Staff Security Engineer, Developer Productivity

1 month ago


Canada, CA Security 1st Title, LLC Full time

The worldwide data management software market is massive (According to IDC, the worldwide database software market, which it refers to as the database management systems software market, was forecasted to be approximately $82 billion in 2023 growing to approximately $137 billion in 2027. This represents a 14% compound annual growth rate). At MongoDB we are transforming industries and empowering developers to build amazing apps that people use every day. We are the leading developer data platform and the first database provider to IPO in over 20 years. Join our team and be at the forefront of innovation and creativity.

The Developer Productivity Platforms team owns the tools, services, and infrastructure that enables our developer ecosystem, ensures optimal performance and scalability, as well as the security of our runtime environments, supply chain, services, and published artifacts. A big part of Devprod Platform’s mission is to ensure the security of our MongoDB software supply chain against threats and attacks as well as the compliance of our products. By securing the supply chain and strengthening the security posture of our internal development systems, we protect our customers and the integrity of our shipped products. We ensure that the MongoDB development ecosystem is secure by driving engineering efforts to design and implement controls, processes, and best practices to provide assurance to internal stakeholders and external customers that their data is protected.

What will this position do?
  • Collaborate with MongoDB Infosec and application security teams to create a threat matrix focused on SDLC processes, tooling and infrastructure to improve and evolve our security posture within our development ecosystem.
  • Provide architectural guidance on best practices on, and implement security tooling, automation and technical controls across our developer pipelines, services and infrastructure that adhere to the central principles of least privilege, defense in depth, protecting integrity and access control.
  • Drive SDLC compliance through engineering efforts and implementation/automation of processes, controls and tools.
  • Work with engineering teams across MongoDB to ensure that we are building scalable and sustainable security solutions for our product development and release processes
  • Engage in security investigations to respond to, and analyze emerging threats.
  • Develop strategies to exercise and improve our SDLC security posture utilizing red team and pen test activities.
  • Be a technical authority to help us stay aligned with MongoDB’s security initiatives and policies by driving mid to large scale projects with high visibility.
  • Stay up to date on emerging trends in the software security industry to help us stay ahead of new threat vectors and compliance requirements.
  • Work with Legal, Privacy and Internal Audit to ensure that we are operating within regulatory and compliance standards.
Requirements
  • 8+ plus years of progressive experience with open source and commercial application security testing and analysis tools for attack surface management, dynamic security analysis (DAST), and static code analysis (SAST).
  • Relevant software development experience, understanding how software is designed, built and can be broken is critical.
  • Subject matter expert in all phases of the software development lifecycle supply chain.
  • Domain expertise of software and security through various software development and security best practices.
  • Demonstrated experience with threat modeling, risk analysis and control design.
  • Advanced understanding of vulnerability exploitation chaining and vulnerability remediation
  • Experience or understanding of languages such as C++, C, Rust, Go, Python, Java, or other related languages
  • Experience with cloud native development pipelines and tooling such as Docker, Kubernetes, and other release/deployment tooling
  • The ability to work autonomously, being able to identify gaps and create solutions independently with minimal direction.
  • Demonstrated ability to work collaboratively across domains with senior engineering leaders and stakeholders in other teams and departments.
What will make you stand out?
  • CISSP, CISA, and/or relevant cybersecurity certifications
  • Deep understanding of SLSA framework & CWE, MITRE, OWASP, CIS Benchmarks
  • Experience running Red Team exercises and building remediation roadmaps
  • Self-education to continuously learn and invest in skills and knowledge relevant to the team and the position
  • Knowledge or experience with MongoDB products and services
Other things you might want to know
  • We’re a distributed team. Our Platforms team is located mostly in the EDT and PDT time zones, but we work with other teams all over the world.
  • Our team is remote-first. We use tools like Slack and Zoom to work together. We try to get together on occasion, but our day-to-day is all remote. (If you live close to one of our offices, and would like to use it, that’s okay, too)
  • While our customers are internal, the work done in this space is still customer impacting, as the integrity of our systems and processes for our product depends on us.
  • You’d have a chance to join our team at the early stages of modernizing and refining our engineering practices, tooling and infrastructure where you will have a tremendous impact to how we deliver our products.
#J-18808-Ljbffr

  • Canada, CA Abnormal Security Corporation Full time

    About the Role Enterprises of all sizes trust Abnormal Security’s cloud products to stop cybercrime. These products are data intensive SaaS applications that depend on reliable, scalable, and secure access to data. This is where our Data Platform team fits in, offering scalable storage systems (Postgresql, OpenSearch, Redis, Kafka, RocksDB), as well as...


  • Canada, CA Abnormal Security Corporation Full time

    About The RoleAbnormal Security is looking for a Software Engineer II who is a solid software developer with a strong interest in Security & Privacy to join the Platform Security team. The Platform Security team owns the Security and Privacy platform services and infrastructure to uphold industry standards for the company’s security posture and customer...


  • Canada, CA Payfare Inc. Full time

    CompanyPayfare is a global financial technology company powering digital banking and instant payout solutions for today’s workforce. Payfare partners with major platforms (including Lyft, DoorDash, and Uber) in the on-demand gig economy to drive financial inclusion and empowerment for next-generation workers.Payfare’s suite of products include Payfare...


  • Canada, CA ResMed Inc Full time

    Senior Manager, Secure Product DevelopmentLocation: Halifax, Canada / Saint-Priest, Lyon, FranceTime Type: Full timePosted on: 8 Days AgoDepartment: Global IT SecurityPrimary ObjectiveThe Senior Manager, Secure Product Development's primary role is to help assure the integrity and security of all ResMed Products. This role plays an integral part in...


