Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Engineer, Product Security image - Rise Careers
Job details

Security Engineer, Product Security

The Company

Cape was founded in early 2022 by Palantir and Anduril alums with deep expertise in privacy and national security. While running Palantir’s US national security business, our CEO became passionate about privacy and security on mobile devices. Our mission is to be a force for good in global wireless.

At Cape, we are not just another cellular service provider; we are the architects of a privacy-centric movement that starts with the devices in your pocket. We are building a cellular network that helps citizens, including those responsible for our nation’s security, regain control of their own data.

We believe that where we are, where we go, and whom we are with are among our most personal information and should be kept private. Privacy is not something you achieve by limiting yourself or by doing less, it is a set of features to be built so you can do more. We have raised money from Andreessen Horowitz and other top-tier VCs, and are excited to grow the team.

The Team

We are relentless builders, constantly pushing the boundaries of what's possible and bringing to life ideas that have never before existed. Innovation is at the core of everything we do. At Cape, we trust our team to deliver greatness and empower them to make a profound impact. As a member of our team, you will collaborate seamlessly with our diverse group of talented engineers and other team members, enjoying dynamic interactions with colleagues from across the organization.

The Role

We are seeking a Security Engineer with a specialization in product security to join our team. As a strategic partner, you will make an immediate impact by leveraging your expertise in cloud and application security. This role is pivotal in reducing risk across our AWS cloud environments and mobile applications. You will be responsible for designing, implementing, and maintaining security measures that comply with regulatory standards, enhance internal processes, and minimize data security risks. Through developing ongoing security strategies and technologies, you will support the organization's business objectives and daily operations.

Responsibilities

  • Design, implement, and manage robust security controls and policies within AWS, focusing on the confidentiality, integrity, and availability of data and services.

  • Perform comprehensive security assessments of our cloud environments to identify vulnerabilities, assess risks, and recommend actionable mitigation strategies.

  • Lead the integration of security practices into the DevOps lifecycle, promoting secure code development, deployment, and operations.

  • Utilize and optimize AWS security tools (such as Amazon GuardDuty, Amazon Inspector, AWS IAM, AWS KMS, AWS WAF, and AWS Shield) and explore third-party solutions to bolster our security posture.

  • Assist in addressing findings from penetration tests and security audits, ensuring prompt and effective remediation.

  • Stay informed about the latest security threats, vulnerabilities, and compliance mandates affecting cloud environments, providing guidance on emerging technologies and security best practices.

  • Offer expert guidance and mentorship to junior security team members and engineers across the company, fostering an organizational culture of security awareness and continuous improvement.

  • Collaborate with stakeholders to integrate security requirements effectively into engineering projects and business initiatives.

Preferred Experience

  • Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience), with advanced degrees or certifications (e.g., CISSP, AWS Certified Security Specialty) being advantageous.

  • A minimum of 5 years of experience in information security, with at least 2 years concentrated on cloud security within AWS environments.

  • Deep understanding of AWS architecture, security services, and best practices for securing cloud applications and data.

  • Proficiency in using infrastructure as code (IaC) tools (like Terraform or AWS CloudFormation) and in automating security tasks within AWS.

  • Skilled in scripting languages (Python, TypeScript, Go) for the automation of security tasks and the integration of security tools.

  • Solid knowledge of network security, encryption technologies, and secure coding practices.

  • Excellent analytical skills for identifying and mitigating complex security vulnerabilities and risks.

  • Strong communication and leadership abilities, capable of working collaboratively across teams and effectively conveying technical information to non-technical stakeholders.

  • Organized and able to manage multiple priorities in a dynamic, fast-paced environment.

Our Culture 

  • We are builders, and we choose to spend our time building things that matter. Many of our people have backgrounds in Defense Tech as well as the defense and intelligence community. We build to win.

  • We hire excellent people, give them outsized responsibility, and trust them to execute at a high level. Everyone here has a track record of solving hard problems throughout their careers.

