CockroachLabs

Software Engineer, Security - New York, NY

New York, NY
USD 174k - 230k
Kubernetes SQL AWS GCP Azure
Search for More Jobs Talk to a recruiter now 💪
Description

Databases are the beating heart of every business in the world.

Cockroach Labs is the creator of CockroachDB, the most highly evolved cloud-native, distributed SQL database on the planet that scales fast, survives anything, and thrives anywhere. We created CockroachDB to unshackle teams from the constraints of their database. Join us on our mission to simplify how businesses build and operate world-changing applications!

About the Role

Cockroach Labs is looking for passionate individuals to support our cloud security efforts. This is a hands-on role where you’ll be working with different teams across the company on a variety of technical projects related to the security of our infrastructure and cloud solution. We are looking for creative individuals, capable of combining software and systems engineering to design, develop, and automate fault-tolerant security solutions. A successful candidate will combine the technical know-how with an empathetic and compassionate approach to engaging with the product and engineering teams across Cockroach Labs. 

In this role, you’ll join a small but growing platform infrastructure security team, using your experience and skills to significantly influence the culture and practices for security engineering at Cockroach Labs.

You Will

  • Provide guidance to leadership, engineering teams, and product teams, on security related topics.
  • Design solutions to complex security problems, while balancing organizational needs and priorities.
  • Leverage security based subject matter expertise to mature the capabilities of the  security team at Cockroach Labs.
  • Define and evangelize security and vulnerability management practices within Cockroach Labs.
  • Support the ongoing process to mature the Cockroach Labs security posture, tooling, process, and overall capabilities, focusing on highly scalable and resilient security systems.
  • Act with compassion and empathy while engaging with the product and engineering teams to further the security posture of the company.
  • Influence product and engineering product feature and function decisions based on security needs of the company.
  • Support the ongoing process to pay down technical debt and reduce technical risk exposure as it relates to security risks.
  • Bring expertise in the field of cloud security in relation to AWS, GCP, and Azure cloud domains.
  • Participate in on-call rotation for security incident response process.
  • Support Cockroach Labs engineering infrastructure security through:

Expectations

In your first 30 days, you will become an integrated member of our engineering team. You’ll become familiar with our production systems, software development workflow, and application architecture for CockroachDB and CockroachCloud. We believe that it's essential for you to take this first month to become familiar with our technology and our company.

In your second month, you’ll focus on gaining familiarity with our security challenges, focusing on security challenges in both our cloud solution as well as in our overall system architecture and infrastructure. You’ll contribute to our engineering team security culture by preparing a security-focused presentation to the engineering team.

In your third month, you’ll become a point person for a major security project, taking direct ownership of a key solution and being a partner with the larger security and engineering organization to drive the project forward.

You Have

  • The qualifications below are ideal, but not all required. We strongly encourage candidates who do not have all the qualifications listed below to apply.

    • Previous experience (7+ years) in security architecture, security engineering, application security, systems engineering, or site reliability engineering (SRE)
    • 2+ years of experience in a security architect role
    • 3+ years of experience in Threat modeling, system risk assessment, or system safety thinking (e.g. STAMP/STPA)
    • 2+ years of experience with information security related compliance frameworks (PCI, SOC, FedRamp, ISO, GDPR, etc.)
    • Hands-on experience with AWS, Azure, or GCP, ideally with a focus on securing public cloud environments
    • Overseen a vulnerability management program to proactively identify, classify, remediate, and mitigate vulnerabilities.
    • Hands-on experience with open-source security (OSS), static application security testing, and dynamic application security testing tools.
    • Knowledge of Kubernetes, HashiCorp suite of tools, infrastructure-as-code (IaC), or alternate cloud or CI/CD platform tooling
    • Solid understanding of networking concepts and cloud security best practices
    • Knowledge of application security and common application security vulnerabilities such as OWASP Top 10
    • The desire and capability to take a structured approach to solving large scale, complex problems
    • The ability to take a caring and empathetic approach to relationship building and problem solving

The Team

Reporting to Adam Brennick - Director of Security, Risk, and Compliance

Adam Brennick has a diverse background, having supported security and compliance efforts across companies in multiple industries. Prior to his security and compliance-focused work, he held program manager, project manager, and IT manager roles at larger organizations, including MobileIron, IGT, Flex, and Dell. When he is not working on securing Cockroach Labs, Adam enjoys spending time with his two young kids, golfing, and playing retro video games.

