About the job
Join vCluster Labs as a Senior Application Security Engineer, where you will play a pivotal role in establishing trust within our innovative ecosystem. Your primary responsibility will be to maintain the highest security standards across our products, ensuring that vCluster is recognized as the gold standard for secure Kubernetes multi-tenancy. You will craft comprehensive security strategies that protect our entire codebase and infrastructure.
Key Responsibilities:
Core Product Security: Conduct thorough security assessments of our core Go-based applications and Kubernetes controllers, focusing on preventing privilege escalation within our multi-tenant architecture.
Threat Modeling: Spearhead the threat modeling initiatives for new features, proactively identifying risks associated with shared GPU resources and multi-cloud configurations.
Automated Security: Implement early-stage security checks within our CI and developer workflows, optimizing for performance to ensure that security processes do not hinder engineering agility. Additionally, you will oversee both automated and manual scanning of our entire product stack.
Vulnerability Management: Manage the lifecycle of security vulnerabilities from discovery to remediation. You will triage reports from both internal and external sources, drive the resolution of critical issues across engineering teams, and communicate effectively with all stakeholders.
Feature Development: Contribute to the ideation and development of new features, many of which directly address security concerns such as container isolation and breakout prevention, pushing the boundaries of what is achievable in constrained environments.
Developer Training: Simplify complex security topics for all engineers, including emerging attack vectors and secure coding practices.
Qualifications:
Experience: A minimum of 5 years in Application Security or Product Security, with a solid focus on containerized environments.
Kubernetes Expertise: Profound knowledge of Kubernetes architecture, RBAC, and container runtime security, along with an understanding of associated risks.

