About the Role
We are seeking a Senior Security Engineer with a product architect mindset and software engineering coding skills to join Veeam Kasten. This role is crucial for embedding security throughout the product lifecycle, from initial design to code-level vulnerability identification and remediation, ensuring the security of our market-leading Kubernetes data protection software.
Responsibilities
- Design secure features in collaboration with engineering teams during the whiteboard phase.
- Dive into the codebase to find and fix vulnerabilities.
- Perform threat modeling on new features, identifying architectural risks.
- Actively review Pull Requests and conduct deep-dive code audits.
- Manually analyze code logic to find complex flaws missed by automated tools.
- Triage findings from security tooling and write production-ready patches.
- Oversee the integrity of build dependencies and secure open-source libraries.
- Triage and fix security alerts from tools like Grype, Cycode, and Wiz.
- Implement code fixes for security tech-debt across the stack.
- Conduct Threat Modeling sessions for upcoming epics and features.
- Serve as a Subject Matter Expert on Kubernetes security primitives (RBAC, unprivileged containers, network policies).
- Own metrics and definition of success for Kubernetes security.
- Share best practices through workshops, reviews, and documentation.
- Lead audits, incidents, and compliance reviews representing the engineering team.
Requirements
- Competent developer in Go (Golang).
- Exposure to modern frontend frameworks like Vue.js.
- Extensive experience with Kubernetes and understanding of its security primitives.
- Experience integrating security into the early stages of the Software Development Life Cycle (Shift-Left Mindset).
- Experience with modern AppSec and Supply Chain tools (specifically Grype, Cycode, and Wiz) is a strong plus.
- Ability to balance theoretical security perfection with the practical reality of shipping software frequently.
Skills
- Go
- Vue.js
- Docker
- Kubernetes
- Grype
- Syft
- Checkmarx
- Cycode
- Wiz
- RBAC
- Unprivileged containers
- Network policies
- AppSec tooling
- Supply Chain tooling
- Threat Modeling
- Code Auditing
- Vulnerability Remediation
Location
- Seattle
- Offices in more than 30 countries
Work Type
- Full-time
Experience Level
- Senior
Salary/Compensations
- Zone 1: $237,800—$441,500 USD
- Zone 2: $218,000—$404,700 USD
- Zone 3: $198,100—$367,900 USD
- Zone 4: $172,400—$320,100 USD
Benefits
- Unlimited paid time off
- 12 paid holidays
- 4 global VeeaMe Days for self-care
- 24 paid volunteer hours annually
- Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
- Medical, dental, and vision coverage starting on your first day
- Mental health support, therapy sessions, and digital wellness tools
- 401(k) retirement plan with company matching contributions
- Fertility, adoption, and surrogacy support
- AirVet: 24/7 virtual veterinary care
- Legal services
- Identity protection
- Supplemental health insurance options
- Tax-advantaged spending accounts for healthcare, dependent care, and commuting
- Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events
About the Company
- Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale.
- Market leader in both data resilience and data security posture management.
- Veeam is built for the convergence of identity, data, security, and AI risk.
- Headquartered in Seattle with offices in more than 30 countries.
- Protects over 550,000 customers worldwide.
- Veeam protects customers' businesses, enabling them to go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.
Equal Opportunity
- Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law.
- All your information will be kept confidential.
