Product Security Engineer - Public Sector

Scale AI Scale AI · Data AI · San Francisco, CA +2 · Public Sector Engineering

Security Engineer focused on product security, code reviews, SAST/DAST, CI/CD security, and infrastructure security using Terraform. The role involves influencing security strategy and guiding engineering teams.

What you'd actually do

  1. Conduct in-depth code reviews to identify and remediate security vulnerabilities.
  2. Evaluate and enhance the security of our product offerings, through RFC and service review.
  3. Implement and maintain CI/CD pipelines with a strong focus on security.
  4. Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify vulnerabilities in production code.
  5. Utilize terraform orchestration to ensure secure and efficient infrastructure management.

Skills

Required

  • TypeScript
  • Python
  • Kubernetes
  • CI/CD
  • SAST
  • DAST
  • terraform orchestration
  • NodeJS
  • modern Javascript application design
  • Kubernetes backed services
  • SAST and DAST tools and methodologies
  • terraform orchestration for infrastructure management
  • structure complex problems
  • diagnose root causes independently
  • communication skills
  • influence security strategies

Nice to have

  • security certifications (e.g., CISSP, CEH, OSCP)

What the JD emphasized

  • TypeScript
  • Python
  • Kubernetes
  • CI/CD
  • SAST
  • DAST
  • terraform orchestration
  • structure complex problems
  • diagnose root causes independently
  • clearly explain the mechanics and significance of security vulnerabilities
  • exploitability
  • potential impact