Software Engineer, Security Infrastructure
Job description
About the role
Siftstack creates data infrastructure for hardware engineering teams working on satellites, rockets, autonomous vehicles, and defense systems. We are seeking a security-focused software engineer to build the defensive layers and infrastructure that protect our mission-critical analysis platform. In this role, you will own the design and implementation of foundational security controls that ensure the integrity, confidentiality, and availability of sensitive engineering data. You will act as the primary security architect for critical workflows, translating complex threat landscapes into robust, production-ready defenses. This position requires a proactive mindset, where you anticipate future risks and build guardrails before problems emerge. You will partner closely with hardware and software engineers to embed security seamlessly into high-performance computing environments. Your work will directly influence the safety and reliability of systems that operate in some of the most demanding and regulated industries in the world.
Key facts
What you'll do
- Establish secure-by-default libraries and standards that govern authentication, authorization, and cryptographic implementations across the codebase.
- Execute in-depth security reviews of Go and Rust codebases, identifying subtle logic flaws and concurrency-related vulnerabilities.
- Lead threat modeling and design reviews for distributed system architectures, ensuring resilience against advanced adversarial techniques.
- Oversee software supply chain integrity by enforcing artifact signing and build-pipeline security protocols for air-gapped deployment scenarios.
- Integrate and tune CI/CD security tooling, including SAST, SCA, and fuzzing frameworks, to deliver high-signal, actionable feedback to developers.
- Architect and implement secrets management and key rotation strategies that minimize exposure and operational risk.
- Mentor the engineering organization on security best practices through detailed documentation and hands-on collaboration with cross-functional teams.
- Define and maintain security benchmarks and compliance controls tailored to the unique requirements of aerospace and defense workloads.
- Investigate and remediate security incidents, performing root cause analysis and implementing corrective measures to prevent recurrence.
- Collaborate with infrastructure and platform teams to harden containerized environments and virtualized compute resources.
- Evaluate emerging security frameworks and tools, conducting proof-of-concept validations for potential adoption.
- Partner with product teams to embed security requirements into feature specifications from the earliest design stages.
- Drive the creation of security playbooks and runbooks that streamline incident response and recovery operations.
- Contribute to open-source security projects where applicable, enhancing the broader ecosystem of trusted software components.
Requirements
- Bring 5+ years of production software engineering experience with a primary focus on security ownership and architectural decision-making.
- Demonstrate proficiency in reading, reviewing, and contributing to Go or Rust codebases at a deep technical level.
- Cultivate a comprehensive understanding of API and web vulnerability classes, applied cryptography, and modern authentication patterns.
- Show a proven ability to perform threat modeling on complex, distributed systems, identifying single points of failure and attack surfaces.
- Exhibit experience embedding security tooling directly into developer workflows and CI/CD pipelines to shift security left effectively.
- Master the art of communicating technical risk and tradeoffs to both engineering teams and executive leadership with clarity and precision.
- Hold U.S. citizenship, as this role requires access to sensitive defense and aerospace intellectual property.
- Maintain a strong commitment to operational excellence, with a focus on reliability, performance, and maintainability of security controls.
Nice to have
- Hands-on experience securing software for on-premise or air-gapped customer environments where connectivity is limited or restricted.
- Familiarity with supply chain security standards such as Sigstore, SLSA, and SBOM generation, including implementation within build pipelines.
- Background in Rust memory safety properties and fuzzing high-throughput data paths to uncover subtle concurrency and correctness issues.
- Expertise in container security, including image scanning, runtime protection, and the use of hardened base images.
- Practical familiarity with DAST or other dynamic testing methodologies to validate runtime behavior and interface security.
- History of working within regulated industries such as aerospace or defense, where compliance and safety are paramount.
Practical notes
This is a hybrid role requiring in-office attendance at our Marina Del Rey headquarters on Mondays and Thursdays, plus a company-wide gathering every two months. We are open to relocating candidates to Los Angeles or basing the role out of our San Francisco office. U.S. citizenship is a mandatory requirement for this position.