PagerDuty·Atlanta·4 дн назад
Senior Security Engineer - Cloud Security
150 000 – 251 900 $ в год
на 2% ниже медианы рынка
≈ 1 млн–1,8 млн ₽
🏢 ОфисSeniorПолная занятость
Вилки нет, про деньги придётся договариваться с нуля.
Вакансия на английскомПереведёт заголовок и описание вакансии на русский
Наша компания
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. The PagerDuty Operations Cloud is an AI-powered platform that empowers business resilience and drives operational efficiency for enterprises. With a generative AI assistant at its core, PagerDuty empowers teams to detect and resolve issues in real time, orchestrate complex workflows, and drive continuous improvement across their digital operations. Trusted by nearly half of both the Fortune 500 and the Forbes AI 50, as well as approximately two-thirds of the Fortune 100, PagerDuty is essential for delivering always-on digital experiences to modern businesses PagerDuty is Great Place to Work-certified™, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2. Go behind-the-scenes on our careers site and on Instagram. Additional Information PagerDuty is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status. Your privacy is important to us. By submitting an application, you confirm that you have read and understand PagerDuty's Privacy Policy. PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email accommodation .com and we will work with you to meet your accessibility needs. PagerDuty uses the E-Verify employment verification program.
Чем предстоит заниматься
Harden PagerDuty's AWS and Kubernetes environments against CIS Benchmarks, DISA STIGs, and FedRAMP Moderate baselines across a multi-account, multi-org footprint — proving results through evidence, config-remediation tooling, and KPIs that track posture, identity, and encryption/PKI health so we know where we stand and where the gaps are
Harden EKS clusters and the Istio service mesh against the CIS Kubernetes Benchmark, DISA Kubernetes STIG, and NSA/CISA hardening guidance
Design and enforce Kubernetes RBAC, least-privilege workload identity, and container supply-chain controls (image provenance, admission control, runtime policy)
Own PKI and encryption standards across the environment — certificate lifecycle and management, KMS-backed key management and rotation, TLS/mTLS (including within the Istio mesh), and encryption-at-rest and in-transit requirements — and define the standards other teams build against
Design and roll out Service Control Policy (SCP) guardrails and least-privilege IAM/PAM across dozens of accounts and multiple orgs
Lean into AI to unlock efficiency and velocity — consume agentic tooling in day-to-day work and build lightweight agentic solutions that streamline repetitive security work: posture triage, threat modeling, risk assessment, incident enrichment and investigation, compliance-evidence generation, and detection tuning
Shape detection strategy for the domains you own — Kubernetes/Istio, identity, and cryptography — authoring and tuning detections in our SIEM stack, defining what "good" coverage looks like for these domains, and threat hunting for container escape, lateral movement, anomalous mesh traffic, and identity or credential abuse
Participate in the team's on-call rotation, triaging and dispositioning cloud and Kubernetes threat alerts and acting as Incident Lead during incidents — driving containment, blast-radius/exposure analysis, and post-incident review
Automate security controls as code using Terraform and Python — including Kubernetes policy-as-code and tool-to-tool integrations that reduce manual work
Partner closely with our AppSec and GRC teams — aligning platform controls with secure-development needs and translating hardening, identity, and encryption work into audit and compliance evidence
Mentor and guide teammates on platform, identity, and cryptography security practices, and contribute to roadmap and annual planning. At the senior end of this role, you'll help draft external- and auditor-facing communication and represent the team in cross-team planning
Наши требования
5+ years as a Security Engineer in an AWS-native, microservice SaaS environment, with a strong focus on cloud infrastructure, container, and identity security
Deep, hands-on expertise securing Kubernetes and containerized environments — EKS, RBAC, Kubernetes admission control, network policy, and workload identity
Container runtime and image security experience; familiarity with a service mesh such as Istio strongly preferred
Strong, hands-on expertise in PKI and cryptography — certificate lifecycle/management, TLS/mTLS, key management and rotation (AWS KMS or similar HSM/KMS), and encryption-at-rest/in-transit standards
