Tailscale is building the new Internet by delivering software that makes it easy to securely interconnect people and their devices. The Security Infrastructure Engineer will help grow the product security team by designing security controls, improving security features, and auditing infrastructure for weaknesses.
Responsibilities:
- Design and build security controls across diverse layers (e.g., cloud platforms, OS, Kubernetes, networks, CI/CD) to defend against sophisticated adversaries and insider threats
- Improve the security properties of Tailscale by identifying opportunities for security and privacy features, bug fixes, defense-in-depth, and implementing them across our codebase
- Audit Tailscale infrastructure for technical security weaknesses, identifying mitigations or solutions, and driving them towards resolution
- Support engineering decisions with threat modeling and security analysis and expertise
- You will spend 25-50% of your time in this role writing software vs purely operational or governance security responsibilities
Requirements:
- Expertise in the security of cloud platforms (e.g., AWS), especially securing multi-cloud networks and infrastructure, and designing cloud agnostic systems
- Familiarity with container security, orchestration security, and authentication/authorization
- Familiarity with internet/web security fundamentals: WAF's, TLS, PKI, DNS security, etc
- Proficiency developing in at least one programming language (Tailscale uses Go) and Infrastructure as Code tooling (e.g. Terraform, Ansible)
- Prior experience in a safety-related technical role, e.g.: infrastructure security, security operations, threat modeling and prioritization, digital forensics and incident response
- Knowledge of operating system internals and security mechanisms
- Knowledge of common networking protocols
- Ability to give and process constructive feedback
- Ability to work independently and collaboratively
- Flexibility to adjust to the dynamic nature of a startup
- Take a risk-based approach to building security controls, balancing your security expertise and broad technical skillsets with practical, usable solutions