远程工作雷达

安全工程师

Security Engineer

开发工程限定地区(需当地身份)
公司Panopto
薪资$150,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

公司简介:

在Panopto,我们是全球最以客户为中心的学习科技公司。作为视觉和音频学习领域的领导者,我们使组织能够轻松地在捕获和后捕获的世界中分享知识。我们不只是构建软件;我们专注于用户的目标,提供真正重要的解决方案。我们的使命很简单:吸引最优秀的人才,像你这样的人,提升专业技能,开展职业生涯中最有影响力的工作。

为了增强我们的团队,我们正在寻找一位经验丰富的高级DevSecOps工程师,能够在工程与安全的交汇点上茁壮成长。在这个职位上,你将负责一个被数百万用户使用的平台的安全态势,与开发人员紧密合作,从一开始就构建安全的系统。

职位概述:
在这个职位上,你将有机会在职业生涯中从事有意义的工作,提升你的专业技能,同时为一个重视终身学习的团队做出贡献。

作为高级DevSecOps工程师,你是支撑全球大学和企业视频知识管理平台的关键守护者。你不会在一个孤立的孤岛或“象牙塔”中工作。相反,你将通过将自动化安全控制直接嵌入开发生命周期和CI/CD流水线来提升安全专业的水平。你将弥合合规标准(ISO 27001、SOC 2、TX-RAMP)与高速度软件工程之间的差距,确保我们的安全态势具有实用性、可扩展性,并建立在清晰而非复杂的基础上。推动以AI为核心的理念,你将利用现代自动化工具和AI工作流程,消除手动安全任务,加速威胁建模,并简化系统架构。

你还将有机会参与其他直接推进我们核心价值观的项目,并支持你提升专业技能。

你将如何贡献:
在这个职位上,你将有机会...

  • 设计安全系统:主导跨多种AWS服务的新功能威胁建模评估,确保安全从第一行代码开始就被融入应用设计中。
  • 推动主动防御与CI/CD安全:在我们的AWS交付流水线中构建、维护并实施自动化静态(SAST)、动态(DAST)和依赖项(SCA)安全测试框架,以在代码进入生产环境之前发现漏洞。
  • 保障云与容器基础设施:设计并管理AWS上的安全防护措施
查看英文原文

Company Overview:

At Panopto, we are the most customer-centric learning technologycompany in the world. As the leader in visual and audio-based learning, we empower organizations to share knowledge effortlessly in a capture and post-capture world. We don’t just build software; we obsess over our users’ goals to deliver solutions that truly matter. Our mission is simple: to attract the brightest talent, people like you, to Elevate the Craft and do the most impactful work of your career.

To enhance our team we are seeking an experienced Senior DevSecOps Engineer who thrives at the intersection of engineering and security. In this role, you’ll own the security posture of a platform used by millions, partnering closely with developers to build secure systems from the ground up.
Position Summary:
In this role, you will have the opportunity to do meaningful work in your career, elevating your craft while contributing to a team that values lifelong learning.
As a Senior DevSecOps Engineer, you are a critical guardian of the platform that powers video knowledge management for global universities and businesses. You will not operate in an isolated silo or an "ivory tower." Instead, you will elevate the craft of security by embedding automated security controls directly into the development lifecycle and CI/CD pipelines. You will bridge the gap between compliance standards (ISO 27001, SOC 2, TX-RAMP) and high-velocity software engineering, ensuring our security posture is pragmatic, scalable, and built on Clarity over Complexity. Driving an AI-first mindset, you will leverage modern automation tools and AI workflows to eliminate manual security tasks, accelerate threat modeling, and simplify system architectures.
You'll also have opportunities to contribute to other initiatives that directly advance our core values and support you in elevating your craft.
How You’ll Contribute:
In this role, you will have the opportunity to…