  • Canada, CA Nomadgao Full time

    Jul 27, 2024 - CoLab Software is hiring a remote Application Security Engineer. Salary: attractive compensation package with stock options. Location: USA, Canada.At CoLab, we help engineering teams bring life-changing products to the world years sooner. Our product, CoLab, is the world’s first Design Engagement System (DES) - a category defining product...

  • Principal Product

    1 month ago


    Canada, CA Sophos Full time

    About Us Sophos is a worldwide leader and innovator of advanced cybersecurity solutions, including Managed Detection and Response (MDR) and incident response services and a broad portfolio of endpoint, network, email, and cloud security technologies that help organizations defeat cyberattacks. As one of the largest pure-play cybersecurity providers, Sophos...


  • Canada, CA Boundlessfellows Full time

    Clover is reinventing health insurance by working to keep people healthier. We value diversity — in backgrounds and in experiences. Healthcare is a universal concern, and we need people from all backgrounds and swaths of life to help build the future of healthcare. Clover's engineering team is empathetic, caring, and supportive. We are deliberate and...


  • Canada, CA Payroc Full time

    Preferred timezone: Central Europe Standard TimeAbout this jobRequired experience: Middlenior experience Minimal education: Bachelor degree Employment type: Full time Role: Software Engineer Category: IT Jobs If you're looking for a unique opportunity to help establish a Technical Operations organization with the oversight to design, implement, and...


  • Canada, CA Versa Networks Full time

    About UsVersa Networks, Inc. is a leading vendor of next-generation Software Defined solutions and architectures, called SASE (Secure Access Service Edge). Versa is providing an end-to-end solution that both simplifies and secures the WAN/branch office network.The goal of Versa Networks is to provide unprecedented business advantages through a software-based...

  • Security Engineer

    1 month ago


    Canada, CA 7Vals PK Full time

    We build cutting-edge Cloud-based solutions which are used by over thousands of companies around the world, predominantly in the US, Canada, Europe, and Australia. Our customers include NASA, 3M, Disney, Amazon, and many others. With such a diverse user base, there are countless ways that a Security Engineer will make an impact in our fast-growing...


  • Canada, CA M87 Cyber Security Inc. Full time

    We are always on the lookout for amazingtalent who can contribute to our growth and deliver results! M87 Cybersecurityis seeking a Cybersecurity Operations Specialist responsible for developing athorough understanding of our security systems and programs to secure ourinfrastructure. If you love technology and are eager to join our team — wewould love to...


  • Canada, CA Grafana Labs Full time

    Security Engineer - Platform Security About our Platform (at Grafana Labs): Grafana Cloud moves millions of metrics, log lines, and traces per second from our customers' environments into a highly available, low-latency stack that processes and stores these data, and serves them to dashboards and alerting tools. We aim to grow this to hundreds of...


  • Canada, CA Iress Part time

    See yourself being part of a large, transformational change? This could be the role for you!At Iress, we make things happenWe believe technology should help people perform better every day. Since our beginning in 1993, people across financial services have trusted us to take their performance to the next level. More than 10,000 businesses and 500,000 people...

  • Software Engineer II

    3 weeks ago


    Canada, CA Abnormal Security Corporation Full time

    Enterprises of all sizes trust Abnormal Security’s cloud products to stop cybercrime. These products are data intensive SaaS applications that depend on reliable, scalable, and secure access to data. This is where our Data Platform team fits in, enabling efficient, reliable and scalable data processing across both realtime and offline processing systems....


  • Canada, CA Boundlessfellows Full time

    We're transforming the grocery industry At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We...


  • Canada, CA Fullcirclebeauty Full time

    Ready to be a Titan?ServiceTitan is looking for a Staff Full Stack Engineer (Staff Software Engineer) to help us build smart, compelling, and intuitive applications for our products. This is an exciting role for an engineer to come in and develop the major application features in a rapidly growing, fast-paced environment. We build for product excellence,...


  • Canada, CA Abnormal Security Corporation Full time

    About The Role In a cloud software world, who you are and what you have access to determines the risk associated with your accounts being compromised, Abnormal Security aims to build a comprehensive tool to understand the employees of our customers, and aid security professionals in assessing the risks and threats impacting their employee base. Help us build...

  • Staff Data Engineer

    1 month ago


    Canada, CA Nomadgao Full time

    Jul 08, 2024 - Fortis Games is hiring a remote Staff Data Engineer. Location: Canada. About the role As a Staff Data Engineer, you will play a crucial role in shaping the technical vision and implementation of our data platform. You will work closely with the data team to build, maintain, and enhance our data infrastructure, ensuring low latency and...

  • Staff DevOps Engineer

    4 weeks ago


    Canada, CA Sportchek Full time

    The Cloud Operations & Automation (COA) team is instrumental in driving cloud transformation within our enterprise. We are responsible for managing public cloud platforms on Azure and GCP, as well as the full developer toolchain including Jenkins, Ansible, Terraform, Jira, GitHub, and more. Our goal is to continuously enhance our platforms by updating...


  • Canada, CA Wipro Full time

    Cybersecurity Product EngineerJob Summary:The Cybersecurity Product Engineer will provide subject matter expertise in key technology areas, including Data Loss Prevention (DLP), Cloud Access Security Broker (CASB/Cloud DLP), Enterprise Encryption, Governance, Risk, and Compliance (GRC), among others. The role involves staying updated on the latest...