Staff Security Engineer, Prod Sec
Iru
This job is no longer accepting applications
See open jobs at Iru.See open jobs similar to "Staff Security Engineer, Prod Sec" General Catalyst.
Miami, FL, USA
Day to Day
- Collaborate with Product, Engineering, and DevOps to embed security into our API and platform development lifecycle.
- Perform threat modeling and security reviews to spot risks early and keep our products secure
- Identify, triage, and remediate security vulnerabilities in our codebase, infrastructure, and third-party dependencies
- Support and manage our bug bounty program, coordinating triage and resolution.
- Build and tweak automation tools for security testing and monitoring (e.g., static/dynamic analysis, secrets detection, dependency scanning)
- Participate in security incident response efforts, including investigation, containment, and post-mortem analysis, to ensure rapid resolution and continuous improvement
- Harden our cloud systems (AWS, Terraform, Snowflake) and products to meet industry standards and protect against evolving threats
- Partner with cross-functional teams to make security seamless without slowing us down
- Promote a security-first mindset by providing guidance, training, and documentation to team members on secure coding practices and emerging threats
- Assist with compliance audits and assessments as necessary (e.g., SOC 2, ISO 27001, etc.)
- Conduct security research and contribute to the development of new security tools and techniques.
- Take ownership of security initiatives from design to implementation and measurable outcomes
- Define and track metrics to assess product security health and incident response effectiveness
- Contribute to security policies, coding standards, and risk management frameworks
- Mentor engineers and foster secure-by-default practices across the organization
Must Haves
- 6-8 years of experience in product security and DevSecOps-focused roles
- Proficiency in at least one programming language (e.g., Go, Python, etc.) and the ability to review and write secure code
- Experience with API security (e.g., OAuth, JWT, WAF, rate limiting)
- Knowledge of LLM based attack vectors and mitigation strategies
- Experience with cloud security (e.g., AWS) including DevSecOps and embedding security in the CI/CD pipeline
- A strong understanding of how to secure containerized environments (e.g., Kubernetes, Docker)
- Familiarity with security tools such as static code analyzers, vulnerability scanners, and penetration testing frameworks
- Knowledge of common security vulnerabilities (e.g., OWASP Top 10) and mitigation strategies
- Analytical, curious, and solutions-oriented—especially under pressure
- Strong communicator who thrives in cross-functional teams
Nice To haves
- Bachelor's degree in Information Technology or a related field
- Security related certifications such as CISSP, GIAC, OSCP, CRTO, K8s is a plus
- Experience working on security products, preventing cross-contamination
- Experience in securing and monitoring APIs
- Business acumen to be able to balance tradeoffs between stakeholders and technology feasibility and budget constraints
This job is no longer accepting applications
See open jobs at Iru.See open jobs similar to "Staff Security Engineer, Prod Sec" General Catalyst.