About the job
Join vCluster Labs as a Senior Application Security Engineer and become an integral part of our mission to create a secure ecosystem. In this pivotal role, you will oversee the comprehensive security of our product offerings, ensuring that vCluster sets the benchmark for secure multi-tenancy in Kubernetes. Your expertise will help us establish security protocols that empower our clients to deploy high-privileged workloads with confidence, while you devise thorough strategies that encompass our entire codebase and infrastructure.
Your responsibilities will include:
Core Product Security: Conduct in-depth security assessments of our core Go-based applications and Kubernetes controllers, including the frontend user interface, with a focus on preventing privilege escalation in our multi-tenant architecture.
Threat Modeling: Spearhead the threat modeling initiatives for new features by identifying risks linked to shared GPU resources and multi-cloud environments.
Automated Security: Implement 'shift-left' practices by enhancing our CI and developer workflows with integrated security checks that prioritize speed, ensuring security remains a facilitator of engineering velocity. You will also oversee both automated and manual scanning across our product stack.
Vulnerability Management: Take charge of the security vulnerability lifecycle, from detection to resolution. You will assess both internal and external reports, drive critical issue resolutions across engineering teams, and maintain effective communication with stakeholders.
Feature Development: Contribute to the ideation and development of new features that often address security challenges such as container isolation and breakouts, pushing the limits of what can be achieved in constrained environments.
Developer Training: Simplify complex security concepts for all engineers, covering new attack vectors and secure coding practices.
You may be a great fit if you possess:
Experience: At least 5 years in Application Security or Product Security, particularly within containerized environments.
Kubernetes Expertise: A profound understanding of Kubernetes architecture, RBAC (Role-Based Access Control), and container runtime security, along with insight into the unique risks associated with these technologies.

