Cloudera

Staff Security Engineer, Product Security

Remote
Python Java JavaScript TypeScript Bash SQL Kubernetes Docker AWS Azure GCP Terraform Ansible Jenkins GitLab CI GitHub Actions SAST DAST SCA IAST HashiCorp Vault Splunk Microservices API
Description

Senior Security Engineer - Product Security

Location: US-Texas-Remote

Remote Type: Remote

Time Type: Full time

Job Description

Business Area:

Engineering

Seniority Level:

Mid-Senior level

Job Description: 

At Cloudera, we empower people to transform complex data into clear and actionable insights. With as much data under management as the hyperscalers, we're the preferred data partner for the top companies in almost every industry.  Powered by the relentless innovation of the open source community, Cloudera advances digital transformation for the world’s largest enterprises.

Senior DevSecOps Engineer

Are you passionate about building a robust security platform that seamlessly integrates security into every phase of the software and infrastructure lifecycle? Do you want to lead the adoption of advanced DevSecOps practices, influence product design at the earliest stage, and get your hands dirty implementing sophisticated, highly automated security tooling for multi-cloud and on-prem environments? Great, we've got the position for you!

Cloudera is looking for a Senior DevSecOps Engineer with deep expertise in multi-cloud and on-prem security engineering to join a unique blended team. Bringing both security platform development knowledge and application security know-how, you and our highly collaborative team will play a crucial role in building the security platform that underpins all of Cloudera’s products.

In this role, you will be a core member of our Product Security (ProdSec) Platform team charged with engineering, deploying, maintaining, and operationalizing our internal security platform providing self-service tools to enable product teams to build and deploy securely by default. You will work as a critical part of our product security development process, driving change at the design stage through automated governance and providing consultation on how to leverage the platform's capabilities.

Our goal is to shift security left by building a mature, automated platform that reduces security toil for developers & security staff by allowing them to focus on innovation while ensuring security by design. You will be instrumental in identifying product security pain points and solving them with scalable, platform-based solutions, driving a cycle of continuous improvement across our product portfolio.

We’re looking for individuals who want to redefine how security is delivered in a high-velocity engineering organization. You will have the opportunity to teach and learn from Kubernetes trailblazers and help blaze new paths for those following behind you.

As a DevSecOps Engineer, you will:

  • Design, develop, and deploy self-service security tools and services that constitute the internal security platform.

  • Lead complex security projects, including end-to-end ownership of tool development and the creation of new security capabilities within the platform.

  • Automate and integrate security controls into CI/CD pipelines (SAST, DAST, SCA, IAST, etc.) and developer workflows.

  • Lead the architecture and deployment of secure multi-cloud environments (AWS, Azure, GCP) using Infrastructure as Code (e.g., Terraform, Ansible).

  • Perform security architecture reviews of new products and features, develop threat models, and provide security-as-code best practices.

  • Collaborate with the Site Reliability Engineering (SRE) team to embed & maintain automated monitoring and security visibility into production systems.

  • Collaborate with internal security teams to support compliance, incident response, and operational security requirements.

  • Develop, refine, and drive the adoption of security engineering best practices and standards across the organization.

  • Evangelize the use of security platform tooling and deliver high-impact DevSecOps training and outreach to internal development & engineering teams.

  • Mentor junior members of the Security team and security advocates in advanced DevSecOps principles, platform engineering, and secure coding practices.

We’re excited about you if you have:

  • Proven experience designing, developing, and deploying security tools and services (e.g., security scanners, secrets management, policy engines) used by other engineering & security teams.

  • Expertise in DevSecOps principles and practical experience implementing security controls in CI/CD pipelines (e.g., Jenkins, GitLab CI, GitHub Actions).

  • Deep experience with large-scale cloud security engineering in AWS, Azure, and Google Cloud, including automated network provisioning and secure configuration management.

  • Experience with code review of one or more programming languages (Java, Python, Go, JS/TS).

  • In-depth knowledge of Kubernetes operations, security, and using tools like Helm for deployment and policy enforcement.

  • Expertise in Infrastructure as Code (IaC) & configuration management tools like Terraform, Cloudformation, or Ansible.

  • Demonstrated experience with security tools and platforms, including HashiCorp Vault for secrets management, Splunk for security monitoring and analytics, and CrowdStrike or similar EDR solutions for endpoint security.

  • Deep understanding of web service frameworks, distributed architectures (event-driven, microservices, serverless), and their corresponding security challenges.

  • Experience performing security reviews, developing and reviewing threat models, and conducting risk assessments against complex distributed systems.

  • Security certifications (CISSP, CISA, etc.) are a bonus but not required.

  • Familiarity with Cloudera’s products or other distributed computing systems is a strong bonus, or a willingness to dig into our products to truly understand how they work.

This role is not eligible for immigration sponsorship.

What you can expect from us:

  • Generous PTO Policy 

  • Support work life balance with Unplugged Days

  • Flexible WFH Policy 

  • Mental & Physical Wellness programs 

  • Phone and Internet Reimbursement program 

  • Access to Continued Career Development 

  • Comprehensive Benefits and Competitive Packages 

  • Paid Volunteer Time

  • Employee Resource Groups

EEO/VEVRAA

#LI-MH2

#LI-remote

Cloudera
Cloudera

0 applies

0 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say