  • We believe that personal privacy and national security interests are not inherently at odds, and can be reconciled via strong technology.

  • We believe that companies exist to build awesome things and take care of their people. Our benefits reflect that– top-tier health care, 401(k) matching, and a generous vacation policy (that we actually use).

  • We hire candidates of any race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, Veteran status, and any other status. Achieving diversity across these categories will serve to make our company stronger and our product better.

How to apply

Click the link below to apply.

We reserve the right to make use of any unsolicited resumes received from outside recruiting agencies and / or individual recruiters without being responsible for payment of any fees asserted from the use of unsolicited resumes.

Cape Glassdoor Company Review
3.3 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Cape DE&I Review
1.8 Glassdoor star icon Glassdoor star icon Glassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Cape
Cape CEO photo
Joe Oatley
Approve of CEO

Average salary estimate

$120000 / YEARLY (est.)
min
max
$100000K
$140000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Engineer, Product Security, Cape

At Cape, we're on a mission to reshape mobile privacy and national security, and we're looking for a passionate Security Engineer specializing in product security to join our innovative team. Founded by experts from Palantir and Anduril, our focus is on creating a cellular network that empowers users to take control of their data, and we need someone with your expertise to get us there! As a Security Engineer at Cape, you will play a crucial role in fortifying our cloud environments, particularly within AWS, and securing the mobile applications that our users rely on. Your extensive knowledge in cloud and application security will be critical as you design and implement robust security measures that comply with regulatory standards and enhance internal processes. Days filled with collaboration and growth await you as you work closely with talented engineers to create security strategies that align with our business goals. You will conduct security assessments, integrate best practices into our DevOps lifecycle, and use advanced AWS security tools. Not only will you help to identify and manage vulnerabilities, but you'll also mentor junior team members and promote a culture of security awareness throughout the company. If you are driven by innovation and want to contribute to something truly impactful, Cape is the perfect place for your skills. Together, we can build a secure future for everyone!

Frequently Asked Questions (FAQs) for Security Engineer, Product Security Role at Cape
What are the key responsibilities of a Security Engineer at Cape?

As a Security Engineer at Cape, your primary responsibilities include designing and implementing security controls and policies within AWS, conducting thorough security assessments to identify and mitigate vulnerabilities, and integrating security practices into our DevOps lifecycle. You will also support the implementation of AWS security tools, assist with penetration tests and audits, and offer mentorship to junior team members. Your role is vital in maintaining the integrity and security of our product, ensuring compliance with standards, and fostering a culture of awareness across the organization.

Join Rise to see the full answer
What qualifications are required for a Security Engineer at Cape?

To be considered for the Security Engineer position at Cape, you should possess a Bachelor's degree in Computer Science, Information Security, or a related field, along with at least 5 years of experience in information security, with 2 years focusing on AWS cloud environments. Additional certifications like CISSP or AWS Certified Security Specialty are preferred. You should also have a deep understanding of AWS architecture, proficiency in automation and scripting tools, and strong analytical skills for identifying security vulnerabilities.

Join Rise to see the full answer
What tools does a Security Engineer at Cape work with?

At Cape, a Security Engineer will work extensively with AWS security tools, including Amazon GuardDuty, Amazon Inspector, AWS IAM, AWS KMS, AWS WAF, and AWS Shield. You'll also explore third-party solutions to enhance our security posture. Proficiency with infrastructure as code tools like Terraform or AWS CloudFormation is essential, along with scripting in languages such as Python, TypeScript, or Go, to help automate security tasks and integrate security practices into our development processes.

Join Rise to see the full answer
How does Cape support professional growth for Security Engineers?

Cape is deeply committed to fostering professional growth and empowering our team members to excel. As a Security Engineer, you will have the opportunity to collaborate with a diverse group of talented individuals, share your expertise, and mentor junior engineers. We encourage continuous improvement and provide access to the latest resources and training in security practices and technologies, ensuring that you stay current with industry trends and threats.

