Anyscale's product security needs are growing as we ship to larger and more demanding customers. We're looking for a Senior Product Security Engineer to own our secure software development lifecycle and to be engineering's partner on building security into the product. Reporting to the Head of Security, you will work in close partnership with engineering
This is a senior, high-ownership role. You will own and operate a scalable SSDL, partner with engineering on security features and secure design, review the security of existing systems and new initiatives, and own how we find, track, drive to resolution and report on vulnerabilities in what we ship. This role is based in India
In your first year, success looks like an SSDL that scales with engineering rather than gating it, security review embedded in how new initiatives ship, and accurate, on-demand vulnerability reporting backed by a working path to resolution
Own and operate a scalable secure software development lifecycle: threat modeling, security requirements, secure design practices, and scanning that engineering can readily adopt
Partner with engineering on security features and secure-by-design architecture, from early design through implementation
Review the security of existing systems and new initiatives, and turn findings into prioritized, actionable work
Own vulnerability management for what we ship: enumerate components, map known vulnerabilities, and produce accurate posture reporting on demand
Drive vulnerabilities to resolution with engineering against defined SLAs
Own software composition analysis, secret scanning, and SAST across product repositories, and set the bar for secure-development checks
Mentor other engineers and raise the security bar across the organization