  • Design Secure Systems: Lead hands-on threat modeling assessments on new features across many different AWS services, ensuring security is baked into application design from the first line of code.
  • Drive Proactive Defense & CI/CD Security: Build, maintain, and enforce automated static (SAST), dynamic (DAST), and dependency (SCA) security testing frameworks within our AWS delivery pipelines to catch vulnerabilities before code reaches production.
  • Secure Cloud & Container Infrastructure: Design and manage security guardrails across AWS environments, Kubernetes clusters, Docker containers, and CloudFormation/CDK/Terraform Infrastructure-as-Code (IaC) deployments.
  • Own Policy & Automated Governance: Lead the technical implementation of policy-as-code and compliance guardrails (ISO 27001, SOC 2, TX-RAMP), translating complex regulatory requirements into simple, actionable engineering standards.
  • Leverage AI Security Tools: Evaluate and integrate AI-assisted tools to accelerate code reviews, log analysis, and vulnerability triage, while establishing secure usage guidelines for developer AI tools.
  • Lead Incident Response: Act with ownership during security events by conducting investigations and root-cause analysis, using collective wisdom to prevent future incidents.
  • Mentor Engineering Teams: Coach developers on secure coding practices, threat identification, and vulnerability remediation through practical mentorship and reusable design patterns.

What Success Looks Like:

  • Within 6 Months: Execute threat modeling assessments for active feature releases. Complete an audit of our current CI/CD pipelines, assume technical ownership of cloud security standards, and establish working relationships with lead developers.
  • Within 1 Year: Automate at least one major vulnerability triage workflow in the build pipeline.
  • Your Legacy: Establish fully automated policy-as-code guardrails across AWS and Kubernetes environments, demonstrating a measurable reduction in security debt during architectural reviews.

Values in Action

  • Customer First, Always: You proactively surface friction points in the customer experience before they are escalated — and propose solutions, not just reports.
  • Thrive Together: You share work-in-progress for early feedback, knowing that challenge improves the outcome. You separate critiques of ideas from critiques of people.
  • Elevate the Craft: You hold the bar high on your own work and invest in developing those around you. You treat every project as an opportunity to learn something new.
  • Act with Ownership: You define success by outcomes, not activity. You flag problems early and bring a proposed path forward, not just the problem.
  • Clarity Over Complexity: You default to the simpler solution. Your written communication — internal or external — is direct, specific, and free of filler.

How We Thrive:
You’ll work with a team of talented engineers with a variety of areas of expertise, from devops to design, architecture to accessibility. The team’s experience level ranges from seasoned developers with well over a decade in industry to junior developers and contractors who are growing their roles and impact.
The Foundation for Success:

  • Cloud & Container Security Mastery: Proven track record securing Multi-Account AWS environments and Infrastructure-as-Code deployments (IAM/Identity Center, Network Security, Encryption, Docker/ECS/Fargate, Terraform, CloudFormation/CDK, Security Hub, GuardDuty).
  • Pipeline Automation & Code Proficiency: Strong hands-on experience integrating security tools into CI/CD pipelines and writing automation scripts using Python or Bash.
  • Practical AI Application: Demonstrated experience using AI tools (such as automated code reviewers, LLM tools, or AI-driven security scanners). In addition, experience securing AI systems, AI supply chinese, and AI-assisted workflows.
  • Threat Modeling Execution: Proven ability to evaluate application architectures for security flaws and guide teams on mitigating OWASP Top 10 vulnerabilities.
  • Pragmatic Compliance: Understanding that security must support business velocity, with experience turning compliance requirements into automated checks without slowing down software releases.
  • Experience: 7+ years in security engineering, DevSecOps, software development, or cloud infrastructure security.

What Sets You Apart:

  • Security or cloud certifications such as CISSP, AWS Certified Security - Specialty, or Certified Kubernetes Security Specialist (CKS).
  • Experience securing video streaming architectures or high-scale backend services.
  • Experience implementing policy-as-code frameworks in regulated SaaS environments.

Join Us
Join Panopto and play a key role in shaping the security foundation of a platform used by millions. If you love threat modeling, automating defenses, guiding engineering teams, and turning compliance standards into practical, scalable security practices, you’ll feel right at home here.

Beyond the Requirements: At this point, we hope you're feeling excited about the job description you’re reading. Even if you don't feel that you meet every single requirement, we still encourage you to apply. We're eager to meet people that believe in our mission and can contribute to our team in a variety of ways - not just candidates who check all the boxes. We want people to feel comfortable expressing their true selves and to come, stay, and do their best work here.

