The role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Software Engineer based in United States.
Join a globally distributed security engineering environment focused on protecting Linux, open source software, and products used across cloud, AI, IoT, and enterprise infrastructure.
This role combines hands-on software engineering with proactive security leadership across product development teams.
You will help teams identify and address security risks through threat modeling, architecture reviews, static analysis, fuzzing, vulnerability research, and other modern practices.
The position spans feature development, vulnerability response, security hardening, compliance, and open source community participation.
You will work closely with engineers, customers, partners, and open source communities to improve the security of software at significant scale.
Depending on your expertise, you may contribute to cryptography, Linux security, vulnerability assessment, security automation, or kernel-level technologies.
This fully remote opportunity is suited to a security-focused engineer who enjoys solving complex problems, influencing engineering practices, and working across a broad technical ecosystem.
Accountabilities:
- Define, implement, test, and document new security features across software products and infrastructure.
- Lead security-focused initiatives within product engineering teams and promote security throughout the software development lifecycle.
- Analyze, reproduce, remediate, and test vulnerabilities in open source software.
- Audit source code and software architectures to identify security weaknesses and recommend appropriate mitigations.
- Apply threat modeling, architecture and design reviews, tabletop exercises, static analysis, fuzzing, and other proactive security practices.
- Contribute security fixes and improvements to Ubuntu and upstream open source projects.
- Integrate security tools into development infrastructure, pipelines, and engineering processes.
- Design and develop hardening automation for Linux-based environments.
- Support security certification initiatives and help maintain compliance with relevant standards.
- Extend and enhance Linux cryptographic components to address country-specific compliance requirements, including FIPS and Common Criteria where applicable.
- Collaborate with external partners on security initiatives such as Center for Internet Security benchmarks.
- Develop, test, and maintain software capabilities supporting security, reliability, and compliance objectives.
- Provide security guidance, technical support, and best-practice recommendations to other engineering teams.
- Monitor emerging security threats, technologies, methodologies, and industry developments.
- Participate in open source communities and contribute to broader security initiatives across the ecosystem.
Requirements:
- Strong professional experience in software engineering with a significant focus on application, product, or infrastructure security.
- Thorough understanding of common categories of software security vulnerabilities and effective approaches for identifying and remediating them.
- Experience applying modern software engineering and secure development practices.
- Demonstrated experience acting as a security champion or driving security initiatives within a broader Software Development Life Cycle (SDLC).
- Strong programming skills in one or more of C, C++, Python, Go, Rust, Java, Ruby, PHP, or JavaScript/TypeScript.
- Experience working with Linux, with Debian or Ubuntu experience preferred.
- Familiarity with open source development tools, workflows, methodologies, and community practices.
- Strong understanding of security architecture, secure coding, vulnerability analysis, and software hardening.
- Excellent analytical and problem-solving abilities, with a willingness to investigate complex security issues in depth.
- Strong communication and presentation skills, with the ability to explain security risks and recommendations clearly to technical stakeholders.
- Excellent interpersonal skills, curiosity, flexibility, and accountability.
- Strong self-motivation, thoughtful decision-making, and a consistent focus on delivering results.
- Professional written and spoken English.
- Undergraduate degree in Computer Science, STEM, or a related technical discipline, or a compelling alternative professional background.
- Demonstrated ability to take ownership, exceed expectations, and deliver against commitments.
- Experience working effectively in globally distributed and asynchronous teams.
- Experience with the Linux kernel is advantageous.
- Knowledge of FIPS, Common Criteria, or other security certification frameworks is a plus.
- Familiarity with OVAL and vulnerability assessment methodologies is beneficial.
- Knowledge of cryptographic technologies such as OpenSSL or Libgcrypt is advantageous.
- Understanding of low-level Linux cryptography APIs is a plus.
- Performance engineering experience and the ability to learn new technologies quickly are valuable additional strengths.
- Willingness and ability to travel internationally at least twice a year, typically for approximately one week per event.
Benefits:
- Geographically adjusted compensation based on location, experience, and performance.
- Performance-driven annual bonus.
- Annual compensation reviews, with additional reviews where appropriate for graduates and associates.
- Fully distributed, remote-first work environment.
- Twice-yearly in-person team sprints and opportunities to collaborate with colleagues globally.
- USD 2,000 annual personal learning and development budget.
- Recognition rewards.
- Annual holiday leave.
- Maternity and paternity leave.
- Employee Assistance Programme.
- Opportunities to travel internationally and meet colleagues in different locations.
- Priority Pass and travel upgrades for long-haul company events.
- Opportunity to work on security challenges across Linux, open source software, cloud, AI, IoT, and enterprise infrastructure.
- Exposure to advanced security practices including threat modeling, fuzzing, vulnerability research, security automation, cryptography, and compliance.
- Opportunity to contribute to upstream open source communities and security-focused projects.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1