המקום בו המומחים והחברות הטובות ביותר נפגשים
What will you do
Engage with engineering teams to promote security-aware development of Red Hat technologies/solutions.
Understand current and emerging threats in the enterprise product and service space.
Analyze complex software systems and identify potential weaknesses in their architecture.
Plan and carry out threat modeling activities, and realistic threat simulations across our offerings.
Consult with software developers and product teams on improved security architecture.
Ensure that product roadmaps and new features mitigate risk, adhere to security policies, and provide customers with minimal security risk.
Contribute to customer facing security documentation, reference, and other data as used by the common vulnerabilities and exposures (CVE) pages.
Promote Red Hat Product Security efforts within the community and the greater public.
What will you bring
Bachelor's degree in computer science/engineering or equivalent/relevant work experience.
Strong understanding of common security vulnerabilities, (e.g. OWASP Top Ten) including how to detect, demonstrate, mitigate and resolve them.
Good understanding of Linux security technologies and product security experience; for example:
POSIX Permissions, ACL, SELinux;
Seccomp, Linux namespaces and cgroups;
Linux administrations related to security: secure boot, TPMs, trusted execution environment, Linux boot chain, virtualization, containers and hypervisor security.
Experience with one or more programming languages like Go, Python, C/C++, and a willingness to learn new ones.
Knowledge and experience with modern container orchestration systems: Kubernetes, Openshift; comfortable with container technologies.
Ability to work with minimal supervision, in a fast-paced environment with a multicultural team distributed across multiple countries and time zones.
Solid communication and negotiation skills. Excellent collaboration skills and dedication as a teammate.
The following will be considered a plus:
Familiarity with open source software and open source as a business model.
Linux-specific and/or security-related certifications (e.g. RHCSA, RHCE, RHCA, CISSP, CISM, CSSLP, CISA, etc.)
Work experience and/or certifications with cloud providers and cloud-related technologies (AWS, Azure, GCP, Tekton, Jenkins, etc.)
משרות נוספות שיכולות לעניין אותך