安全工程师
Security Engineer
### **关于 Starburst**
Starburst 通过为组织提供安全、受控的数据访问,实现大规模的企业智能。针对分布式数据环境构建,Starburst 帮助企业无需传统数据整合的成本和复杂性即可推动 AI 和分析。凭借包括 Trino 和 Apache Iceberg 在内的开放标准,Starburst 使组织能够获得完整的企业上下文信任访问,同时避免供应商锁定。领先的全球企业信赖 Starburst 来驱动 AI、分析和企业智能。了解更多信息,请访问 [starburst.ai](http://starburst.ai)。
##### 关于该职位
作为 Security Engineer II,你将通过构建自动化工具,帮助推进 Starburst 的应用安全计划,使一个小团队能够保护一个大型工程组织。你将把安全问题转化为可靠、自动化的系统,必要时利用 AI 提高效率。这是一个需要动手实践的工程职位:你将编写生产代码,将安全检查集成到 CI/CD 流水线中,并构建安全计划所依赖的自动化和防护机制。
你不需要在漏洞管理或进攻性安全方面有深入的专业知识。重要的是具备扎实的信息安全基础、强大的工程技能,以及做出合理安全权衡的判断力。这个职位提供了成长空间,可以逐步提升你的安全深度并承担更广泛的产品安全职责。
你将与工程和产品团队紧密合作。
##### 在 Starburst 担任安全工程师,你将:
- **为应用安全计划构建自动化和工具**,将手动、重复或难以扩展的安全工作转化为可靠的自动化系统,越来越多地由 AI 驱动。
- **将安全融入开发生命周期**,在 CI/CD 流水线中实现自动化安全检查,并构建可重用的防护机制和默认安全组件。
- **支持并扩展我们的安全工具栈**(SAST、DAST、SCA、密钥扫描),连接工具以便发现快速传递给正确的工程团队,并帮助开发者理解和修复问题。
- **应用 AI 扩展安全工作**,为分类、分析和修复原型设计并实现 AI 辅助的工作流程。
- **支持漏洞管理运营**,协助检测、分类和分配新披露的漏洞,并使该流程更快、更一致。
- **做出合理的安全权衡**
查看英文原文
### **About Starburst**
Starburst delivers enterprise intelligence at scale by giving organizations secure, governed access to all their data, wherever it lives. Built for distributed data environments, Starburst helps enterprises power AI and analytics without the cost and complexity of traditional data consolidation. With open standards including Trino and Apache Iceberg, Starburst enables trusted access to complete enterprise context while helping organizations avoid vendor lock-in. Leading global enterprises trust Starburst to fuel AI, analytics, and enterprise intelligence. Learn more at [starburst.ai](http://starburst.ai).
##### About the role
As a Security Engineer II, you'll help advance Starburst's Application Security program by building the automation and tooling that allows a small team to secure a large engineering organization. You'll take security problems and turn them into reliable, automated systems, using AI where it adds leverage. This is a hands-on engineering role: you'll write production code, integrate security checks into CI/CD pipelines, and build automation and guardrails the program depends on.
You don't need deep specialist expertise in vulnerability management or offensive security. What matters is a solid information security foundation, strong engineering skills, and the judgment to make sound security tradeoffs. This role offers room to grow your security depth and take on broader product security responsibilities over time.
You'll work closely with Engineering and Product.
##### As a Security Engineer at Starburst you will:
- **Build automation and tooling for the Application Security program**, turning manual, repetitive, or hard-to-scale security work into reliable automated systems, increasingly powered by AI.
- **Integrate security into the development lifecycle**, enabling automated security checks within CI/CD pipelines and building reusable guardrails and secure-by-default components.
- **Support and extend our security stack** (SAST, DAST, SCA, secrets scanning), connecting tools so findings reach the right engineering team quickly and helping developers interpret and remediate them.
- **Apply AI to scale security work**, prototyping and productionizing AI-assisted workflows for triage, analysis, and remediation.
- **Support vulnerability management operations**, helping detect, triage, and route newly disclosed vulnerabilities, and making that process faster and more consistent.
- **Make sound security tradeoffs** and help improve secure coding standards, documentation, and remediation playbooks.
##### Some of the things we look for:
- Bachelor's degree in Computer Science, Engineering, MIS, or equivalent practical experience.
- 2–4 years of experience in security engineering, software engineering, or a related technical role.
- A solid foundation in information security fundamentals, with the judgment to make sound security tradeoffs.
- Strong understanding of application vulnerabilities and mitigation strategies (OWASP Top 10, CWE).
- Demonstrated experience building automation and tooling, especially using AI, to solve real problems.
- Experience with one or more languages such as Python, Go, Java, or JavaScript/TypeScript (Java and Python preferred).
- Experience with CI/CD tooling, Git-based workflows, and modern development practices.
- Familiarity with cloud security concepts and hands-on experience with at least one cloud platform (AWS, Azure, or GCP).
- Experience in enterprise B2B software, self-managed and/or SaaS, is a plus.
### **Build your career at Starburst**
All-Stars have the opportunity and freedom to realize their true potential. By building alongside top talent, we’re empowered to take ownership of our careers and drive meaningful change. Anchored in industry-proven technology and unprecedented success, All-Stars are taking on the challenge everyday to disrupt our industry – and the future.
Our global workforce is supported by a competitive Total Rewards program that reflects our commitment to a rewarding and supportive work environment. This includes a variety of benefits like competitive pay, attractive stock grants, flexible paid time off, and more.
We are committed to fostering an intentional, inclusive, and diverse culture that drives deep engagement, authentic belonging, and an exceptional All-Star experience. We believe that diversity of thought, perspective, background and experience will enable us to own what we do, drive our success and empower our All-Stars to show up authentically.
Starburst provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state
or local laws.