Sr. Cloud & Mobile Security Engineer

iRobot
Bedford, United States
3 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$107,000.0 - $152,500.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access JavaScript (Programming Language) Artificial Intelligence Amazon Web Services Apple IOS Software System Penetration Testing Authentication Protocols Automation of Tests Cloud Computing Identity and Access Management Mobile Application Software Python (Programming Language)
+15 more
Node.Js OAuth Open Web Application Security Role-Based Access Control Cloud Services Red Team (Cyber Security) Single Sign-On Software Security Build Management AI Platforms Integration Tests Api Design Serverless Computing Static Application Security Testing Dynamic Application Security Testing

Job description

iRobot is in immediate need of a Senior Engineer on its Product Security team who is experienced in applying security best practices and principles to the design, development, and maintenance of AWS Managed Service architecture, and to the mobile applications written for the most common platforms and languages. iRobot leads the market in consumer robotics and enabling the smart home, and the cloud infrastructure underpins its millions of connected robots, while the mobile application connects our millions of customers to their robot devices.

The responsibilities will require a mix of partnering with development teams to assess new designs for potential security issues, and designing and building centralized security services, test frameworks, and integrated testing tools for use in automated build pipelines.

What You Will Do:

  • Assess new cloud designs and mobile app feature changes for potential security vulnerabilities.
  • Evaluate production and test builds of cloud services and mobile applications for adherence to security best practices.
  • Develop guidelines for security of products based on industry standards.
  • Triage reported vulnerabilities from the field across a spectrum of sources and determine impact, priority, and risk.
  • Design and build secure cloud services that centralize critical security functionality.
  • Implement test frameworks for automated security validation testing of cloud and mobile deployments.
  • Work with the latest SAST/DAST tooling, AI-powered and traditional, to evaluate and report on flaws and vulnerabilities to the development teams.
  • Ensure the components meet the regulatory needs of every market within which iRobot products are sold.
  • Engage third-party and AI services for penetration testing, red team exercises, threat modeling, and more.

Requirements

  • 7+ years designing, building, and deploying AWS-based managed service infrastructure, with at least 2 years as a security champion within a development team
  • Extensive knowledge and practical experience designing, building and deploying secure serverless, API-based services with a deep understanding of the standard callflow of managed service architecture: Gateway to Work Process to Storage to Access
  • Deep knowledge of authentication protocols and technologies, including IAM, SSO, OAuth 2.0, and RBAC
  • Experience building mobile apps for iOS and Android, with a deep understanding of the security best practices of each
  • Understanding of, and alignment with, OWASP standards and best practices, including the OWASP Top Ten lists
  • Strong understanding of AWS policy hierarchy, and practical knowledge of Organizations, SCPs, IAM, et al
  • Python and Node/ JavaScript proficiency
  • Practical experience constructing architecture risk assessments and leveraging standard security tooling to build empirical evidence in support of those assessments
  • Preferred: experience at a consumer product company

Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or assume sponsorship of any additional employment visas at this time.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

45 sec

Working securely with Node.js path application programming interfaces

Sonya Moisset · World Congress 2023

2:25 min

Testing the AI generated Apple iOS Flashcards application

MIlan Todorović MIlan Todorović · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:14 min

Exploring internal AI product initiatives and global engineering roles

Maria Apazoglou · Coffee With Developers

Videos

See all

Related articles

See all