Security Infrastructure Engineer

Tailscale Tailscale · Enterprise · Remote · Engineering

Software engineer specializing in security and infrastructure to grow the product security team. Responsibilities include designing and building security controls, improving security properties, auditing infrastructure, and supporting engineering decisions with threat modeling and security analysis. Requires expertise in cloud security, container security, internet/web security fundamentals, and proficiency in Go and IaC tooling. Prior experience in a safety-related technical role is also required.

What you'd actually do

  1. Design and build security controls across diverse layers (e.g., cloud platforms, OS, Kubernetes, networks, CI/CD) to defend against sophisticated adversaries and insider threats.
  2. Improve the security properties of Tailscale by identifying opportunities for security and privacy features, bug fixes, defense-in-depth, and implementing them across our codebase.
  3. Audit Tailscale infrastructure for technical security weaknesses, identifying mitigations or solutions, and driving them towards resolution.
  4. Support engineering decisions with threat modeling and security analysis and expertise.
  5. You will spend 25-50% of your time in this role writing software vs purely operational or governance security responsibilities.

Skills

Required

  • security of cloud platforms (e.g., AWS)
  • securing multi-cloud networks and infrastructure
  • designing cloud agnostic systems
  • container security
  • orchestration security
  • authentication/authorization
  • internet/web security fundamentals: WAF’s, TLS, PKI, DNS security
  • developing in Go
  • Infrastructure as Code tooling (e.g. Terraform, Ansible)
  • operating system internals and security mechanisms
  • common networking protocols

Nice to have

  • familiarity with container security
  • familiarity with orchestration security
  • familiarity with authentication/authorization
  • familiarity with internet/web security fundamentals: WAF’s, TLS, PKI, DNS security
  • prior experience in a safety-related technical role

What the JD emphasized

  • security controls
  • threat modeling
  • security analysis
  • cloud platforms
  • container security
  • authentication/authorization
  • internet/web security fundamentals
  • operating system internals
  • networking protocols
  • security incidents