Principal SecDevOps Engineer

Procore Technologies

Principal SecDevOps Engineer

austin, TX
Full Time
Paid
  • Responsibilities

    Job Description

    What if you could use your technology skills to develop a product that impacts the way communities’ hospitals, homes, sports stadiums, and schools across the world are built? Construction impacts the lives of nearly everyone in the world, and yet it’s also one of the world’s least digitized industries, not to mention one of the most dangerous. That’s why we’re looking for a Principal Security Engineer to join Procore’s journey to revolutionize a historically underserved industry.

    As a Principal Security Engineer , you’ll be a key member of the CyberSecurity Platform Security Engineering Department. You’ll also work internally to understand the Procore Application & supporting infrastructure. This role requires a strong background in security as it relates to platform infrastructure, application security, and other aspects of network/cloud infrastructure security. If you’re interested in becoming a foundational member of the Procore security team, setting the course for security within Procore for years to come—we’d like to hear from you.

    This position will report to our Director of Security Engineering, Platform Security and has the opportunity to be based in our Austin, TX Office location. Remote candidates will be considered with experience. We’re looking for someone to join us immediately.

    What you’ll do:

    • Apply suitable design patterns to manage the privacy and security of customer data within our production environment

    • Understand the security and general architectural vision of Procore 2.0

    • Be a technical security mentor for the Security Engineering team, as well as an influencer of the Cloud Runtime Engineering team

    • Work closely with Security Architecture, Product, Cloud Runtime Engineering, and Legal

    • Work across Terraform, Ruby on Rails, Apache, Nginx, Snowflake, data Analytics, PostgreSQL, AWS tech stacks

    What we are looking for:

    • BS degree in Computer Science, a similar technical field of study, or equivalent practical experience is required; MS or Ph.D. degree in Computer Science or a related field is preferred

    • 8+ years of experience in Software Engineering with at least 5 years of experience building security products and internal security tools

    • Experience with conducting threat assessments and building threat models

    • Differential Privacy techniques as they apply to access to sensitive data, anonymization and sharing

    • Thorough understanding of vulnerability classes (OWASP), how they can be exploited

    • Knowledge of cryptography, including symmetric and asymmetric ciphers, hash functions, PKI, and certificates. Application of cryptography to software engineering problems, such as secrets management, authentication, and data masking, and tokenization.

    • Understanding of open standards such as OAuth2, OIDC, SAML, and TLS

    • Familiarity of data privacy laws such as GDPR and CCPA and related data security requirements

    • Deep background and experience in:

      • AWS services (EC2, ELB, RDS, KMS, Cloudfront, Secrets Manager, Route53, S3, Lambda) and orchestration tools

      • IAM implementation

      • Linux Systems

      • Hashicorp Technologies (Consul, Terraform, Vault, Packer)

      • Containers (Docker, Kubernetes) and Container Management (Istio, EKS,Secrets management)

      • Config Management (Puppet, Ansible, Salt)

      • Endpoint host protection technologies (Prismacloud,Crowdstrike,Falco)

      • WAF technologies (Cloudflare)

      • Security Observability and analytics (ELK, Elastic)

      • Networking protocol knowledge (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols)

    • Basic project management skills, experience creating application documentation, and demonstrated ability to train other team members

    • Experience creating engineering as-built diagrams and data flow diagrams to describe engineered product

    • Technical Certifications are a plus (GIAC, OCSP, CISSP, AWS Security Specialty, Solutions Architect, etc)

  • Qualifications

    Additional Information

    Base Pay Range $185,800 - $255,475. Eligible for Bonus Incentive Compensation. Procore is committed to offering competitive, fair, and commensurate compensation, and has provided an estimated pay range for this role. Actual compensation will be based on a candidate’s job-related skills, experience, education or training, and location.

    Perks & Benefits

    At Procore, we invest in our employees and provide a full range of benefits and perks to help you grow and thrive. From generous paid time off and healthcare coverage to career enrichment and development programs, learn more details about what we offer and how we empower you to be your best.

    About Us

    Procore Technologies is building the software that builds the world. We provide cloud-based construction management software that helps clients more efficiently build skyscrapers, hospitals, retail centers, airports, housing complexes, and more. At Procore, we have worked hard to create and maintain a culture where you can own your work and are encouraged and given resources to try new ideas. Check us out on Glassdoor to see what others are saying about working at Procore.

    We are an equal-opportunity employer and welcome builders of all backgrounds. We thrive in a diverse, dynamic, and inclusive environment. We do not tolerate discrimination against employees on the basis of age, color, disability, gender, gender identity or expression, marital status, national origin, political affiliation, race, religion, sexual orientation, veteran status, or any other classification protected by law.

    If you'd like to stay in touch and be the first to hear about new roles at Procore, join our Talent Community.

    For Los Angeles County (unincorporated) Candidates:

    Procore will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable federal, state, and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act.

    A criminal history may have a direct, adverse, and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment: 1. appropriately managing, accessing, and handling confidential information including proprietary and trade secret information, as well as accessing Procore's information technology systems and platforms; 2. interacting with and occasionally having unsupervised contact with internal/external customers, stakeholders, and/or colleagues; and 3. exercising sound judgment.

  • Industry
    Other