Veeam Software

Product & Application Security Engineer

Veeam Software$237K — $441K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in security engineering or a similar role
  • Strong proficiency in Go (Golang) and experience with frontend frameworks like Vue.js
  • Extensive experience with Kubernetes, particularly its security features
  • Familiarity with AppSec and supply chain security tools, specifically Grype, Cycode, and Wiz
  • Experience integrating security into the SDLC with a shift-left mindset
  • Ability to balance theoretical security with practical software shipping

Responsibilities

  • Serve as the primary security advisor during design reviews
  • Conduct threat modeling for new features before development
  • Review Pull Requests and perform in-depth code audits to identify vulnerabilities
  • Triage security alerts and implement effective fixes
  • Oversee the security of software supply chain dependencies
  • Lead audits, incidents, and compliance reviews within the security community

Benefits

  • Unlimited paid time off and 12 paid holidays, including dedicated self-care days
  • Paid parental leave with extended time for birthing parents
  • Comprehensive medical, dental, and vision coverage from day one
  • Mental health support including therapy sessions and wellness tools
  • 401(k) retirement plan with company matching contributions
  • Support for fertility, adoption, and surrogacy services
  • Access to 24/7 virtual veterinary care at no cost
  • Legal services and identity protection offerings
  • Tax-advantaged accounts for healthcare and other expenses
  • Opportunities for professional growth through various learning resources
Full Job Description
About the Role

We are looking for a Senior Security Engineer who thinks like a product architect and codes like a software engineer. At Veeam Kasten, we release market-leading Kubernetes data protection software, which makes security critical to safeguarding our customers' environments and data. This role ensures security is embedded throughout the lifecycle, not just as a gate at the end. You will partner with engineering teams during the whiteboard phase to design secure features and dive into the codebase to find and fix vulnerabilities.

Your Impact
  • Design & Architecture: You will be the primary security voice in design reviews. You will perform threat modeling on new features, identifying architectural risks before a single line of code is written
  • Code-Level Security: You will actively review Pull Requests and conduct deep-dive code audits. You won't just run scanners; you will manually analyze logic in our code to find complex flaws that automated tools miss
  • Vulnerability Remediation: unlike traditional security roles that only "report" bugs, you will help fix them. You will triage findings from our tooling and write production-ready patches to resolve vulnerabilities
  • Secure Software Supply Chain: You will oversee the integrity of our build dependencies, ensuring that the open-source libraries we import (and the tools we use to build them) are secure
What You'll Do
  • Triage and fix security alerts from tools like Grype, Cycode, and Wiz
  • Implement code fixes for security tech-debt across our stack
  • Conduct Threat Modeling sessions for upcoming epics and features in our two-week sprint cycles
  • Serve as a Subject Matter Expert on Kubernetes security primitives (RBAC, unprivileged containers, network policies) for the engineering team, owning metrics and definition of success, share best practices through workshops, reviews, and documentation
  • Lead audits, incidents, and compliance reviews representing the engineering team with the wider security community in Veeam
Technologies You'll Work With

Core: Go, Vue.js, Docker, Kubernetes
Security Tooling: Grype, Syft, Checkmarx, Cycode, Wiz
Environment: Public Cloud (Azure/AWS/GCP), On-Prem K8s distributions (OpenShift, Tanzu)
What You'll Bring
  • Developer DNA: You are a competent developer in Go (Golang) and have exposure to modern frontend frameworks like Vue.js.
  • Kubernetes Native: You've worked extensively with Kubernetes and understand it's security primitives.
  • Shift-Left Mindset: You have experience integrating security into the early stages of the Software Development Life Cycle.
  • Tooling Familiarity: Experience with modern AppSec and Supply Chain tools (specifically Grype, Cycode, and Wiz) is a strong plus.
  • Pragmatism: You can balance theoretical security perfection with the practical reality of shipping software on a continuously frequent basis.

#LI-KC1

What you'll get
  • Unlimited paid time off, 12 paid holidays including 4 global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
  • Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
  • Medical, dental, and vision coverage starting on your first day
  • Mental health support, therapy sessions, and digital wellness tools via our Employee Assistance Program
  • 401(k) retirement plan with company matching contributions
  • Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
  • AirVet: 24/7 virtual veterinary care at no cost
  • Legal services, identity protection, and supplemental health insurance options
  • Tax-advantaged spending accounts for healthcare, dependent care, and commuting
  • Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O'Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning

Compensation Transparency

Veeam is committed to pay transparency and equitable compensation. For this role, the compensation range below reflects the expected total target compensation (TTC), inclusive of base pay and a competitive performance-based bonus. For roles with a commission plan, the compensation range represents On Target Earnings (OTE), which includes base salary plus variable commission. When determining compensation, Veeam takes into consideration factors such as experience, education, skills, and geographic zone. Offers are typically made below the midpoint of the range.

In addition to compensation, Veeam provides a comprehensive benefits package, including health coverage, retirement plans, and unlimited time off.

U.S. Geographic Zones & Compensation Ranges (TTC / OTE)

Zone 1: San Francisco Bay Area, New York City Boroughs

$237,800-$441,500 USD

Zone 2: Washington, California (excluding San Francisco Bay Area)

$218,000-$404,700 USD

Zone 3: Texas, Illinois, North Carolina, Colorado, Massachusetts, Pennsylvania, Virginia, Oregon, Nevada, Hawaii, New York (excluding NYC boroughs); Sales roles located in Georgia, Ohio, and Arizona

$198,100-$367,900 USD

Zone 4: All other US locations

$172,400-$320,100 USD

About Veeam Software

Veeam Software is a privately held information technology company that develops backup, disaster recovery and intelligent data management software for virtual, physical and multi-cloud infrastructures. The company's headquarters are in Baar, Switzerland, and it has offices in more than 30 countries. Veeam has more than 375,000 customers worldwide, including 82% of the Fortune 500 and 69% of the Global 2,000 enterprises. The company was founded in 2006 by Ratmir Timashev and Andrei Baronov.
Learn more about Veeam Software
Size
5,000 employees
Industry
Founded
2006

Similar Jobs

More Jobs at Veeam Software

More Information Technology Jobs

Find similar Product & Application Security Engineer jobs: