Position Title: Security Engineer, Managed Service
Position Description
SingleStore is a cutting edge business leading a wave of disruption in the database space focused on delivering a single platform for all data intensive applications. We believe in building secure by design solutions for cloud and on-premises deployments without compromising performance.
At SingleStore we are making security part of the entire software development lifecycle, from design to development, through testing and operations. To meet the needs of our rapidly growing business we are seeking an experienced and highly motivated Security Engineer to help us deliver products and services that meet customer security requirements and provide the highest levels of security assurance.
Job Responsibilities
- Drive and support secure software development lifecycle activities and practices across SingleStore (e.g., Security Architecture, Threat Modeling, Secure Coding, Ethical Hacking, Incident Response).
- Stay abreast of emerging security threats and vulnerabilities to ensure the appropriate security controls and mitigations are built into SingleStore products and services.
- Research and evaluate evolving software security standards, best-practices and guidelines to ensure alignment and coverage within upcoming product releases.
- Provide re-usable solutions to identified software vulnerabilities from internal and external penetration tests.
- Collaborate with the larger engineering division by providing role based training and guidance for software security.
- Understand customer and partner software security requirements and interpret them to both technical and management audiences.
- Work closely with Product Management to develop security requirements and acceptance criteria that clearly describe customer requested security features, capabilities and opportunities for growth initiatives.
- Support the sales and marketing organization to ensure consistent and clear external messaging is presented describing the security posture of SingleStore products and services.
- Help present software security initiatives to customers, partners and external stakeholders.
- Assist with and support internal and external software security reviews and assessments.
- Collaborate with the Information Security team on enterprise security projects and initiatives that require software engineering support.
Basic Qualifications
- 2+ years experience in software development.
- 2+ years experience in software security.
- Strong understanding of security requirements, guidelines and best practices for building highly resilient hardened software systems (e.g. such as those from NIST, CIS, OWASP)
- Understanding of cloud-native and container technologies, as well as the security risks and countermeasures to secure them.
- Comfortable with programming and/or scripting languages (preferred: Golang, C/C++, Python, shell/bash).
- Well-versed in supporting the design and implementation of secure software services and secure APIs, with a clear understanding of what a Secure Software Development LifeCycle (SSDLC) entails.
- Understanding of encryption and key management systems.
- Comprehensive knowledge in assessing vulnerabilities identified by security scanning tools and third party penetration testing engagements.
Preferred Qualifications
- Familiar and hands-on experience with security scanning tools (e.g., SAST, DAST, IAST, SCA)
- Experience in managed services security issues and architecture.
- Demonstrable testing competency with a focus on penetration testing and ethical hacking.
- Certifications in one or more of the following areas: CISSP, CCSP, CSSLP, OSCP, CEH
- Bachelors in Computer Science or Software Engineering.
-
- Experience in working, presenting and communicating effectively with engineering, sales, marketing and product management in all aspects security-related, regardless of whether it’s a technical, management or executive audience.
- Familiarity with Kubernetes and understanding of containerized/microservices-oriented architecture.
Optional Qualifications
- Experience developing software security features and product capabilities (e.g., SSO, key management, data masking, access control)
- Familiarity with data security frameworks and regulatory standards, including PCI DSS, GDPR and/or CCPA/CPRA, or/and FedRAMP.
Benefits
- Company Wide
- Technology Stipend for New Employees
- Monthly Cell Phone and Internet Stipend
- Health and Wellness benefit
- Company and team events
- Flexible time off
- Volunteer time off
- Stock Options
As employees are located in many different countries around the world, some benefits may differ from country to country. In all cases, we do our best to provide equitable perks and benefits across our locations.
Other:
- Full Time Employment
- Eligibility to work for an India based employer
- Fully Remote Role or Hybrid based in India - Hyderabad or Bangalore.
SingleStore is one platform for all data, built so you can engage with insight in every moment. Trusted by industry leaders, SingleStore enables enterprises to adapt to change as it happens, embrace diverse data with ease, and accelerate the pace of innovation. SingleStore is venture-backed and headquartered in San Francisco with offices in Sunnyvale, Seattle, Boston, London, Lisbon, Bangalore, Dublin and Kyiv. Defining the future starts with The Single Database for All Data-Intensive Applications.
Consistent with our commitment to diversity & inclusion, we value individuals with the ability to work on diverse teams and with a diverse range of people.
To all recruitment agencies: SingleStore does not accept agency resumes. Please do not forward resumes to SingleStore employees. SingleStore is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company that does not have a signed agreement with the Company.