Staff Product Security Engineer, Secure Design (Kernel and Virtualization)

Digital Ocean $180K - $215K/year Posted about 2 hours ago

100% remote US only · US (remote)

About the role

DigitalOcean is looking for a Staff Product Security Engineer who is passionate about partnering with engineers to assess and mitigate the security risk of its virtualization stack. You will own the security risk posture for the virtualization stack, building the frameworks the organization uses to reason about hypervisor risk: systematic threat models that surface risks, shared rubrics for assessing impact and likelihood, and clear ways of communicating them to security, kernel, virtualization, and provisioning teams. From there, you own the response, designing defense-in-depth mitigations and driving their implementation. The Secure Design team enables DigitalOcean to build secure-by-design products through early-stage reviews, threat models, automation, security patterns, guidance, and training.

Key Responsibilities:

  • Propose and implement mitigations and defense-in-depth for threats discovered through threat modeling the virtualization stack.
  • Provide deep technical expertise in systems architecture, kernel security features, and network architecture to build out a threat model for the virtualization stack.
  • Identify the trade-offs of different solutions and recommend efficient designs that achieve both functional goals and security requirements, working alongside cross-functional partners rather than delivering mandates.
  • Collaborate with development teams to implement remediations that protect customer workloads.
  • Mentor software engineering teams in security best practices and help oversee the vulnerability management program.
  • Help engineers understand how security events impact them, from new CVEs to hardware side-channel attacks like RetBleed.

Qualifications:

  • Deep familiarity with at least one kernel security feature (AppArmor, SELinux, Landlock, or similar).
  • Hands-on ability to assess the performance implications of code changes to virtualization stacks, especially in QEMU and KVM.
  • A record of partnering with internal engineering teams to tackle security problems across an entire stack with empathy and creativity.
  • Ability to clearly communicate security topics and vulnerability classes (memory corruption, privilege escalation, TOCTOU) and provide actionable direction to product teams.
  • Working knowledge of modern development concepts: virtualized environments, containerization, and continuous integration and delivery.
  • Preferred: 5+ years writing systems-level code (embedded, kernel, assembly), experience building or reviewing threat models, understanding of patches for hardware side-channel attacks, and familiarity with Go, Rust, or C.

Skills

How to apply

Apply directly on the employer's application page. Your application goes straight to them.

Republished listing

This opportunity was discovered on Digital Ocean's public careers page and is republished here for discovery purposes. Applications are handled by the employer.

Digital Ocean team? Claim this listing or ask us to remove it.