MongoDB is a leading database company that empowers innovation at the speed of the market. They are seeking a Senior Product Security Engineer to enhance the security of their core database products by collaborating with engineering teams and implementing security controls across their software and systems.
Responsibilities:
- You will take ownership, define strategy, and drive improvement for parts of our program such as fuzzing, threat modeling, secrets management, or container security
- Advocate for and lead complex security projects from inception through completion
- Drive architecture, patterns, and processes across Server Engineering that make security the easiest path
- Partner closely with engineering teams to design and implement security controls across our software and systems
- Research and POC new attacks against our systems. Plan and perform product security assessments including architecture review threat modeling, code review, pen testing and general security consulting to proactively build security controls
- Serve as a security subject matter expert for software security and architecture
- Educate the engineering org on security through CTFs, lunch-and-learns, and one-on-one mentorship
Requirements:
- 7+ years of experience in application security, software security, or product security
- Proven experience in C++ programming, performing security assessments on low-level codebases, and implementing remediation strategies for memory-related security flaws such as buffer overflows and memory leaks
- Programming experience and ability to contribute code back to our environments
- A strong track record of partnering with software engineers: leading threat models, performing security design reviews, and developing an understanding of their product space to form pragmatic security recommendations and influence their prioritization
- Comfortable communicating complex technical issues in a simple manner that builds trust with a variety of audiences
- Demonstrated ownership of security initiatives, with the ability to deliver results autonomously or collaboratively
- Subject matter expertise in database security, or data security
- Knowledge of database engines, database internals, or applied cryptography
- Experience contributing or partnering with security researchers to identify vulnerabilities that eventually are published CVEs or administrative responsibilities of a CNA