Full Stack Security Engineer (Application & Product)
Job description
About the role
RunPod is at the forefront of transforming the AI Developer Cloud landscape, providing innovative solutions for developers working with artificial intelligence and machine learning. We are seeking a highly skilled Full Stack Security Engineer to join our engineering team and focus on enhancing the security of our customer-facing products, APIs, and internal services. This role is essential in safeguarding the integrity of our platform, protecting user data, and ensuring the security of our billing systems and web interfaces. The ideal candidate will have a strong background in application security, a proactive approach to identifying vulnerabilities, and the ability to work closely with engineering teams to implement security best practices. As a key member of our security team, you will help us maintain a secure environment that fosters trust and confidence among our users and partners.
Key facts
What you'll do
- Lead efforts to secure our products by conducting comprehensive threat modeling, architecture reviews, and detailed code assessments for web applications, APIs, and microservices.
- Write, review, and improve code to address security vulnerabilities across our Python, Go, and JavaScript/TypeScript codebases, collaborating closely with software engineers to implement fixes and enhancements.
- Implement and manage security testing tools such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) within our continuous integration and continuous deployment (CI/CD) pipelines to identify vulnerabilities early in the development process.
- Configure, monitor, and optimize application-layer security measures, including Web Application Firewalls (WAF), bot protection mechanisms, and API gateways, to prevent malicious attacks and unauthorized access.
- Provide ongoing security guidance and secure coding best practices to development teams through training sessions, documentation, and code reviews.
- Collaborate with operations and compliance teams to ensure adherence to relevant security frameworks such as SOC 2, ISO 27001, and GDPR, and assist in bug bounty program triage and vulnerability management.
- Stay current with emerging security threats, attack techniques, and industry best practices, and proactively implement necessary countermeasures to protect our platform.
- Participate in incident response planning, conduct security incident investigations, and help develop strategies to mitigate future risks.
- Assist in designing security features for new products and features, ensuring security is integrated into the development lifecycle from the outset.
- Work with cross-functional teams to develop security metrics, dashboards, and reporting tools to monitor the security posture of our platform continuously.
Requirements
- A minimum of 5 years of professional experience in application security, product security, or related software engineering roles with a focus on security.
- Proven proficiency in programming and code review in languages such as Python, Go, JavaScript, or TypeScript, with a strong understanding of secure coding practices.
- Deep knowledge of web application vulnerabilities, including OWASP Top 10, and familiarity with API security protocols such as REST and GraphQL.
- Hands-on experience with offensive security testing tools like Burp Suite, ZAP, or similar, to identify and exploit vulnerabilities for testing purposes.
- Practical experience integrating security testing tools into CI/CD pipelines, supporting a DevSecOps approach to development.
- Strong ability to communicate complex security issues clearly and effectively to technical and non-technical stakeholders, translating risks into actionable engineering tasks.
- Familiarity with authentication and authorization standards such as OAuth, OpenID Connect (OIDC), and JWT.
- Knowledge of security compliance standards and frameworks relevant to cloud-native applications, including experience with cloud providers and containerized environments.
- Ability to work independently and collaboratively in a fast-paced, dynamic environment, managing multiple priorities effectively.
- A proactive mindset with a passion for continuous learning and staying updated on the latest security trends and threats.
Nice to have
- Relevant security certifications such as Offensive Security Web Expert (OSWE), GIAC Web Application Penetration Tester (GWAPT), Certified Information Systems Security Professional (CISSP), or similar credentials.
- Experience in securing cloud-native applications hosted on Kubernetes, Docker, or similar container orchestration platforms.
- Prior involvement in managing bug bounty programs, coordinating vulnerability disclosures, or working with external security researchers.
- Familiarity with cloud security best practices and tools for AWS, GCP, or Azure environments.
- Experience working in a startup or fast-growth environment, adapting quickly to evolving security needs.
Skills & tools
- Proficiency in Python, Go, JavaScript, and TypeScript programming languages.
- Familiarity with security testing tools such as SAST, DAST, and SCA.
- Knowledge of Web Application Firewalls (WAF), API gateways, and related security infrastructure.
- Experience with CI/CD pipelines and integrating security testing into development workflows.
- Understanding of container security, orchestration, and cloud security principles.
- Ability to analyze security logs, develop security dashboards, and generate reports to track security metrics.
Practical notes
RunPod is committed to fostering an inclusive and diverse workplace, where all employees are valued and respected. We believe that diversity enhances our team's creativity and problem-solving capabilities. As an equal opportunity employer, we do not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or any other protected characteristic. We encourage applicants from all backgrounds to apply and join us in building a secure, innovative platform for AI developers worldwide.