远程工作雷达

资深产品安全工程师

Staff Product Security Engineer

开发工程限定地区(需当地身份)
公司UpGuard
薪资未公开
工作地点Australia
地域资格限定地区(需当地身份)
时区要求日间重叠约 7 小时,基本正常作息
用工类型permanent
发布时间6 天前
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 Australia 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

### **我们是谁?**

在 UpGuard,我们正在用人工智能驱动的精准性取代手动安全瓶颈。刚刚完成 7500 万美元 C 轮融资后,我们正在扩展基础设施,以每天处理 1000 亿个风险信号。这不仅仅是增长;而是对全球管理网络风险方式的彻底重新定义。

我们打造了网络安全态势管理(CRPM)平台,这是安全团队真正喜爱的平台。通过整合安全评分、威胁情报和代理型人工智能,我们使组织能够领先于不断变化的攻击面。

我们不仅仅是在打造另一个工具;我们正在定义一个新类别。我们提供自主开发世界级技术的能力,以及在全球范围内实现这一目标的资源。

### **关于该职位**

这是 UpGuard 首次专门招聘产品安全人员。随着公司规模扩大,你将对产品安全的方向拥有重要掌控权。你不会继承他人的决策,而是将定义保护 UpGuard 产品和基础设施多年的安全标准、工具和实践。

在这个职位上,你将在我们的产品和生产环境中工作:执行安全审查,管理漏洞,并在我们的云原生基础设施中运行检测和响应操作。你将与我们的产品工程和平台团队紧密合作,确保我们的产品、CI/CD 管道和生产系统安全,并从底层构建时就嵌入安全。

产品安全的职责范围很广,因此我们有意识地进行了优先级排序。在你最初的 6-12 个月内,你将:

- 将威胁建模和安全审查作为我们交付流程中的标准部分进行更新

- 确定 AI 在应用安全(代码审查、分类、覆盖率)中实际能起作用的地方,并构建有效的解决方案

- 强化我们的 GCP 和 Kubernetes 基线,并将默认安全配置纳入基础设施即代码

该职能位于我们工程组织的核心,你将拥有真正的自主权和影响力:定义安全路线图,推动最佳实践,并随着公司成长提升我们的安全态势。

这是一个高级别的个人贡献者职位。

### **你将负责**

- 在 UpGuard 的产品组合和云基础设施上领导威胁建模和安全审查,主动识别攻击路径并设计可随增长扩展的缓解策略。

- 构建自动化、政策即代码和人工智能驱动的安全工具,让产品工程团队能够“提前”进行安全防护,并有效减少风险。

查看英文原文

### **Who are we?**

At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk.

We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.

We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale.

### **About the role**

This is UpGuard's first dedicated product security hire. You'll have significant ownership over the direction of product security at UpGuard as we scale. You won't be inheriting someone else's decisions. You'll be defining the security standards, tooling, and practices that protect UpGuard's products and infrastructure for years to come.

In this role, you'll work across our product and production environments: performing security reviews, managing vulnerabilities, and running detection and response operations in our cloud-native infrastructure. You'll collaborate closely with our product engineering and platform teams to secure our products, CI/CD pipelines, and production systems, and to embed security into how we build from the ground up.

The full remit of product security is broad, so we've been deliberate about sequencing. In your first 6–12 months you'll:

- Refresh threat modelling and security review as a standard part of how we ship.

- Figure out where AI actually helps in AppSec (code review, triage, coverage) and build what works

- Harden our GCP and Kubernetes baseline and get secure-by-default configs into infrastructure-as-code

The function sits at the heart of our engineering organisation, and you'll have genuine autonomy and influence: defining the security roadmap, driving best practices, and scaling our security posture as we grow.

This is a Staff-level individual contributor role.

### **What you'll do**

- Lead threat modelling and security reviews across UpGuard's product portfolio and cloud infrastructure, proactively surfacing attack vectors and designing mitigation strategies that scale with growth.

