> Markdown version of [/jobs/ext/629175-telecommute-lead-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/629175-telecommute-lead-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # TELECOMMUTE Lead Product Security Engineer - **Company:** AALYRIA TECHNOLOGIES, INC. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Bash Shell, Computer Networks, Computer Engineering, Continuous Integration, Software Design Documents, Firmware, Hardware Security Module, Identity and Access Management, Python (Programming Language), Key Management, Public Key Infrastructure, Systems Development Life Cycle, Software Vulnerability Management, Cloud Platform System, Software Security, Amazon Virtual Private Cloud (VPC), Gitlab, Kubernetes, U-Boot, Software Coding, Terraform, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** June 24, 2026 - **Apply:** https://www.dice.com/job-detail/abc45e4b-68c4-47ae-9de9-387272ebb432 ## About the Role * Senior- or staff-level hands-on experience in product security or security engineering, with significant depth in software/AppSec. * Production experience securing cloud environments such as IAM, org policy, VPC Service Controls, KMS, and Kubernetes at depth. * Strong cryptographic foundations, PKI architecture, key management, signing, mTLS, and secrets handling at scale. * Hands-on coding ability in Python, Bash, and Go, you can write tooling, automate controls, and ship Terraform/scripts when the situation calls for it. Comfort reviewing code is a plus. * A track record of building security programs, not just operating tools someone else stood up. * Experience leading product incident response, triage, response, coordination with engineering teams, customer comms, and post-mortem ownership. * A pattern of mentoring engineers and raising the security bar of teams around you, even without direct reports. * Experience interfacing with hardware/firmware teams, even if hardware isn't your primary domain. * Strong written communication, you'll write threat models, design docs, and program updates that go to the executives, customers, and assessors. * Working knowledge of the compliance frameworks that govern our environment such as CMMC, FedRAMP, and DFARS along with the ability to translate controls into engineering work. Preferred Qualifications: * Hands on experience with NIST 800-53, NIST 800-171, or DoD SRG environments. * Experience with government-cloud platforms. * Hardware security depth in HSMs, TPMs, secure elements, supply-chain attestation. * Embedded / firmware security background, secure boot, RoT, OTA update integrity, hands-on firmware review. * Experience standing up or running a vulnerability disclosure program or bug bounty, triage, researcher comms, and CVE coordination., * U.S. citizen or national * U.S. lawful permanent resident () * Refugee under 8 U.S.C. 1157 * Asylee under 8 U.S.C. 1158 (B) Be eligible to access export-controlled information without requiring an export authorization. (C) Be eligible and reasonably likely to obtain the necessary export authorization from the appropriate U.S. government agency. ## Description You'll be the technical voice of product security across Aalyria, reporting to the Director of Security & IT. You'll own application security, CI/CD and supply-chain security, our Kubernetes-based product infrastructure, product-side authentication and PKI, and you'll partner closely with hardware engineering on Tightbeam., * Application & software security. SAST/DAST/SCA, secure SDLC, threat modeling, and software vulnerability management across our codebase. * CI/CD and supply-chain security. Hardening our GitLab pipelines, build provenance, dependency integrity, signing, and SLSA-aligned controls. * Product infrastructure security. GKE and Kubernetes hardening, container security, workload identity, network policy, and runtime protection. * Product PKI. Certificate lifecycle, issuance, rotation, and mTLS architecture across distributed services and remote assets. * Vulnerability management. Triage, prioritization, remediation tracking, and exception handling, for both disclosed upstream issues and internal findings. * Product incident response. Leading triage and response for product-side security incidents, coordinating with corporate IR, and driving post-mortems to action. * Product infra hardening. Baseline configurations, secure defaults, and compensating controls across product environments. * Hardware security partnership. Working with the Tightbeam team on firmware security, secure boot, key storage, and hardware supply-chain integrity. ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Retooling and refactoring - an investment in people.](https://www.wearedevelopers.com/videos/371-retooling-and-refactoring-an-investment-in-people) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)