This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
At Cloudera, the Product Security group is dedicated to ensuring our platforms are secure by design and compliant with the most rigorous industry and government standards. We are seeking a highly motivated and experienced Level 4 Individual Contributor to join our Product Security Engineering (Security Features) team. In this role, you will be a "go-to" technical expert and the connective tissue between Security, Product, and Engineering teams, translating complex security requirements into actionable, automated engineering solutions. As a senior technical member of the team, you will exercise considerable latitude in determining technical objectives and defining approaches to complex issues. You will serve as a technical lead for security-driven initiatives, leveraging a deep understanding of technical architecture and underlying platforms to drive high-impact solutions for our products.
Job Responsibility:
Design, develop, and maintain advanced build tooling to accelerate the remediation of vulnerabilities across engineering pillars
Lead Proof of Concepts (POCs) for security initiatives and evaluate third-party tools to increase developer velocity while enhancing our security posture
Design, Develop Security Feature initiatives such as FIPs, TLS/Encryption, Secrets rotation, Identity & Access Management, Certificate Management
Help find root causes and triage complex product-related stability issues related to security
Build tooling around Security initiatives such as encryption inventory and other tools to gauge security standards of feature delivery
Author comprehensive design documents and test plans for cross-component security features, positively affecting change even in the face of ambiguity
Mentor lower-level team members and contribute to the growth of the team’s technical expertise through code reviews and documentation
Collaborate across organizational lines, interacting with internal stakeholders and senior management to resolve customer escalations and meet long-term objectives
Requirements:
B.S. or B.A. in Computer Science / related field or equivalent experience. with 10+ years of experience. Additional experience is acceptable in lieu of a degree
Deep technical expertise in containerized environments, specifically Kubernetes (EKS) and Docker
Strong proficiency in general-purpose programming and scripting languages like Python, Go, Java, and Bash
Proven experience with Infrastructure-as-Code (IaC) tools such as Terraform and Helm to automate secure infrastructure rollouts
Experience automating CI/CD processes using platforms like GitLab CI/CD, Jenkins, or GitHub Actions
Effective analytical and problem-solving skills, with the ability to root cause site outages or P1 escalations
Nice to have:
Experience with Post-Quantum Cryptography is desirable for our upcoming product transition
Experience with FIPS, Encryption is desirable to help with transitioning to FIPS 140-3, TLS 1.3 and beyond
Security-specific experience in CVE remediation automation and integrating SAST/DAST scanning (e.g., Trivy, Aquasec, Tenable Nessus, Fortify) into developer workflows
Familiarity with government compliance frameworks and standards such as FedRAMP, ISO 27001, or SOC 2
Knowledge of secure coding practices and common vulnerabilities (OWASP Top 10)
Experience in Identity and Access Management (IAM) or Identity Governance platforms
Strong stakeholder management skills, with the ability to influence without authority in a remote, cross-functional environment