SlipstreamJobsFresh Startup & VC-Backed Jobs

Product & Application Security Engineer

Veeam Software - San Francisco, CA, United States - In-office - posted 2026-07-31

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Veeam is seeking a Senior Product & Application Security Engineer to embed security throughout the product development lifecycle for Veeam Kasten, a market-leading Kubernetes data protection platform. This role bridges product architecture and software engineering, requiring someone who can think strategically about security design while also coding and fixing vulnerabilities hands-on. You will serve as the primary security voice in design reviews, conducting threat modeling on new features to identify architectural risks before implementation. You'll actively review pull requests and perform deep-dive code audits, manually analyzing logic to find complex flaws that automated tools miss. Unlike traditional security roles that only report bugs, you'll help fix them—triaging findings from tools like Grype, Cycode, and Wiz, then writing production-ready patches to resolve vulnerabilities. Key responsibilities include overseeing the integrity of the build supply chain by ensuring open-source dependencies and build tools are secure, implementing code fixes for security tech-debt across the stack, and conducting threat modeling sessions aligned with two-week sprint cycles. You'll be a subject matter expert on Kubernetes security primitives (RBAC, unprivileged containers, network policies), sharing best practices through workshops, reviews, and documentation. You'll also lead audits, incidents, and compliance reviews, representing the engineering team with the broader security community at Veeam. The role requires strong developer fundamentals in Go and exposure to modern frontend frameworks like Vue.js, extensive hands-on Kubernetes experience, and familiarity with modern AppSec and supply chain tools. You'll balance theoretical security perfection with the practical reality of shipping software frequently. The tech stack includes Go, Vue.js, Docker, Kubernetes, public cloud platforms (Azure/AWS/GCP), and on-premises Kubernetes distributions like OpenShift and Tanzu.

Similar roles