Senior Product Security Engineer
hace 7 días
About Mirantis¿Está pensando en solicitar este empleo? No se demore, desplácese hacia abajo y envíe su solicitud lo antes posible para no perder la oportunidad.Mirantis is the Kubernetes-native AI infrastructure company, enabling organizations to build and operate scalable, secure, and sovereign infrastructure for modern AI, machine learning, and data-intensive applications. By combining open source innovation with deep expertise in Kubernetes orchestration, Mirantis empowers platform engineering teams to deliver composable, production‑ready developer platforms across any environment—on‑premises, in the cloud, at the edge, or in sovereign data centers. As enterprises navigate the growing complexity of AI‑driven workloads, Mirantis delivers the automation, GPU orchestration, and policy‑driven control needed to manage infrastructure with confidence and agility. Committed to open standards and freedom from lock‑in, Mirantis ensures that customers retain full control of their infrastructure strategy.Job DescriptionMirantis is seeking aSenior Product Security Engineerto help secure our portfolio of products and services, including enterprise software and critical infrastructure. This role is part of our growingProduct Security programand will play a key role in implementing security controls, driving remediation efforts, supporting compliance initiatives, and partnering with engineering teams to ensure a secure software development lifecycle.As a Senior Product Security Engineer, you will work closely with engineering, security operations, and compliance teams to reduce risk across Mirantis products. You will have the opportunity to shape security strategy, automate controls, and ensure security is embedded into every stage of product development and operations.Key ResponsibilitiesSecure Products & Infrastructure:- Design, implement, and maintain security controls across applications, infrastructure, and CI/CD pipelines to align with internal security standards and regulatory frameworks (e.g., SOC 2, ISO 27001).- Drive adoption of modern security tooling and practices including SAST, DAST, container image scanning, Infrastructure as Code (IaC) security, and dependency analysis.Offensive Security & Vulnerability Management:- Lead vulnerability assessments, application security reviews, and penetration tests.- Triage and prioritize findings, collaborating with product and engineering teams to drive timely and measurable remediation.- Proactively identify and exploit vulnerabilities to strengthen product security posture.Incident Response Support:- Partner with Security Operations and Engineering to investigate application and infrastructure vulnerabilities. Contribute to root cause analysis, remediation plans, and long-term risk reduction.Compliance & Assurance:- Support security reviews, audits, and compliance initiatives through documentation, evidence collection, and coordination with external auditors or vendors.Cross-Product Security Coverage:- Build and maintain security expertise across multiple Mirantis products to strengthen team resilience, provide flexible coverage, and help shape a scalable, sustainable Product Security program.Security Advocacy & Enablement:- Champion secure design and development practices, provide actionable guidance during security reviews, and drive security automation efforts across the SDLC.Qualifications5+ years of experience in product security, application security, or a related security engineering role.Strong understanding of common vulnerabilities (e.g., OWASP Top 10, SANS Top 25) and secure development best practices.Demonstrated experience performing offensive security activities such as manual penetration testing, threat modeling, and exploitation of vulnerabilities.Hands‑on experience with security testing and automation, including:SAST/DAST tooling and pipelinesContainer image scanning(e.g., Trivy, Grype, Anchore)IaC security(e.g., Terraform, Helm, Kics, Checkov)Dependency and supply‑chain security toolingFamiliarity with vulnerability scanning and management tools, application security testing, and manual review techniques.Experience with containerized environments, Kubernetes, and cloud platforms.Proven ability to integrate security controls into CI/CD pipelines and automate security testing as part of the SDLC.Excellent collaboration and communication skills, with the ability to work closely with product and engineering teams.Experience with SOC 2, ISO 27001, or similar compliance frameworks is a plus.Relevant certificationssuch as OSCP, OSEP, OSWE, or SANS/GIAC certifications (e.g., GPEN, GWEB, GWAPT, GCSA), or other equivalent offensive security and application security credentials are strongly preferred.Proficiency in scripting or programming languages (e.g., Go, Python or similar) is an advantage.Additional InformationWhat does Mirantis offer you?Work with an established Silicon Valley leader in the cloud infrastructure industry.Work with exceptionally passionate, talented and engaging colleagues, helping Fortune 500 and Global 2000 customers implement next‑generation cloud technologies.Be a part of cutting‑edge, open‑source innovation.Thrive in the high‑energy environment of a young company where openness, collaboration, risk‑taking, and continuous growth are valued.Professional development and training.Attend conferences and working groups.Customized workstation (macOS, Windows).A competitive compensation package with strong benefits plan and stock options.It is understood that Mirantis, Inc. may use automated decision‑making technology (ADMT) for specific employment‑related decisions. xsgfvud Opting out of ADMT use is requested for decisions about evaluation and review connected with the specific employment decision for the position applied for. You also have the right to appeal any decisions made by ADMT by sending your request to By submitting your resume, you consent to the processing and storage of your personal data in accordance with applicable data protection laws, for the purposes of considering your application for current and future job opportunities.#J-18808-Ljbffr
-
Senior Product Security Engineer
hace 2 días
Madrid, España Mirantis A tiempo completoA cloud infrastructure company in Spain is looking for a Senior Product Security Engineer to secure their product portfolio.Por favor, lea detenidamente la siguiente descripción del puesto para asegurarse de que encaja con el perfil antes de enviar su solicitud.The candidate will implement security controls, support compliance, and work closely with...
