Senior Product Security Engineer
TLDR
Improve Uplight's security posture through leadership in security projects and by integrating security best practices throughout the software development lifecycle.
- Support, implement, and improve Secure Software Development Lifecycle (SDLC).
- Act as a consultant to the design and development stages of SDLC.
- Document and work with product and engineering teams to implement security best practices and system configuration standards.
- Support Asset Management initiatives to ensure all assets are tagged and classified.
- Work with outside parties to perform penetration tests.
- Perform Security Architecture, AppSec and Risk Assessments.
- Perform Threat Modelling.
- Analyze, manage, and work with other teams to address vulnerabilities, code weaknesses, misconfigurations, and non-compliance findings.
- Coordinate and participate in Disaster Recovery exercises, including Backup tests.
- Maintain and administer security tooling.
- Lead security projects dedicated to improving Uplights's security posture.
- Respond to and assist with incidents as needed or assigned.
- Implement and be responsible for best product security practices and procedures.
- Perform an on-call shift rotation.
- Demonstrate effective communication skills, both verbal and written.
- Advanced experience in securing applications and application settings
- Advanced experience in app and product security
- Advanced understanding in securing cloud technologies
- Experience with technologies from at least one public cloud (AWS, GCP, Azure)
- Experience in securing containerization (Docker, K8s, etc) and API
- Experience with modern DevSecOps practices including implementing automated security in IaC and CI/CD pipelines
- Strong scripting skills Python/Shell Scripting experience
- Mid to advanced level Linux knowledge in a physical, virtual, or public cloud environment.
- Exceptional verbal and written communication skills are necessary to effectively collaborate with peers, and to present and explain highly technical information to stakeholders who may have limited technical knowledge.
- CISSP, CASP+, GSLC, CISM certified.
- Make a Meaningful Impact: Your work directly impacts our mission of decarbonization and building a more sustainable future.
- Grow Your Career: We offer ample advancement opportunities, robust learning and development programs, and a supportive team environment that fosters collaboration and innovation.
- Thrive: We offer comprehensive benefits, including flexible time off, generous parental leave, a wellness stipend, and work flexibility to help you thrive both personally and professionally.
- Belong to an Inclusive Community: We celebrate diversity and foster an inclusive workplace where everyone feels respected, empowered, and heard. Our Employee Resource Groups offer opportunities to connect with colleagues who share your interests and backgrounds.
- Be Part of a Growing Movement: Join a team of dedicated individuals who are passionate about creating a more sustainable future. We offer a collaborative environment where your ideas are valued and your contributions
Benefits
Paid Parental Leave
generous parental leave
Paid Time Off
comprehensive benefits, including flexible time off
Wellness Stipend
TENDRIL builds software to manage energy resources in homes and businesses, integrating smart technologies like thermostats, electric vehicles, and solar panels. Our platform helps users generate, shift, or save energy, optimizing efficiency and enhancing grid reliability. We're focused on delivering solutions that support the transition to clean energy while reducing costs for consumers.