Secure Runpod's platform by ensuring software is secure by design.
•Runpod is seeking a Full Stack Security Engineer to secure our customer-facing products, APIs, and internal services.
•Key Responsibilities Lead threat modeling, architecture reviews, and code reviews for our web applications, APIs, and microservices.
•Actively develop and commit code to fix security flaws in our Python, Go, or JavaScript/TypeScript codebases.
•Implement, tune, and manage security testing tools (SAST, DAST, SCA) within our CI/CD pipelines.
•Configure and manage application-layer security controls, including Web Application Firewalls (WAF), bot protection, and API gateways.
•Provide security guidance, secure coding training, and standard operating procedures to development teams.
•Requirements 5+ years of experience in application security, product security, or as a software engineer with a heavy security focus.
•Strong programming and code-review skills in languages like Python, Go, JavaScript/TypeScript.
•Deep understanding of web application vulnerabilities (OWASP Top 10), API security (REST/GraphQL), and modern authentication flows (OAuth, OIDC, JWT).
•Hands-on experience with offensive web security testing tools (e.g., Burp Suite, ZAP).
•Experience building and maintaining automated security pipelines (DevSecOps).
•Ability to translate complex security risks into actionable engineering tasks.