Back to all jobs

Engineer III - Product Security

Work from home Full-time role Hiring
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

Help us protect CrowdStrike and its customers from the most advanced threats by securing our applications. CrowdStrike’s Product Security team breaks the mold of traditional internal security, and focuses on active threats to CrowdStrike’s products. As an Application Security Engineer you will dig into web applications, find design and implementation flaws, help our product engineers fix defects, and play a role in shipping secure code. You’ll hunt for security defects and play a part in fixing those defects rather than just reporting them and hoping for the best. Additionally, you will be involved in cross-cutting projects to further harden internal systems and processes against active and emerging threats.

  • Join engineering teams working on applications as a security expert and advisor, influencing the design and capabilities of our products
  • Create and maintain threat models to drive security decisions and minimize threat surface area
  • Review application source code, looking for security defects and risk
  • Attack applications throughout the Secure Development LifeCycle
  • Work with developers to help them understand defects, risks, design weaknesses, etc. and implement proven solutions
  • Build integrated tools and automation to make life easier for you, your team, and our engineering partners
  • Assist in responding to our bug bounty program, hunt for similar issues, and improve the security of our applications

Qualifications

  • A moderate understanding of how software products are created and shipped in Agile/DevOps like environments
  • Moderate experience with threat modeling, especially using STRIDE
  • Code review experience for apps built with Go (Golang), Python, or Java
  • Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments (GCP, Azure, AWS)
  • Experience using and/or maintaining commercially available AppSec tools like SAST, DAST, CSPM, DSPM, and ASPM suites
  • An understanding of common software weaknesses that impact cloud and web applications (not just the OWASP Top 10) and experience in application penetration testing
  • Comfort with collaborating across technical teams: asking technical questions, challenging assumptions, getting or providing context for decisions, etc.
  • Experience with driving ambiguous research projects

Bonus Points

  • Self-motivated to identify security problems and engage with teams to find solutions
  • Demonstrable experience developing/maintaining automation for application security tasks and defect identification
  • Example(s) of having a positive working relationship with product engineers (software product development experience is a huge bonus)
  • Knowledge of Docker and Kubernetes (k8s)
  • Can explain and demonstrate the limitations of AI assisted development and associated security implications
  • Engaged in providing security enhancements to open source projects
  • Experience with threat intelligence driven testing and adversarial emulation

Education/Certifications

  • Technical security certifications or academic background are a plus.

Benefits

  • Remote-friendly and flexible work culture
  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays for recharge
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees regardless of level or role
  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
  • Vibrant office culture with world class amenities
  • Great Place to Work Certified™ across the globe
Apply To This Job Apply for this job

Related remote jobs

Senior FP&A Analyst

Work from home Full-time role

Senior DevOps Engineer

Work from home Full-time role

Systems Engineer

Work from home Full-time role

Lead Internal Auditor Data Analytics

Work from home Full-time role

Program Manager

Work from home Full-time role

Project Cost Estimator

Work from home Full-time role

Senior Project/Program Manager, Revenue Program Management

Work from home Full-time role

Product Manager

Work from home Full-time role

Director of Digital & Social Media

Work from home Full-time role

Associate Director, Quality Assurance

Work from home Full-time role

Entry-Level Remote Data Entry Associate – No Experience Required – Join arenaflex’s Growing Team

Work from home Full-time role

[Work From Home] PART TIME Remote Call Center Customer Service

Work from home Full-time role

Experienced Online Data Entry Specialist for Students - Flexible Home-Based Opportunities with The Elite Job

Work from home Full-time role

Senior Tax Analyst

Work from home Full-time role

Experienced Full Stack Customer Support Specialist – Remote Live Chat Support for Apple Products and Services

Work from home Full-time role

Associate II, Fund Administration (Accounting)

Work from home Full-time role

Experienced Customer Service Agent & Remote Data Entry Specialist – Unlock Endless Opportunities at arenaflex

Work from home Full-time role

Remote Energy Services Data Entry Clerk (Typist) – Full-Time Work From Home Opportunity Supporting Community Impact Programs

Work from home Full-time role

[PART_TIME Remote] Immediately Require Student Educational

Work from home Full-time role

Senior Software Engineer - Access & Notifications

Work from home Full-time role