Join Rise to see the full answer
What is the company culture like for Security Engineers at Cape?

The culture at Cape is one of innovation and resilience. We are relentless builders committed to creating meaningful, privacy-centric technology. We trust our team to take on significant responsibilities and drive impactful solutions. As a Security Engineer, you will join a group of talented individuals with diverse backgrounds, including in Defense Tech, who share a common goal of enhancing personal privacy and national security through technology. We prioritize a supportive work environment with excellent benefits, encouraging a healthy work-life balance.

Join Rise to see the full answer
Common Interview Questions for Security Engineer, Product Security
Can you describe your experience with AWS security tools?

During your interview, illustrate specific experiences you have had using AWS security tools such as GuardDuty, IAM, and KMS. Highlight how you have implemented these tools to enhance security measures and share any particular challenges you've faced and resolved while using them.

Join Rise to see the full answer
How do you approach conducting security assessments?

When asked this question, describe your methodology for conducting security assessments. Emphasize the importance of identifying vulnerabilities, assessing risks, and providing actionable recommendations. Discuss any frameworks or tools you utilize to ensure thorough and effective assessments.

Join Rise to see the full answer
How do you integrate security into the DevOps lifecycle?

To address this question, explain your understanding of DevOps and the significance of 'shifting left' to incorporate security early in development. Share specific practices you use to automate security checks and ensure secure coding during application development.

Join Rise to see the full answer
What are the most common security threats affecting cloud environments?

In your response, provide examples of prevalent security threats such as data breaches, misconfigured cloud settings, and insider threats. Explain how you stay informed about these threats and any proactive measures you take to mitigate them.

Join Rise to see the full answer
Can you explain your experience with automation in security tasks?

Highlight your familiarity with automation tools and scripting languages that you have used to streamline security processes. Discuss specific tasks you have automated and the positive outcomes that resulted from this automation.

Join Rise to see the full answer
How do you handle security incidents or breaches?

Share your strategy for responding to security incidents, including detection, containment, eradication, and recovery processes. Emphasize your ability to communicate effectively with stakeholders during an incident and how you follow up with risk assessments post-incident.

Join Rise to see the full answer
Describe how you keep updated with the latest security trends.

In your answer, mention how you rely on various resources such as blogs, industry publications, webinars, and conferences. Discuss any memberships in professional organizations that help you stay current in the ever-evolving field of security.

Join Rise to see the full answer
How do you mentor junior engineers in security practices?

Exemplify your mentoring style by detailing how you support junior engineers through guidance, training, and sharing best practices. Discuss any experiences you have had where your mentorship made a significant impact on their development.

Join Rise to see the full answer
How do you prioritize tasks and manage security risks in a fast-paced environment?

When addressing this question, describe your approach to risk management, highlighting your ability to assess the severity of threats and prioritize tasks accordingly. Mention any tools or frameworks you use for tracking and managing security tasks in a dynamic setting.

Join Rise to see the full answer
Can you give an example of a complex security vulnerability you identified and mitigated?

Use this opportunity to showcase your analytical skills by discussing a specific vulnerability you encountered in the past. Explain your process for identifying it, the steps you took to mitigate the risk, and the lessons learned from the experience.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 5 days ago
Posted 2 days ago
Photo of the Rise User
Vanta Remote No location specified
Posted 4 days ago
Inclusive & Diverse
Growth & Learning
Customer-Centric
Collaboration over Competition
Medical Insurance
Maternity Leave
Flex-Friendly
401K Matching
Photo of the Rise User
Posted 10 days ago
Posted 13 days ago

Our aim is to bring excellence to every customer we support, and continuously look into new ways we can add to and improve on what we provide for our clients. Through our values we will build a better business for the long-term and achieve our o...

11 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
January 11, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!