → Browse all live jobs

This posting was published by Veeam on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.