-
Madrid, España Mirantis A tiempo completoA cloud infrastructure company in Spain is looking for a Senior Product Security Engineer to secure their product portfolio.Por favor, lea detenidamente la siguiente descripción del puesto para asegurarse de que encaja con el perfil antes de enviar su solicitud.The candidate will implement security controls, support compliance, and work closely with...
-
Madrid, España n8n A tiempo completoA leading tech company in Madrid is seeking a Senior Product Security Engineer to enhance product security. This role requires 5+ years in application security and strong vulnerability management skills. You will collaborate with engineering teams to define security practices and respond to incidents. You will also manage security advisories and ensure a...
-
Security Operations Engineer
hace 4 semanas
Madrid, España Kudelski Security A tiempo completoAbout Kudelski SecurityKudelski Security is a leading global cybersecurity company, delivering tailored services and technologies to help organizations protect their data, systems, and reputation. With a strong heritage in innovation, we combine deep technical expertise with a proactive, client-focused approach to security.Position OverviewWe’re looking...
-
Senior Security Engineer
hace 1 semana
Madrid, España Prima A tiempo completoA leading insurance technology company is looking for a Senior Security Engineer - Incident Response. The position offers flexibility with the option to work remotely and the opportunity to make a significant impact as part of a growing team. The ideal candidate should have excellent communication skills and a proactive approach to security challenges.#
-
Senior Platform Security Engineer
hace 6 días
Madrid, España Flanks A tiempo completoA fintech company based in Barcelona is looking for a Senior Security Engineer to strengthen their security framework.Para una comprensión completa de esta oportunidad y de lo que se requerirá para ser un candidato exitoso, siga leyendo.This role involves evolving security tools, leading initiatives, and collaborating on secure architecture designs.Ideal...
-
madrid, España Flanks, Inc. A tiempo completoA leading fintech startup in Madrid is seeking a Senior Security Engineer to enhance their security foundations. The ideal candidate will continuously evolve security measures, lead security initiatives, and possess strong experience in ethical hacking and secure software design. Proficiency in Python, JavaScript, Kubernetes, and GCP is essential, along with...
-
Madrid, España Flanks, Inc. A tiempo completoA leading fintech startup in Madrid is seeking a Senior Security Engineer to enhance their security foundations. The ideal candidate will continuously evolve security measures, lead security initiatives, and possess strong experience in ethical hacking and secure software design. Proficiency in Python, JavaScript, Kubernetes, and GCP is essential, along with...
-
Security Operations Engineer
hace 4 semanas
Madrid, España Kudelski Security A tiempo completoAbout Kudelski Security Kudelski Security is a leading global cybersecurity company, delivering tailored services and technologies to help organizations protect their data, systems, and reputation. With a strong heritage in innovation, we combine deep technical expertise with a proactive, client-focused approach to security.Position Overview We’re looking...
-
Sr Product Security Engineer
hace 2 días
Madrid, España n8n A tiempo completoOverview The AI orchestration of your wildest imagination. n8n is the open workflow orchestration platform built for the new era of AI. We give technical teams the freedom of code with the speed of no-code, so they can automate faster, smarter, and without limits. Backed by a fiercely inventive community and 500+ builder-approved integrations, we’re...