Senior Product Security Engineer, Secure Design jobs in United States
info-icon
This job has closed.
company-logo

DigitalOcean · 1 day ago

Senior Product Security Engineer, Secure Design

DigitalOcean is a cutting-edge technology company focused on simplifying cloud and AI for builders. They are seeking a Senior Product Security Engineer to assess security risks of new products and features, collaborate with engineering teams, and promote a security culture within the organization.

Cloud ComputingDevOpsSaaSVirtualizationWeb Hosting
check
Growth Opportunities
check
H1B Sponsor Likelynote

Responsibilities

Threat model application designs and solutions and provide security risk assessments (70%) Provide deep technical expertise in software and network architecture during holistic assessments of security layers across infrastructure, application, people, and process
Collaborate with product managers, designers, and engineers to threat model and architect secure and resilient systems
Identify the trade-offs of different solutions and recommend the efficient design to achieve both functional goals and security requirements
Provide hands-on remediation guidance to development teams
Cultivate and promote a security culture (20%) Champion an internal security culture (developer training, internal CTFs, etc.)
Mentor software engineering teams in security best practices
Help oversee our vulnerability management program (we call it security debt)
Help DigitalOcean engineers understand how security events impact them. Do they need to worry about the next Log4j CVE? How does RetBleed impact DigitalOcean’s fleet?
Build security tooling and automations to help scale the Product Security team's practices (10%) Use software architecture and coding patterns to reduce the impact of security issues
Drive architecture, patterns, and processes across engineering that make security the easiest path
Integrate custom security tooling into engineering workflows

Qualification

Threat modelingSecurity risk assessmentSecure architecture designVulnerability managementSoftware architectureContainerizationEmpathyProgramming languagesCommunication skillsMentoringCollaborationCreativity

Required

Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities
Ability to clearly communicate security topics and vulnerability classes (e.g. OWASP Top Ten) and ability to provide actionable direction to product teams
A record of partnering with internal engineering teams to tackle security problems across an entire stack with empathy and creativity. Engineering teams are our partners, not our adversaries
Working knowledge of modern development concepts (virtualized environments, containerization, continuous integration + delivery)

Preferred

3+ years experience guiding software teams on secure architecture design
Experience building or reviewing threat models and ability to craft malicious user, attacker, and abuse/misuse cases
Working knowledge of hardware and software supply chain security
Familiarity with object oriented and functional programming concepts, particularly with languages such as Go, JavaScript, Rust, or C

Benefits

Reimbursement for relevant conferences, training, and education
Access to LinkedIn Learning's 10,000+ courses
Employee Assistance Program
Local Employee Meetups
Flexible time off policy
Bonus in addition to base salary
Equity compensation
Equity grants upon hire
Option to participate in our Employee Stock Purchase Program

Company

DigitalOcean

company-logo
DigitalOcean provides a cloud platform to deploy, manage, and scale applications of any size.

H1B Sponsorship

DigitalOcean has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (30)
2024 (8)
2023 (9)
2022 (22)
2021 (11)
2020 (2)

Funding

Current Stage
Public Company
Total Funding
$1.92B
Key Investors
Global Secure InvestAccess IndustriesKeyBanc Capital Markets
2025-08-12Post Ipo Debt· $625M
2025-05-05Post Ipo Debt· $800M
2021-09-13Post Ipo Equity· $34.91M

Leadership Team

leader-logo
Paddy Srinivasan
Chief Executive Officer
linkedin
leader-logo
Larry D'Angelo
Chief Revenue Officer
linkedin
Company data provided by crunchbase