Carta - San Francisco, CA

posted 13 days ago

Full-time - Senior
San Francisco, CA
10,001+ employees
Health and Personal Care Retailers

About the position

As a Senior Product Security Engineer at Carta, you will play a crucial role in enhancing the security of our products and ensuring that our engineering teams can deliver high-quality software securely and efficiently. Your primary mission will be to develop tooling, automation, and infrastructure that not only accelerates the engineering process but also integrates security seamlessly into the software development lifecycle. You will be tasked with identifying security vulnerabilities from various sources and implementing solutions that empower developers to prioritize security in their workflows. This position requires a proactive approach to security, where you will advise on risks related to application, container, and cloud security vulnerabilities, and automate tasks to streamline processes for developers. You will collaborate closely with the Product Security team within the Information Security organization, which is dedicated to protecting customer data and investments by ensuring that Carta's products adhere to the highest security standards. Your work will involve providing guidance and tools to developers, enabling them to conduct effective peer reviews and fostering a culture where security is a continuous consideration. You will also be responsible for educating Product and Engineering teams on relevant security topics, ensuring that security best practices are integrated into their daily operations. In this role, you will leverage your extensive experience in product security to improve Carta's product offerings and developer experience, paving the way for security ownership across all product teams. Your contributions will be vital in establishing a trusted partnership with engineering teams, helping them to release secure software that meets the needs of our customers.

Responsibilities

  • Develop tooling, automation, and infrastructure to enhance product security.
  • Identify security vulnerabilities from various sources and implement solutions.
  • Advise on risks related to application, container, and cloud security vulnerabilities.
  • Automate tasks for developers to streamline security processes.
  • Educate Product and Engineering teams on relevant security topics.
  • Conduct code reviews and penetration tests to proactively identify vulnerabilities.
  • Provide guidance and tools to developers for effective peer reviews.
  • Foster a culture of security awareness among engineering teams.

Requirements

  • 6+ years of experience implementing scalable security programs.
  • Experience with a variety of product security testing tools (e.g. Burp Suite, OWASP Zap, Semgrep, CodeQL).
  • Software development experience with several interpreted or compiled programming languages.
  • Understanding of threat modeling and general software development practices.
  • Ability to automate tasks for themselves or developers.
  • Empathetic approach as a security consultant on new and existing products.

Nice-to-haves

  • Experience in a fast-paced engineering environment.
  • Familiarity with cloud security best practices.
  • Knowledge of compliance frameworks and regulations.

Benefits

  • Market competitive salary
  • Equity for all full-time roles
  • Exceptional benefits package
  • Commission plans for applicable roles
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service