vCluster Labs is looking for a
Senior Software Engineer focused on Product Security to help us build secure infrastructure software from the ground up. You'll design, build, and maintain production features alongside the rest of the engineering team, while bringing a security perspective to the broader product by reviewing security-sensitive designs, threat modeling new features, investigating vulnerabilities, and helping teams make sound security decisions as the platform evolves.
Operating security tooling and compliance are not the primary goals; we need an experienced engineer who can work deeply in our codebase and architecture, build security into the product itself, and serve as the security expert for our product.
As a Senior Software Engineer (Product Security), your role will include:- Building production features: Design, build, and maintain production features alongside the rest of the engineering team. When there's no security work in the queue, you work on roadmap features.
- Owning vulnerability response: Triage, prioritize, and fix security issues in our code and dependencies through to a patched release.
- Threat modeling new features: Review security-sensitive designs early, identify risks, and help teams make sound security decisions as the platform evolves.
- Code and design reviews: Participate in code reviews, design reviews, and technical discussions with the rest of the engineering team.
- Improving security practices across engineering: Help engineers build secure defaults into the product.
This role could be a fit for you if you bring:- Production engineering in Go: Experience building and shipping production systems with Go as a primary language.
- Kubernetes internals depth: Working knowledge of the API server, admission control, RBAC, controllers, and the kubelet, ideally from building controllers or operators with controller-runtime, Kubebuilder, or client-go.
- Kubernetes attack surface knowledge: Hands-on experience with container breakout, privilege escalation, RBAC, and policy best practices.
- Threat modeling and secure design: Experience threat modeling and reviewing designs for production systems, and explaining risk clearly to other engineers.
- Vulnerability ownership: Experience investigating and fixing vulnerabilities in code you work on, including the CVE lifecycle, coordinated disclosure, and patch releases.
Bonus points for:- CKS certification: Certified Kubernetes Security Specialist.
- Startup Experience: Experience at an early-stage organization where you function autonomously and strive towards building something great.
BenefitsWe offer the following benefits:
- Competitive Salary: We offer a competitive compensation package, including equity.
- Premium Insurance: Health, dental, vision, and life Insurance, including plans for you and eligible dependents (benefits vary depending on country).
- Flexible Working Schedule: You have a doctor's appointment or need to head to the supermarket to get groceries at 2pm? We won't have an issue with that. To us, results matter more than clocking in and out at the same time every day.
- Workplace Flexibility: We're very flexible about where you work. We know things can change in life and we're happy to adjust the work environment for you along the way.