Recruiting Tips: From crafting an impressive resume to presenting your best self during our interviews, we're dedicated to ensuring you feel well-prepared and self-assured as you embark on opportunities at Panopto. Discover some valuableRecruiting Tipsfrom our team.

The standard interview process at Panopto involves several steps, outlined below, to ensure we approach the process thoughtfully and consistently:

Application Review -> Recruiter Call -> Video Interview & Assessment -> Hiring Manager Call -> Interview Loop -> Debrief -> Offer

Our people and culture

Panopto’s mission is to be the leader in visual and audio-based learning in a capture and post-capture world. Our user base is as diverse as the world’s universities and businesses. Panopto’s commitment to fostering a fair, equitable, and inclusive culture empowers each member of our team to express their authentic selves, contribute their distinct perspectives and make a meaningful impact both individually and collectively. This inclusive environment not only encourages creativity and the free exchange of ideas but also harnesses the power of varied viewpoints. As a result, we are better equipped to tackle our most intricate challenges, leveraging the wealth of different experiences and backgrounds within our team. This collaborative spirit empowers us to challenge ideas (not people) recognizing that our shared success relies on collective wisdom. It drives us to continuously improve and innovate, ultimately elevating the quality of our products and services. It’s what sets Panopto apart as a unique and rewarding place to work.

Our purpose

We believe that video can have a transformative effect on learning. So we built a video knowledge management platform that helps businesses and universities improve the way that they train, teach, and share knowledge. Since 2007, we have been a pioneer in video capture software, video management, and inside-video-search technology. Panopto has been adopted by more than 1,600 companies and universities worldwide with over 11 million end users. Today, Panopto’s knowledge management platform is the largest repository of expert learning videos in the world. A proud remote-first company, Panopto is headquartered in Pittsburgh, with offices in London, Hong Kong, Singapore, and Sydney, and has received industry recognition for its innovation, rapid growth, and company culture.

Panopto is an Equal Opportunity Employer.

We value and encourage diversity and solicit applications from all qualified individuals which will receive consideration for employment without regard to race, color, religion, sex, marital status, sexual orientation, gender identity or expression, national origin, age, disability or protected veteran status, or any other legally protected criteria, in accordance with applicable law. Panopto is committed to providing reasonable accommodation to applicants with disabilities. If you require accommodation for interviewing or otherwise participating in the employee selection process, please provide more detail on how we can further support you by reaching out to the Employee Experience department.

Remote, US: Candidates looking for flexible or remote-friendly positions are encouraged to apply. Panopto is proud to be a remote-first company. Employees in this position are eligible to work remotely.

Remote, International: Candidates looking for flexible or remote-friendly positions are encouraged to apply. Panopto is proud to be a remote-first company. Employees in this position are eligible to work remotely. Still, they may make regular trips to the local international office from time to time, where applicable.

Use of Artificial Intelligence (AI):

Panopto may utilize artificial intelligence (AI) tools to assist in our recruitment and evaluation process. This may include analyzing resumes, assessing skills, and generating insights to help identify qualified candidates.

Please be assured that AI tools are used to support our team, and all final hiring decisions are made by human reviewers. Panopto hiring teams will thoroughly review your application and assessment results. AI is not used to make final decisions regarding your candidacy.

By submitting your application and participating in the recruitment process, you acknowledge and consent to Panopto's use of AI tools as described above.

We are committed to full compliance with all applicable labor laws, including Equal Employment (EEOC) laws, across all our company entities.

To ensure fairness and transparency: We have human oversight in all hiring decisions. If you have concerns regarding the use of AI in your assessment, please contact Panopto Talent Attraction to request a manual review of your application. Please be aware that while we offer this option, the manual review process may take longer than the standard AI-assisted process.

Any data collected during this process, including video recordings if applicable, will be retained only for the duration necessary to fulfill the hiring purpose and will be deleted shortly thereafter once the role is filled.

We may utilize vendor tools to assist with the AI process. Vendor functions are ‘skill assessments' or 'resume analysis'.

Panopto is dedicated to a fair and equitable hiring process for all candidates.

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

DataOps工程师

PanoptoUnited States$150,000 - $170,000/年Full Time今天
开发工程职能支持限定地区(需当地身份)

← 返回全部职位