Deep, hands-on expertise with AWS security services, including but not limited to: IAM family, Organizations/SCPs, Secrets Manager, KMS, GuardDuty, CloudTrail, and Config
Ability to inform and drive detection strategy within your domains — comfortable authoring and tuning detections in a modern SIEM and threat hunting for Kubernetes, identity, and cryptography-related threats
A builder's mindset toward AI — hands-on experience using agentic/AI coding tools and an interest in developing lightweight automation and agents to accelerate security work
Experience with security incident response and on-call — triaging alerts and coordinating containment during incidents
Proficiency with Infrastructure as Code and at least one programming language (Terraform plus Python, or similar), and comfort automating controls, including Kubernetes policy-as-code
Proven ability to scope ambiguous projects, break complex work into actionable items, and drive them to completion with a high degree of ownership
Hands-on experience hardening cloud and Kubernetes environments to CIS Benchmarks and DISA STIGs, and operating within FedRAMP Moderate (or similar) authorization; familiarity with NIST CSF, SOC 2, or ISO 27001
Experience building agentic or AI-assisted security automation (e.g., agent frameworks, LLM-backed tooling, and translating playbooks into automated pipelines)
Familiarity with securing AI/ML or agentic workloads running on cloud and Kubernetes infrastructure
Experience with cloud-native security tooling such as a CNAPP platform and an EDR/runtime-protection agent, including container and Kubernetes runtime protection
Experience partnering with AppSec and GRC teams to align controls and produce compliance evidence
Azure security exposure (Entra ID, Defender for Cloud) a plus, but not required
Demonstrated history of mentoring engineers and strong written and verbal communication skills
Working knowledge of PagerDuty's Incident Management and Process Automation products
Hesitant to apply?
We encourage you to submit your resume even if you don't meet every requirement. We value potential and consider each candidate's full professional story. Whether you're exploring a career change or taking your next step, we look forward to reviewing your application. If this just isn’t the right role or time - sign up for job alerts!
Where we work
PagerDuty operates a hybrid work model with offices in 8 major cities: Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. While we offer flexibility within our established locations, we cannot employ candidates residing in
Мы предлагаем
As a global organization, our total rewards approach is competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site
Competitive salary
Comprehensive benefits package
Flexible work arrangements
Company equity
ESPP (Employee Stock Purchase Program)
Retirement or pension plan
Generous paid vacation time
Paid holidays and sick leave
Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)
Paid volunteer time off: 20 hours per year
Company-wide hack weeks
Mental wellness programs
Eligibility may vary by role, region, and tenure
Дополнительно
Australia: Northern Territory, Queensland, South Australia, Tasmania, Western Australia
Canada: Alberta, Manitoba, Newfoundland, Northwest Territories, Nunavut, PEI, Quebec, Saskatchewan, Yukon
United States: Alaska, Hawaii, Iowa, Louisiana, Mississippi, Nebraska, New Mexico, Oklahoma, Rhode Island, South Dakota, West Virginia, Wyoming
Candidates must reside in an eligible location, which vary by role
How we work
Our values guide how we support customers, collaborate with colleagues, develop products, and foster a culture of belonging. They define not just our actions, but what it means to be Dutonian
People Leaders at PagerDuty are responsible for creating high performance environments that drive accountability. PagerDuty has four key dimensions that define our Leadership Impact: Lead Self, Lead the Team, Lead the Business, and Lead the Future. Each dimension has three associated competencies to give leaders a shared language for guiding their development, career, promotion, and succession planning discussions. Our Manager Expectations serve as a practical guide for managers to understand their responsibilities, prioritize their efforts, and drive engagement and performance
The base salary range for this position is 150,000 - 251,900 USD. This role may also be eligible for bonus, commission, equity, and/or benefits
Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience
Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process