Senior Product Security Engineer, Server

MongoDB MongoDB · Enterprise · Dublin, Ireland · Platform Security

This role is for a Senior Product Security Engineer at MongoDB, focusing on securing their database products which are used for AI/ML applications. The role involves taking ownership of security initiatives, driving strategy, performing security assessments, and partnering with engineering teams to implement security controls. While the company is transforming industries with AI/ML and the database is positioned for the AI era, the core function of this role is product security engineering, not direct AI/ML model development or research.

What you'd actually do

  1. You will take ownership, define strategy, and drive improvement for parts of our program such as fuzzing, threat modeling, secrets management, or container security
  2. Advocate for and lead complex security projects from inception through completion
  3. Drive architecture, patterns, and processes across Server Engineering that make security the easiest path
  4. Partner closely with engineering teams to design and implement security controls across our software and systems
  5. Research and POC new attacks against our systems. Plan and perform product security assessments including architecture review threat modeling, code review, pen testing and general security consulting to proactively build security controls

Skills

Required

  • application security
  • software security
  • product security
  • C++ programming
  • security assessments on low-level codebases
  • implementing remediation strategies for memory-related security flaws
  • threat modeling
  • security design reviews
  • security consulting

Nice to have

  • database security
  • data security
  • database engines
  • database internals
  • applied cryptography
  • contributing or partnering with security researchers to identify vulnerabilities

What the JD emphasized

  • strong security engineering background
  • strong emphasis on customer experience
  • 7+ years of experience in application security, software security, or product security
  • Proven experience in C++ programming, performing security assessments on low-level codebases, and implementing remediation strategies for memory-related security flaws such as buffer overflows and memory leaks
  • A strong track record of partnering with software engineers: leading threat models, performing security design reviews, and developing an understanding of their product space to form pragmatic security recommendations and influence their prioritization