Reporting to Mike Geehan - Senior Director of Engineering

Mike Geehan is responsible for the safety and security of CockroachDB Cloud and surrounding infrastructure. Mike joined Cockroach Labs from a DC based start-up, and prior to that spent time in larger tech companies in a wide range of roles. Mike is focused on team development. Enabling and growing his team is paramount to the success of the team, and hence the business as a whole. Mike is based in Houston, Texas, and outside of work is focused on his family, his bikes, and in getting a cycling related non-profit organization off the ground.

Our Benefits

  • Competitive Health Insurance Coverage (for you & your dependents!)
  • Paid Parental Leave (with baby bucks)
  • Flexible PTO 
  • Learning & Development Budget
  • Relocation Support (as applicable)

Cockroach Labs is proud to be an Equal Opportunity Employer building a diverse and inclusive workforce. If you need additional accommodations to feel comfortable during your interview process, please email us at accessibility@cockroachlabs.com.

The annual anticipated base salary range for U.S. candidates for this role is USD $174,000 to $230,000, plus commission if a sales role. We set standard ranges for all U.S.-based roles based on function, level, and geographic location, benchmarked against similar stage growth companies. In order to be compliant with local legislation, as well as to provide greater transparency to candidates, we share salary ranges on all job postings regardless of desired hiring location.  Actual salaries may vary and fall outside of this range depending on factors such as a candidate’s qualifications, geographic location, skills, experience, and competencies. In addition, we are often open to a wide variety of profiles, and recognize that the person we hire may be less experienced (or more senior) than this job description as posted. Salary is one component of the Cockroach Labs’ total rewards package, which includes stock options, health insurance, life and disability insurance, funds towards professional development resources, flexible PTO, paid holidays, and parental leave, to name a few! Salaries for candidates outside the U.S. will vary based on local compensation structures.

CockroachLabs
CockroachLabs
Cloud Computing Database Enterprise Software Software

0 applies

29 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 389 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • Salaries for the engineering jobs on our site range from $100K-$200K. On average, senior engineer positions on our EchoJobs are about $160K.
  • The EchoJobs positions have been sourced and vetted from the top companies to work for in the US as a software engineer, including LinkedIn and other reputable job sites. We also have syndicated jobs from companies that have just raised funding, as well as those that have great unique products and culture. From all of these sources, our founder, Morgan, has also resourced the company's authenticity in terms of their website, public appearance, and more.
  • Yes, our users asked us for just this, so now our search filters allow you to search for your top jobs via location, as well as by onsite, remote, or both. Approximately 30% of our jobs are remote, so you’ve got the best options for you!
  • We have not yet implemented this option, but are considering doing so in the future. For the moment, you would need to cancel your subscription, and resubscribe when you wanted to come back.
  • We add new jobs to EchoJobs every day! We scan our sources for the newest jobs, verify them, and post them to EchoJobs within minutes. We add about 2,000-3,000 new jobs for you each day!
  • From starting your job search to getting hired, the entire job search process can take us software engineers anywhere between 3-6 months. However, at EchoJobs, we’re striving to shorten this duration by finding the best, newest jobs for you, so you can do less job searching, and more applying.
  • We’d recommend checking EchoJobs daily, as we add new jobs to the site each day. Additionally, if you got a chance to read our previous email on “what makes EchoJobs different from any other job search tools,” we also recommended that you set a job alert based on your job filters, so if you get emails on those new jobs, you could be checking more than once per day.
  • If you decide to continue with us after the 1-month trial, we definitely recommend this, as we all know it usually takes 3-6 months to find a quality job as a software engineer these days. So to best support you, we just adjusted our membership options at EchoJobs to monthly, 3 months, or 12 months (this option is more for passive job seekers looking a little bit for the future if they want to come back to work or make a job switch potentially. This lets you see what’s out there in case an even better fit job becomes available.)
  • EchoJobs is truly the only job site of its kind. We want to be THE spot for you to find the best job for you, and haven’t encountered any other company doing this. Other job sites are in niches besides software engineering or focus on a small portion of engineering jobs (like a specific coding language). In the words of Morgan, our founder, “I think what makes EchoJobs different is the amount of jobs, frequency that we add new jobs (we add 2,000-3,000 new jobs daily!), and the powerful search engines to find exactly the job you want more easily and efficiently. We can provide you with the most jobs that are vetted by us, we’ll continually find more new jobs for you, and we make it easier for you to apply and get hired.

What Fellow Engineers Say