company_logo

Full Time Job

Senior Security Partner - Application Security

Netflix

Los Gatos, CA 03-14-2021
 
  • Paid
  • Full Time
Job Description
Netflix has a unique and creative culture that guides us to operate with ''Freedom and Responsibility''. This helps keep engineering velocity high, but also means that our security team needs to operate differently than a traditional security team. Employees have tremendous freedom in their work, along with the corresponding responsibility to do the right thing for Netflix. Instead of controlling engineers with process and security gates, we enable them to build secure code and provide them with adequate security context to make the right decisions for Netflix.

The Application Security (Appsec) team at Netflix helps secure systems and applications in our cloud infrastructure that run the Netflix business and the streaming product. We aren't your typical Appsec team because we focus our efforts on scalable techniques as opposed to just operational services. The Appsec Partnerships team builds close partnerships with key areas in our engineering ecosystem to identify security leverage opportunities and drive high impact security initiatives (e.g.: Secure by Default in Developer Productivity tools, Secure Application Gateway for all apps). The Appsec Engineering team focuses on building automation for security self-service and vulnerability management to meaningfully reduce security risk.

We are looking for a security engineer to complement the team's existing partnership work with project-based engagements to reduce security risk outside of the core partnership areas. The goal is to help identify impactful security projects and conduct fast discovery and thoughtful solutioning to provide recommendations that improve the security of the Netflix engineering ecosystem. As a part of the team, you will also leverage your security skills to support the Netflix bug bounty program, participate in our product security incident response efforts and other operational Appsec responsibilities.

Desired background:
• You have experience with threat modeling, security design reviews, and architecture.
• You have excellent written and verbal communication skills and are able to translate security objectives to engineering team asks.
• You have experience partnering with cross-functional teams to deliver widely impactful security initiatives.
• You have a breadth of knowledge and experience in application, infrastructure and systems security domains.
• You are a fast learner and have experience partnering with cross-functional teams.
• You demonstrate excellent judgement in prioritizing security efforts to mitigate the appropriate risks.

Finally, here's a few more reasons why we love this work and think that you will too:
• You will have the opportunity to facilitate impactful security work for the Netflix engineering ecosystem.
• You will work with an industry leading security team with many opportunities to reduce risks in existing projects and identify new ones.
• You will have the opportunity to research new ideas and share your ideas across the community.
• You will work closely with domain experts in diverse areas such as microservices architecture, big data, compute platforms and content delivery networks.

We are looking for thoughtful security professionals who enable our mission and support our culture of freedom and responsibility. You can learn more about life at Netflix by watching our security talks or exploring our open source work.

Jobcode: Reference SBJ-gq68j1-18-188-241-82-42 in your application.