xelys jobs xelys jobs

Senior Application Security Engineer

vCluster

full-remoteseniorpermanentsecuritybackend United States 4 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Application SecurityProduct SecurityKubernetes SecurityRBACThreat ModelingCI/CD SecurityVulnerability ManagementGoMulti-tenancySecure Coding

About the role

Role Overview

As a Senior Application Security Engineer at vCluster Labs, you will architect and own end-to-end application security for a Kubernetes multi-tenancy platform. The goal is to make vCluster the de facto standard for secure Kubernetes multi-tenancy, enabling high-privileged workloads without fear.

Responsibilities

  • Core Product Security
    • Conduct deep-dive security reviews of Go-based applications, Kubernetes controllers, and the frontend UI.
    • Focus on preventing privilege escalation in a multi-tenant architecture.
  • Threat Modeling
    • Lead threat modeling for new features.
    • Identify risks related to shared GPU resources and multi-cloud environments.
  • Automated Security (“Shift Left”)
    • Integrate security checks into CI and developer workflows.
    • Optimize checks for speed so security doesn’t bottleneck engineering velocity.
    • Manage automated and manual scanning across the product stack.
  • Vulnerability Management
    • Own the full lifecycle of vulnerabilities: discovery → triage → remediation.
    • Drive resolution of critical issues across engineering and communicate with stakeholders.
  • Security-Driven Feature Development
    • Collaborate on new features, including security-related work like container breakout prevention and isolation.
  • Developer Training & Enablement
    • Educate engineers on secure coding and emerging attack vectors.

Requirements

  • 5+ years in Application Security or Product Security, with strong focus on containerized environments.
  • Deep understanding of Kubernetes architecture, RBAC, and container runtime security.
  • Strong grasp of multi-tenancy security risks.
  • Proficiency reading and writing Go; able to spot vulnerabilities in PRs.
  • Thrives in fast-paced, cutting-edge environments.
  • Strong “cognitive flexibility” and ability to learn from feedback.

Bonus / Nice-to-Haves

  • Certifications: CKS (Certified Kubernetes Security Specialist) or OSCP.
  • Experience securing AI workloads or GPU cloud infrastructure.
  • Experience building security automation tooling/scripts in Python or Go.
  • Contribute to public security documentation and the Trust Center.

About vCluster

vCluster Labs is a venture-backed tech startup pioneering Kubernetes virtualization for the AI era. The company operates a platform for running and virtualizing GPU infrastructure, helping AI cloud providers deliver a hyperscaler-like experience for their customers.

Scraped 8/2/2026