FreshRemote.Work

Software Engineer, Security - San Francisco, CA or Remote (USA & Canada)

At Render, we are building a powerful, easy-to-use cloud platform to host anything online: from simple static sites to complex applications with dozens of microservices. Render offers the flexibility of traditional cloud providers without their complexity and maintenance headaches so developers and businesses can focus on building products instead of managing servers.

We're a talented and diverse group solving a problem faced by every development team. We iterate quickly while placing the utmost importance on user experience, quality, and reliability. We push ourselves to do better every day. Our organic, product-led growth has already attracted over a million developers. Customers include innovators like Mitchell Hashimoto, the cofounder of HashiCorp; climate unicorns like Watershed; and global enterprises like Red Bull. With our rapidly increasing revenue, we're on to something big.

Applying to Render

We're looking for candidates with high integrity, low ego, and an insatiable drive to learn. We use reasoned discussion and constant feedback to improve as individuals and as a company. We cultivate mutual trust and respect, empowering us to debate ideas effectively and create the best outcomes for our customers and our team.

We especially encourage members of underrepresented groups in the tech community to apply.

Our interview process is unique to each role, and we value the candidate experience just as much as our customer experience. We hope your conversations with us reflect a thoughtful process that is illuminative, enjoyable, and respectful of your time.

About the role

We have a product developers love and proven market momentum. Enterprise teams are onboarding to Render with mature security programs. They have built strong internal controls and policies to support their business needs. We're raising the bar on our platform security to give our customers confidence in the confidentiality, integrity, and availability of their services on Render. Through our work, we'll continue to attract and retain larger customers, unlocking revenue growth for our business. We're looking for a well-rounded, empathetic, security-minded software engineer to be a foundational part of building Render's security program.

You will

  • Build internal tooling to enable secure access to resources (e.g., wrappers, utilities, authentication services, and proxies).
  • Maintain a development toolkit that enables our teammates to write secure code with ease and apply security best practices.
  • Analyze and assess security issues identified through security reviews, threat modeling, penetration testing, and vulnerability disclosure.
  • Work with developers on sensitive code paths and educate them on secure design patterns.
  • Liaise with customers regarding their security and compliance needs, and in return, inform our security program.
  • Reduce compliance toil and friction through high-leverage automation and programmatic workflows.
  • Communicate security risks and solutions to technical and non-technical stakeholders as part of company-wide planning and prioritization processes.
  • Stay up-to-date with the latest security threats, vulnerabilities, and best practices and make recommendations for improvements to our security posture.
  • Partner with product engineering teams to inform and build thoughtful security features for our customers.
  • Continually ensure that our systems have appropriate authentication, authorization, and accounting with low internal overhead.

What we’re looking for

  • Experience designing and building secure web applications, tools, and APIs
  • Experience securing systems on AWS or GCP
  • Experience with infrastructure as code (e.g. Terraform, Ansible)
  • Knowledge of the Go programming language
  • Experience with vulnerability review and analysis

Nice-to-Haves

  • Experience building a security program such as one based on NIST CSF or ISO 27001
  • Experience securing Kubernetes clusters and workloads
  • Experience designing and analyzing secure GraphQL APIs
  • Experience securing software supply chains in accordance to frameworks like SLSA
  • Experience with testing tools such as Burp Suite, OWASP ZAP, and Semgrep
  • Active participation and contributions to the security community through public research, blogging, presentations, and other means
  • Proven expertise in exploiting common security vulnerabilities, demonstrating practical experience in identifying and leveraging vulnerabilities to assess security posture
  • Security certifications such as CISSP

Benefits

  • Our openings span more than one career level. The starting salary for this role is between $150,000 and $220,000 USD. The provided salary depends on many factors, such as work experience and transferable skills, business needs and impact, and market demands.
  • The opportunity is also eligible for equity with early exercise options and extended exercise windows.
  • 4 weeks of paid vacation, available from day one.
  • 14 weeks of fully paid parental leave for all parents to bond with a newly born, adopted, or fostered child. We will also work with you to create a supportive plan of return.
  • Long-term disability, life insurance, and 401K plans.
  • 100% employer-paid medical coverage and 99% employer-paid dental and vision coverage for you and a dependent. FSAs available as well.
  • Monthly lifestyle stipend for wellness, mental heath and therapy, hobbies, etc. 
  • Monthly cell phone and internet subsidy.
  • Commuter benefits for Renders in the Bay Area, and home office stipends for remote Renders.
  • Continuous learning benefits & related support.

Render is an equal-opportunity employer. We know employing a team rich in diverse thoughts, experiences, and opinions allows our employees, our product, and our community to flourish. We make all employment decisions including hiring, evaluation, termination, promotional, and training opportunities, without regard to race, religion, color, sex, age, national origin, ancestry, sexual orientation, physical handicap, mental disability, medical condition, disability, gender or identity or expression, pregnancy or pregnancy-related condition, marital status, height and/or weight.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive other benefits and privileges of employment. Please contact us to request an accommodation.

We encourage all who are interested to apply. We can't wait to hear from you!

Apply

Job Profile

Regions

North America

Countries

Canada United States

Benefits/Perks

Paid parental leave Paid Vacation

Skills

AWS GCP Go programming language Infrastructure as Code Secure web applications User Experience

Tasks
  • Analyze security issues
  • Automate compliance tasks
  • Build internal tooling for secure access
  • Collaborate on security features
  • Communicate security risks
  • Educate developers on secure design
  • Ensure system security measures
  • Liaise with customers on security needs
  • Maintain development toolkit for secure coding
  • Stay updated on security best practices
Timezones

America/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9