Head of Security
4 months ago
Job type: Full-time
Hiring from: Anywhere
Category: DevOps / Sysadmin
Balena is a highly distributed company that has embraced a remote-first approach since 2013. We are a group of individuals from across the globe working together to achieve our mission: “reduce friction for fleet owners and unlock the power of physical computing”. For us, this means removing the barriers to entry for developing IoT products, whether that’s easing software deployments with balenaCloud, simplifying image flashing with balenaEtcher, or offering our own hardware based on our experience seeing thousands of devices running in production environments. We're engineering a complete, end-to-end solution that makes it easy for any developer to build applications at the Edge.
- We place trust and autonomy in our team to own the outcome of their work.
- We practice radical candor and transparency with open, honest, and clear communications.
- We embrace first-principles thinking and constantly challenge our assumptions.
- We organize ourselves based on the best use of our collective abilities to solve our highest priority problems at any given time, rather than by a strict hierarchy.
- We’re not afraid to fail as long as we learn from our mistakes.
- We’re always looking for common patterns that allow us to reduce complexity.
- We embrace short term pain for long term gain, building products that will stand the test of time.
Our users trust us to provide critical infrastructure for their distributed IoT fleets, and our engineers work hard to protect each of these devices from attacks. Our “security stack” spans from the bootloader and OS on-device, to the network and security infrastructure of our backend, to the operational security of our team.
As a Head of Security, you will learn how our complex interdependent systems are built and run. You will dig deep into diagnostics & debugging surfaces, logs, and reports to identify areas of risk and strategies to minimize vulnerabilities. You will develop and deploy security controls and concepts stretching from cloud- based apps to systems running on embedded devices, and lead initiatives to create new frameworks and roadmaps. You will influence infrastructure and product decisions and, above all, establish and promote a culture of shared responsibility for security.
- Analyze weaknesses and attack patterns, and architect solutions to address them
- Construct a comprehensive threat model that includes a variety of actors and security contexts
- Define standards and streamline workflows for managing incidents, recovery, and vulnerability reports
- Implement, tune, and enhance security auditing, monitoring, and notification systems
- Perform checks to ensure our production pipeline is secure — from developer machines to servers
- Design and review security related product features, like automated vulnerability scanning and audit logs
- Be a key resource for peers on support, share knowledge and mentor others on best practices
- Strong technical background in software development, operations and/or information security
- Experience writing high-quality code and debugging production systems
- Working knowledge of Linux operating system internals
- Awareness of classic and emerging threat actor tactics, techniques, and procedures in both pre- and post-exploitation phases of attack lifecycles
- Ability to manage ambiguity, push through friction, and independently make critical trade-off decisions
- Continuous improvement mindset and desire to make yourself and others more effective
- Willingness to constantly build on your knowledge of the balena platform and new technologies
- Excellent communication skills and fluency in English
- Knowledge of state of the art authentication standards such as OIDC
- Good understanding of networking (TCP/IP) and higher-level HTTP & TLS protocols
- Background in leading teams and working across functions to build secure products
- Experience with IoT, embedded SW, dev tools, or balena as a user/contributor
- Contributions to OSS projects and community involvement
Make sure to let us know if any of these items apply to you! If possible, please also share a sample of your work or examples of projects (URL or attachment).
- Work with a talented and globally distributed team
- Equipment of your choice
- Flexible working hours
- Flexible vacation policy
- Annual company gathering in an international location
- We send you hardware for side projects!
Before you apply, please check if any restrictions apply in terms of time zone or country.
This job has a geo-restriction in place: Anywhere.
Please mention that you come from Remotive when applying for this job.
Does this job need an edit? 🙈