Security Engineer, Core Command

Verkada Verkada · Enterprise · Bayoffice · Security

Verkada is seeking a Security Engineer to collaborate with the Core Command engineering team, focusing on threat modeling, security design reviews, and refining security tools throughout the SDLC. The role involves defining the security roadmap, requirements, and priorities for the Verkada Command platform's core security services, web frontend, and mobile applications. Responsibilities include evangelizing security best practices, partnering with engineering and product teams, setting up security tooling, performing architecture analysis, and operating a bug bounty program. The role requires coding ability in Python/Go for automation and security tasks, and experience with Security Development Lifecycle, Threat Modeling, Architecture Analysis, Technical Design Review, and Security Code Review.

What you'd actually do

  1. Facilitate the security baked into our applications throughout the software development lifecycle
  2. Partner closely with engineering and product teams to improve the security of Verkada’s products and exceed customers’ expectations
  3. Set up security tooling and secure defaults to ensure software security best practices
  4. Perform architecture analysis, threat modeling and technical design reviews of sensitive features and infrastructure
  5. Triage and recommend solutions for security bugs from tools, third party assessments and bug bounties

Skills

Required

  • AWS, GCP or other cloud service provider
  • Security Development Lifecycle
  • Threat Modeling
  • Architecture Analysis
  • Technical Design Review
  • Security Code Review
  • Python
  • Go

Nice to have

  • Bug bounty program operation
  • Security conferences and blogs presentation

What the JD emphasized

  • security baked into our applications
  • security roadmap
  • security requirements
  • security priorities
  • core security services
  • software security best practices
  • security tooling
  • secure defaults
  • architecture analysis
  • threat modeling
  • technical design reviews
  • security bugs
  • security conferences
  • security reasoning
  • security engineer
  • security weaknesses
  • security products
  • security features
  • security strategies
  • Security Development Lifecycle
  • Threat Modeling
  • Architecture Analysis
  • Technical Design Review
  • Security Code Review