- Build automation, policy-as-code, and AI-driven security tooling that lets product engineering teams "shift left" and embeds security across the SDLC, leveraging agentic workflows to triage, review, and scale the reach of a lean security function.

- Design and implement secure-by-default configurations for cloud and Kubernetes infrastructure.

- Own vulnerability management end-to-end, triaging and prioritizing by real risk, driving remediation with engineering teams, and building preventative controls across the software supply chain from development through production.

- Build scalable detection and response systems that catch malicious activity, triage the noise, and run incidents end to end.

- Build deep partnerships with our product engineering and platform teams, helping them deliver secure-by-design solutions.

You'll be building a function, not inheriting one; with real executive backing, at a company where product security is core to the business rather than a cost centre. Our engineering culture values iteration, collaboration, and speed, with a no-ego approach and pragmatic trade-offs. We're fully remote with optional offices in Sydney and Hobart, and no mandatory office attendance.

### **What you'll bring**

- 7+ years of experience in security engineering and/or software engineering/or security operations, work in cloud environments, with a focus on the below:

- Cloud security experience (GCP preferred, but AWS or Azure is welcome)

- Cloud native Kubernetes services (EKS/GKE/AKS) and strong container security principles

- Strong understanding of securing IAM and cloud identities

- Experience leading technical security reviews of products and architectures, running threat modelling exercises, and turning findings into security controls engineering teams can implement.

- Strong knowledge of common web application vulnerabilities and how to prevent them (OWASP Top 10 and similar).

- Hands-on experience with IAC and related tools (preferably Terraform/OpenTofu)

### **What will give you an edge?**

- Experience as the first security hire or founding member of a security function at a scaling company.

- Familiarity with AI/LLM security risks (e.g. OWASP LLM Top 10) and securing AI-powered product features.

- Strong backend engineering skills, particularly in Go

- Experience supporting SOC 2 / ISO 27001 audits from an engineering perspective.

- Public security research, CVEs, open-source security tooling, or conference talks.

- Offensive security skills, with the ability to validate findings through hands-on exploitation.

### **What's in it for you?**

- **WFH set-up allowance:** To ensure you have the right environment to work in, we will help you get set up within your first 3 months at UpGuard

- **Monthly Lifestyle subsidy:** Use this for financial, physical, and mental well-being

- **$1500 USD annual Learning & Development allowance:** To support your career development, all team members will be able to expense development opportunities against this allowance

- **Annual leave:** PTO plus two additional UpGuardian leave days to give you time to recharge your batteries.

- **18 weeks paid Parental Leave:** Irrespective of parenting role

- **Personal Leave Allowance:** This includes sick & carer’s leave

- **Fully remote working environment:** While we have physical offices in Sydney & Hobart, we do not mandate compulsory attendance

- **Top-spec hardware:** All team members will be provided with top-spec laptops for their role

- **Generative AI subsidy:** UpGuard provides paid subscriptions for all team members to access generative AI tools to support their work.

- **Stock options:** Share in UpGuard's growth and long-term success

UpGuard is a Certified Great Place to Work® in the US, Australia, UK and India, establishing its position as a leading global technology employer. 99% of team members agree that UpGuard is a great place to work! Apply now to find out why!

As an Equal Employment Opportunity and Affirmative Action Employer, qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.

**Please Note:** Not all roles can be performed from the United States. Please check your specific job listing to confirm its advertised location. If the role you are applying for is listed as based in the US, we are currently only able to support hiring in the following locations: CA, CO, FL, IL, LA, MA, MD, MO, OR, PA, TX, WA, and DC.

Before starting work with us, you will need to undertake a national police history check and reference checks. Also, please note that at this time, we cannot support candidates requiring visa sponsorship or relocation.

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

客户成功经理

UpGuardIreland, UKFull-Time今天
市场运营限定地区(需当地身份)

高级产品经理

UpGuardAustraliapermanent12 天前
职能支持限定地区(需当地身份)

← 返回全部职位