companySpire logo

Software Engineer - Product Security

SpireBoulder, Colorado, United States
On-site Full-time $171K/yr - $202.5K/yr

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Unlock Your Potential

Generate Job-Optimized Resume

One Click And Our AI Optimizes Your Resume to Match The Job Description.

Is Your Resume Optimized For This Role?

Find Out If You're Highlighting The Right Skills And Fix What's Missing

Experience Level

Mid to Senior

Qualifications

Key Responsibilities: Implement Security Controls in SDLC: Assist in integrating security automation into pipelines (e.g., GitHub Actions/ArgoCD for SAST/DAST/SCA, SBOM generation, and vulnerability scanning). Support Shared Libraries and Infra: Contribute to evolving standard libraries/infra for authentication/authorization, logging, and other runtime security features, including testing and updates. Contribute to CMMC Compliance: Provide hands-on support for implementing controls (e.g., encryption, secure configurations, monitoring) to meet/exceed CMMC Level 2 requirements in AC, IA, SC, and SI families, building upon our ISO 27001 foundation. Assist with Reviews and Models: Participate in security architecture reviews, code audits, and threat modeling; identify and remediate issues such as API vulnerabilities or supply chain risks. Team Collaboration: Engage in code reviews, pair programming sessions, and tooling development to advance secure practices; offer peer support within the security engineering team.

About the job

 

About the Role 

As a Software Engineer focused on Product Security at Spire, you will engage in the hands-on design and implementation of security software aimed at integrating security measures early in our development lifecycle. Your responsibilities will include embedding automated controls like Software Bill of Materials (SBOM) and vulnerability scanning within CI/CD pipelines, maintaining and enhancing our internal libraries and infrastructure for authentication, authorization, and logging, and assisting with operational monitoring tools. You will also play a key role in aligning systems with NIST 800-171/CMMC standards, closely collaborating with the Principal Security Engineer, AWS infrastructure team, development tooling team, chief software engineer, and cybersecurity/GRC group.

In this lean and impact-driven environment, you will prioritize the delivery of secure code and architecture while minimizing bureaucratic hurdles, allowing you to focus on what truly matters. You may occasionally engage in security discussions with government entities under the guidance of the Principal Security Engineer.

Your work will be approximately 80-90% hands-on, with the remaining time dedicated to collaboration and learning.

About Spire

Spire is a leading innovator in the field of aerospace data and analytics, dedicated to providing actionable insights through cutting-edge technology and comprehensive data solutions.

Similar jobs

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.