About the job
About Pantheon
Pantheon WebOps Platform empowers the open web, hosting over 300,000 sites in the cloud for esteemed clients like Google, Princeton, Salesloft, and Doctors Without Borders. Every day, countless developers and marketers design, iterate, and scale WordPress and Drupal websites, reaching billions of users worldwide. Pantheon’s multitenant, container-based platform allows organizations to manage all their websites seamlessly from a single dashboard. Renowned companies, including Clorox and the United Nations, achieve remarkable results through accelerated development and real-time publishing utilizing Pantheon’s collaborative workflows.
The Role
As part of Pantheon’s Security Engineering team, you will play a crucial role in protecting, auditing, and testing the security of our comprehensive platform. We are dedicated to implementing a robust and multi-faceted approach to application security, emphasizing Security by Design within agile software development and cloud-native environments.
We are on the lookout for a motivated and experienced application security engineer to join our expanding team. The Staff Security Engineer will hold a pivotal strategic and technical position within the Application Security team.
Our mission is to ensure the security, audit, and testing of the entire cloud hosting platform across several core areas:
- Security by Design: Integrate “Security by Design” principles into agile software development and cloud-native frameworks.
- Support and Mentorship: Serve as Subject Matter Experts (SMEs), providing mentorship and guidance to enhance all security engineering initiatives organization-wide.
- Standard Setting: Establish, organize, and implement application security policies, processes, standards, and guidelines.
- Application Security Performance: Assist engineering teams in designing and constructing high-performing, secure applications by addressing security issues through risk-based methodologies.
What You Will Do
- Policy Definition: Develop, document, and advocate for processes and practices that ensure a secure Software Development Life Cycle (SDLC).
- Security Culture: Be a key player in fostering a robust security culture within platform engineering teams.
- Proactive Security: Lead Threat Modeling initiatives as a fundamental aspect of the Secure by Design strategy.
- Secure Design Reviews: Conduct thorough Secure Code and Architecture Design assessments.

