
Senior Product Security Engineer, Cloud
- Seattle, WA New York City, NY
- Permanent
- Full-time
- Defines and drives an engaging, exciting security strategy for MongoDB and our customers
- Builds a developer driven security program where there is tight integration with engineering artifacts, process, and tooling
- Uses software architecture and coding patterns to reduce the impact of security issues
- Are the security subject matter experts for our tech stack and products
- At least 7 years of Cloud Security experience
- Deep subject matter expertise in modern cloud environments, particularly in large scale AWS, GCP and Azure multi-cloud environments
- Deep understanding of IAM, audit logging, network security, and data protection mechanisms within AWS, GCP, and Azure
- Demonstrated experience working with native(e.g., AWS Security Hub, GCP Command Center) and non-native tooling (e.g., Orca, Wiz) for Cloud Security Posture Management
- Scripting experience and ability to contribute code back to our environments
- Comfortable leading threat modeling, security architecture reviews, and being a security ambassador to other engineering teams
- Communicate complex technical issues in a simple manner that builds trust with a variety of audiences
- A strong sense of ownership and delivery
- Can facilitate a conversation rather than dominate it
- Skilled at providing collaborative, actionable feedback, not just a list of flaws
- Kubernetes and container security experience (e.g., securing workloads on EKS, GKE, or OpenShift)
- Experience with security incident response in cloud-native environments
- Background in leveraging machine learning or AI techniques for cloud security threat detection or anomaly detection
- You will take ownership, define strategy, and drive improvement for various aspects of our program, including security assessments, threat modeling, secrets management, vulnerability management, and cloud security posture management
- Advocate for and lead complex security projects from inception through completion
- Drive architecture, patterns, and processes across cloud engineering that make security the easiest path
- Partner closely with engineering teams to design and implement security controls across our software and systems
- Research and POC new attacks against our systems. Plan and perform product security assessments including architecture review threat modeling, code review, pen testing and general security consulting to proactively build security controls
- Serve as a security subject matter expert for software security and architecture
- Partner with cloud detection and response to create new capabilities or respond to security events
- Seeing projects through from conception to completion in order to deliver new services or capabilities for the team
- Establishing yourself as a go-to person for discussing Cloud Security topics