Job Description:
• Create an environment that favors context, not control.
• Empower product engineers and ensure they have the relevant information and tools to deliver secure products and services.
• Design, implement, and operate security controls and services (e.g., identity and access management, secrets management, endpoint/agent hardening, network segmentation, detection, and response automation) that meet reliability, security, scalability, and observability standards.
• Partner with product and platform teams to integrate security into architecture and developer workflows while articulating business impact and tradeoffs.
• Perform security reviews, threat modeling, and risk assessments (code, design, 3rd-party apps).
• Investigate and resolve urgent and/or complex security issues, triaging effectively and driving architectural changes that prevent recurrence.
• Participate via RFCs, community of practices, and other internal knowledge sharing channels to share learnings, align on standards, and influence secure patterns across areas; model The Times' core values in cross-functional collaboration.
• Support team growth through peer design/code review, pairing, and clear feedback.
Requirements:
• 5+ years of experience in software engineering and/or security engineering space
• Understanding of security controls across a variety of security domains, including access management, encryption, vulnerability management, AI security, network security, authentication/authorization, etc
• Knowledge of one or more Cloud platforms (AWS, GCP) and best practices for architecting and securing
• Experience with software engineering practices (CI/CD, GitOps, IaC, etc.) and related security practices (SAST, SCA, secure by design, shift left, etc.)
• Programming skills in at least one language (Go, Python)
• Experience with containerization and orchestration platforms
Benefits:
• medical, dental and vision benefits
• Flexible Spending Accounts (F.S.A.s)
• company-matching 401(k) plan
• paid vacation
• paid sick days
• paid parental leave
• tuition reimbursement
• professional development programs