All roles at JumpCloud are Remote unless otherwise specified in the Job Description.
About JumpCloud
JumpCloud® delivers a unified open directory platform that makes it easy to securely manage identities, devices, and access across your organization. With JumpCloud, IT teams and MSPs enable users to work securely from anywhere and manage their Windows, Apple, Linux, and Android devices from a single platform. JumpCloud is IT Simplified.
What we are looking for
JumpCloud is looking for a Senior Security Engineer on the DevSecOps team focusing on building and maintaining infrastructure, software, and automation to monitor and mitigate attacks and vulnerabilities across JumpCloud products and services. You will be part of a team based in the IST time zone responsible for ensuring JumpCloud products' integrity and keeping JumpCloud users safe. A US-based DevSecOps team is already in place and we are looking to build out a global team as an extension of the current team.
About the team
As a Senior Security Engineer on DevSecOps, you will be responsible for designing and developing software solutions for protecting data and infrastructure deployed into the cloud. You will collaborate with SecOps, GRC, and other security functions, gaining exposure to a broad range of security domains.
What you will be doingLead the design and maintenance of infrastructure, including custom software and vendor integrations, to meet advanced security needs for Product and Infrastructure SecurityDevelop and implement policy enforcement automation and comprehensive reporting systemsSet up data ingestion, as needed, for the SIEM or other toolingCollaborate with DevOps and Developer Enablement teams outside of the US to embed security best practices and establish guardrails for developersConduct and oversee threat model reviews of product features and architectures, providing strategic guidanceMentor and guide service/feature teams in secure software design principlesNecessary skills5 years of experience in the field of security engineering with an extensive background and experience in software development and architectureProduction experience with AWS or GCPComfortable writing Golang codeSome familiarity in Terraform (HCL) and KubernetesExperience with CI/CD tools, particularly GitHub ActionsStrong written and oral communication skills, with the ability to convey complex security conceptsYou also have some experience in one of the following areasRed teaming/internal pentesting Product Security (ProdSec) Including threat modeling and secure architecture design/reviewAuthentication protocols (SAML, OAuth, LDAP, etc.) Mobile application security (iOS and Android)Bonus points for experience withOpen Policy Agent (OPA) Open source security tools Data pipeline toolingCertificate infrastructureDistributed systemsWorking on core OS (Windows, Mac, Linux) APIsPersonal characteristics we are looking forResults oriented, self driven, and able to work independently with minimal supervisionHigh level of integrity with a commitment to accountabilityExcellent communication skills, capable of articulating complex ideas clearlyCreative problem-solving abilities with a passion for securityRole requirementsYou must overlap and work at least 5 hours within US Central Time business hours (e.g., 9:00 AM - 2:00 PM Central Time)You must be available for on-call (after hours) duties for any internal tools/services this new team might ownYou must be willing to support the Security Operations team during incidents in performing ad-hoc queries, forensics, etc. #LI-JW1
Where you’ll be working/Location:
JumpCloud is committed to being Remote First, meaning that you are able to work remotely within the country noted in the Job Description.
You must be located in and authorized to work in the country noted in the job description to be considered for this role.
Please note: There is an expectation that our engineers participate in on-call shifts. You will be expected commit to being ready and able to respond during your assigned shift, so that alerts don't go unaddressed.
Language:
JumpCloud has teams in 15+ countries around the world and conducts our internal business in English. The interview and any additional screening process will take place primarily in English. To be considered for a role at JumpCloud, you will be required to speak and write in English fluently. Any additional language requirements will be included in the details of the job description.
Why JumpCloud?
If you thrive working in a fast, SaaS-based environment and you are passionate about solving challenging technical problems, we look forward to hearing from you! JumpCloud is an incredible place to share and grow your expertise! You’ll work with amazing talent across each department who are passionate about our mission. We’re out of the box thinkers, so your unique ideas and approaches for conceiving a product and/or feature will be welcome. You’ll have a voice in the organization as you work with a seasoned executive team, a supportive board and in a proven market that our customers are excited about.
One of JumpCloud's three core values is to “Build Connections.” To us that means creating " human connection with each other regardless of our backgrounds, orientations, geographies, religions, languages, gender, race, etc. We care deeply about the people that we work with and want to see everyone succeed." - Rajat Bhargava, CEO
Please submit your résumé and brief explanation about yourself and why you would be a good fit for JumpCloud. Please note JumpCloud is not accepting third party resumes at this time.
JumpCloud is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
Scam Notice:
Please be aware that there are individuals and organizations that may attempt to scam job seekers by offering fraudulent employment opportunities in the name of JumpCloud. These scams may involve fake job postings, unsolicited emails, or messages claiming to be from our recruiters or hiring managers. Please note that JumpCloud will never ask for any personal account information, such as credit card details or bank account numbers, during the recruitment process. Additionally, JumpCloud will never send you a check for any equipment prior to employment.
All communication related to interviews and offers from our recruiters and hiring managers will come from official company email addresses (@jumpcloud.com) and will never ask for any payment, fee to be paid or purchases to be made by the job seeker. If you are contacted by anyone claiming to represent JumpCloud and you are unsure of their authenticity, please do not provide any personal/financial information and contact us immediately at recruiting@jumpcloud.com with the subject line "Scam Notice"
#LI-Remote #BI-Remote