vCluster Labs is a venture-backed tech startup pioneering Kubernetes virtualization for the AI era. As a Senior Application Security Engineer, you will be responsible for ensuring the security of the product, defining security standards, and managing vulnerabilities while contributing to feature development and developer training.
Responsibilities:
- Core Product Security: Perform deep-dive security reviews of our core Go-based applications and Kubernetes controllers, as well as the frontend user interface. With a targeted focus on avoiding privilege escalation within our multi-tenant architecture
- Threat Modeling: Lead the threat modeling process for new features, proactively identifying risks associated with shared GPU resources and multi-cloud environments
- Automated Security: "Shift left" by continuing to integrate security checks into our CI and developer workflows. Optimizing these checks for speed, ensuring security never becomes a bottleneck for engineering velocity. Separately, you will manage automated and manual scanning of our entire product stack
- Vulnerability Management: Own the lifecycle of security vulnerabilities from discovery to remediation. You will triage both external and internal reports, drive the resolution of critical issues across the engineering organization, and communicate effectively across stakeholders
- Feature Development: Everyone at the organization contributes to both the ideas and development of new features. Many of which are directly related to security topics such as container breakouts and isolation, pushing the envelope of what’s possible in constrained environments
- Developer training: Make complex topics easier to understand for all engineers, including new attack vectors and secure coding concepts
Requirements:
- 5+ years in Application Security or Product Security, with a strong focus on containerized environments
- Deep understanding of Kubernetes architecture, RBAC, and container runtime security
- Comfortable reading and writing Go, which is the language of our core product
- Thrives in fast-paced cutting-edge environments
- Views feedback as a learning mechanism, not a critique, and is willing to understand the unique needs and concerns of customers
- CKS (Certified Kubernetes Security Specialist) or OSCP
- Experience securing AI workloads or GPU cloud infrastructure
- Experience writing custom security tooling or automation scripts in Python or Go
- Willingness to contribute to public-facing security documentation and 'Trust Center' to help customers navigate compliance