About the Role
DigitalOcean is seeking a Senior Product Security Engineer passionate about partnering with engineers to assess and mitigate security risks within their virtualization stack. This role involves owning the security risk posture, building frameworks for hypervisor risk assessment, and driving the implementation of defense-in-depth mitigations.
Responsibilities
- Propose and implement mitigations and defense-in-depth to threats discovered through threat modeling the virtualization stack.
- Provide deep technical expertise in systems architecture, kernel security features, and network architecture to build out a threat model for the virtualization stack.
- Identify the trade-offs of different solutions and recommend efficient designs that achieve both functional goals and security requirements.
- Collaborate with development teams to implement remediations and defense in depth to protect DigitalOcean’s customers’ workloads.
- Cultivate and promote a security culture.
- Mentor software engineering teams in security best practices.
- Oversee the vulnerability management program (security debt).
- Help DigitalOcean engineers understand how security events impact them.
Requirements
- Deep familiarity with at least one kernel security feature (e.g., AppArmor, SELinux, Landlock).
- Capable of assessing and understanding the performance implications of code changes to virtualization stacks (especially in Qemu and KVM), built from hands-on experience.
- A record of partnering with internal engineering teams to tackle security problems across an entire stack with empathy and creativity.
- Ability to clearly communicate security topics and vulnerability classes and provide actionable direction to product teams.
- Working knowledge of modern development concepts (virtualized environments, containerization, continuous integration + delivery).
- 5+ years of writing systems level code (embedded systems, kernel, assembly or similar).
- Experience guiding software teams on secure architecture design.
- Written code for an embedded system (raspberry pi, arduino, etc).
- Experience building or reviewing threat models and ability to craft malicious user, attacker, and abuse/misuse cases.
- An understanding of patches and mitigations for hardware side-channel attacks.
- Familiarity with object oriented and functional programming concepts, particularly with languages such as Go, Rust, or C.
Skills
- Systems architecture
- Kernel security features
- Network architecture
- Threat modeling
- Security best practices
- Vulnerability management
- Virtualization
- Containerization
- Continuous integration
- Continuous delivery
- Embedded systems
- Assembly
- Secure architecture design
- Go
- Rust
- C
Location
- Remote
Work Type
- Remote
- Full-time
Experience Level
- Senior
Salary/Compensations
- $140,000 - $175,000
Benefits
- Competitive array of benefits
- Employee Assistance Program
- Local Employee Meetups
- Flexible time off policy
- Reimbursement for relevant conferences, training, and education
- Access to LinkedIn Learning's 10,000+ courses
- Bonus in addition to base salary
- Equity compensation
- Equity grants upon hire
- Option to participate in Employee Stock Purchase Program
About the Company
- DigitalOcean is a cutting-edge technology company with an upward trajectory, proud to simplify cloud and AI so builders can spend more time creating software that changes the world.
- We value winning together—while learning, having fun, and making a profound difference for the dreamers and builders in the world.
- We are a high-performance organization that will always challenge you to think big.
- Our organizational development team will provide you with resources to ensure you keep growing.
Equal Opportunity
- DigitalOcean is an equal-opportunity employer. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.
