SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
vCluster Labs is seeking a Senior Software Engineer focused on Product Security to build secure infrastructure software from the ground up. You will design, build, and maintain production features alongside the engineering team while bringing a security perspective to the broader product through security-sensitive design reviews, threat modeling, vulnerability investigation, and guidance on security decisions as the platform evolves.
Key responsibilities include:
- Building production features: Design, build, and maintain production features with the engineering team. When security work is not in the queue, you contribute to roadmap features.
- Owning vulnerability response: Triage, prioritize, and fix security issues in code and dependencies through to patched release.
- Threat modeling: Review security-sensitive designs early, identify risks, and help teams make sound security decisions as the platform evolves.
- Code and design reviews: Participate in code reviews, design reviews, and technical discussions with the engineering team.
- Improving security practices: Help engineers build secure defaults into the product.
About vCluster Labs: The company is the #1 platform for AI infrastructure, trusted by the world's fastest-growing AI cloud builders. A venture-backed startup that has raised over $28M from top-tier investors including Khosla Ventures, the company is in hyper-growth phase. Headquarters are in San Francisco (Salesforce Tower), with a distributed, remote-first team. The company powers over 100,000 GPUs and 1 million CPUs across 50+ AI clouds and Fortune 500 companies, backed by 40+ infrastructure engineers. vCluster Labs is the company behind vCluster, open source technology for tenant isolation on Kubernetes with 11,000+ GitHub stars and 40M+ tenant clusters created since 2021. At KubeCon North America 2025, the company launched its Infrastructure Tenancy Platform for AI, a Kubernetes-native framework for running AI, ML, and GPU-intensive workloads anywhere.
Requirements:
- Production engineering in Go: Experience building and shipping production systems with Go as a primary language.
- Kubernetes internals depth: Working knowledge of the API server, admission control, RBAC, controllers, and the kubelet, ideally from building controllers or operators with controller-runtime, Kubebuilder, or client-go.
- Kubernetes attack surface knowledge: Hands-on experience with container breakout, privilege escalation, RBAC, and policy best practices.
- Threat modeling and secure design: Experience threat modeling and reviewing designs for production systems, and explaining risk clearly to other engineers.
- Vulnerability ownership: Experience investigating and fixing vulnerabilities in code you work on, including the CVE lifecycle, coordinated disclosure, and patch releases.
Bonus qualifications:
- CKS certification: Certified Kubernetes Security Specialist.
- Startup experience: Experience at an early-stage organization where you function autonomously and strive towards building something great.