Software Engineer, Security

Factory
  • San Francisco, California
    30+ days ago

    Job Description

    About the Role

    Factory is seeking a talented Security Engineer to join our team. In this role, you will play a critical role in developing and maintaining the security foundation of our platform. You will conduct in-depth code reviews, implement security best practices, and influence the overall security strategy. Your expertise in TypeScript, Python, Kubernetes, CI/CD, and terraform orchestration will be crucial in identifying and mitigating potential security vulnerabilities.

    What you will do and achieve

    • Design, implement, and manage security measures for the protection of our cloud infrastructure, applications, and data, focusing on both preventative controls and rapid response capabilities.

    • Collaborate closely with our engineering teams to integrate security practices into the software development lifecycle, including secure coding standards, automated security testing, and secure architecture design.

    • Stay up-to-date on the latest security threats, vulnerabilities, and mitigation strategies.

    • Conduct security code reviews to identify and remediate security vulnerabilities.

    • Develop and implement automated security testing procedures to identify vulnerabilities and risks, recommending and implementing appropriate mitigation strategies.

    • Respond to security incidents and participate in incident response procedures.

    • Document security processes, procedures, and best practices.

    • Lead security awareness and training programs, empowering all team members to recognize and prevent potential security threats.

    Qualifications

    • Minimum 5+ years of experience as a Security Engineer with a focus on product security, with a strong background in securing cloud-based environments (AWS, Azure, GCP) and understanding of Infrastructure as Code (IaC) security practices.

    • Strong coding skills with proficiency in TypeScript and Python.

    • Expertise in various security domains such as application security, network security, security operations, and incident response.

    • Experience with container security (Docker Security, Kubernetes Security).

    • Familiarity with a wide range of AWS services, including but not limited to VPC, EC2, Lambda, Amazon RDS, and S3.

    • In-depth knowledge of CI/CD pipeline tools and practices, ideally with experience in GitHub Actions or Jenkins.

    • Knowledgeable in security compliance frameworks and regulations (e.g., ISO 27001, SOC 2, GDPR) and experience with security assessments and third-party audits.

    • Proficiency with security tools and technologies, such as firewalls, IDS/IPS, vulnerability scanners, WAF, SIEM, and encryption solutions.

    • Demonstrated ability to influence security strategies and drive improvements within a team.

    This is an in-office position (5 days/week) in San Francisco (walking distance to Caltrain)

    Numbers & Facts

    LocationSan Francisco, California
    Websitehttps://factory.ai

    Skills

    • AWS Lambdaunmatched
    • Amazon Elastic Compute Cloud (EC2)unmatched
    • Amazon Relational Database Service (RDS)unmatched
    • Amazon Web Services (AWS)unmatched
    • Best Practicesunmatched
    • Cloud Applicationsunmatched
    • Cloud Computingunmatched
    • Code Reviewsunmatched
    • Coding Standardsunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Cryptographyunmatched
    • Firewallsunmatched
    • GCP (Good Clinical Practices)unmatched
    • GitHubunmatched
    • ISO (International Organization for Standardization)unmatched
    • Incident Responseunmatched
    • Intrusion Detection Systemsunmatched
    • Intrusion Prevention Systemsunmatched
    • Jenkinsunmatched
    • Microsoft Windows Azureunmatched
    • Process Improvementunmatched
    • Python Programming/Scripting Languageunmatched
    • Regulatory Complianceunmatched
    • Risk Analysisunmatched
    • Secure Codingunmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Security Complianceunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Monitoringunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Software Engineeringunmatched
    • Test Automationunmatched
    • Test Designunmatched
    • Testingunmatched
    • Training Programunmatched
    • Vulnerability Scannersunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder