Engineer III - Product Security

Remote Full-time

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.




Role Description


Help us protect CrowdStrike and its customers from the most advanced threats by securing our applications. CrowdStrike’s Product Security team breaks the mold of traditional internal security, and focuses on active threats to CrowdStrike’s products. As an Application Security Engineer you will dig into web applications, find design and implementation flaws, help our product engineers fix defects, and play a role in shipping secure code. You’ll hunt for security defects and play a part in fixing those defects rather than just reporting them and hoping for the best. Additionally, you will be involved in cross-cutting projects to further harden internal systems and processes against active and emerging threats.



Join engineering teams working on applications as a security expert and advisor, influencing the design and capabilities of our products


Create and maintain threat models to drive security decisions and minimize threat surface area


Review application source code, looking for security defects and risk


Attack applications throughout the Secure Development LifeCycle


Work with developers to help them understand defects, risks, design weaknesses, etc. and implement proven solutions


Build integrated tools and automation to make life easier for you, your team, and our engineering partners


Assist in responding to our bug bounty program, hunt for similar issues, and improve the security of our applications



Qualifications



A moderate understanding of how software products are created and shipped in Agile/DevOps like environments


Moderate experience with threat modeling, especially using STRIDE


Code review experience for apps built with Go (Golang), Python, or Java


Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments (GCP, Azure, AWS)


Experience using and/or maintaining commercially available AppSec tools like SAST, DAST, CSPM, DSPM, and ASPM suites


An understanding of common software weaknesses that impact cloud and web applications (not just the OWASP Top 10) and experience in application penetration testing


Comfort with collaborating across technical teams: asking technical questions, challenging assumptions, getting or providing context for decisions, etc.


Experience with driving ambiguous research projects



Bonus Points



Self-motivated to identify security problems and engage with teams to find solutions


Demonstrable experience developing/maintaining automation for application security tasks and defect identification


Example(s) of having a positive working relationship with product engineers (software product development experience is a huge bonus)


Knowledge of Docker and Kubernetes (k8s)


Can explain and demonstrate the limitations of AI assisted development and associated security implications


Engaged in providing security enhancements to open source projects


Experience with threat intelligence driven testing and adversarial emulation



Education/Certifications



Technical security certifications or academic background are a plus.



Benefits



Remote-friendly and flexible work culture


Market leader in compensation and equity awards


Comprehensive physical and mental wellness programs


Competitive vacation and holidays for recharge


Paid parental and adoption leaves


Professional development opportunities for all employees regardless of level or role


Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections


Vibrant office culture with world class amenities


Great Place to Work Certified™ across the globe




Apply Now
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Seasonal Sales Associate-7234 Henderson, KY 42420

Remote Full-time

[Remote] CTO - AI Thought Partner - fractional/virtual

Remote Full-time

Experienced HR Business Partner for Innovative Technology and Entertainment Solutions – Full Time and Part Time Opportunities at arenaflex

Remote Full-time

[Remote-Position] Senior Designer, Bedding(Remote Or Hybrid)

Remote Full-time

[Remote] Manager, ISS – Cybersecurity

Remote Full-time

Chargé d'affaires, ingénierie commerciale (h/f)

Remote Full-time

Verizon Specialist

Remote Full-time

Join Today: SACC Military Job Fair, Construction Manager

Remote Full-time

Require Middle School Language Arts Teacher in Michigan

Remote Full-time

Disney Remote Jobs (Work At Home)

Remote Full-time
← Back to Home