Senior Product Security Engineer

Security United States


Description

Uplight is creating a new category of energy. We make software that manages energy resources in homes and businesses—including things like smart thermostats, electric vehicles, solar panels, storage batteries, heat pumps, and even people’s behavior—to generate, shift, or save energy to balance the grid, making it more efficient and reliable. This creates clean energy capacity that can be used by the power grid instead of burning more fossil fuels. Our solutions accelerate the transition to clean energy and save money for energy customers.  
We are seeking a Senior Product Security Engineer to join our team and help us achieve our ambitious goals for our business and the planet.
How you will make an impact:
  • Support, implement, and improve Secure Software Development Lifecycle (SDLC).
  • Act as a consultant to the design and development stages of SDLC.
  • Document and work with product and engineering teams to implement security best practices and system configuration standards. 
  • Support Asset Management initiatives to ensure all assets are tagged and classified.
  • Work with outside parties to perform penetration tests.
  • Perform Security Architecture, AppSec and Risk Assessments.
  • Perform Threat Modelling.
  • Analyze, manage, and work with other teams to address vulnerabilities, code weaknesses, misconfigurations, and non-compliance findings.
  • Coordinate and participate in Disaster Recovery exercises, including Backup tests.
  • Maintain and administer security tooling.
  • Lead security projects dedicated to improving Uplights's security posture. 
  • Respond to and assist with incidents as needed or assigned. 
  • Implement and be responsible for best product security practices and procedures.
  • Perform an on-call shift rotation.
  • Demonstrate effective communication skills, both verbal and written.
Skills and experience are necessary, but we hire on value alignment first, so if you feel you would be a good fit with us, still consider applying.
What you bring to Uplight:
  • Advanced experience in securing applications and application settings
  • Advanced experience in app and product security
  • Advanced understanding in securing cloud technologies
  • Experience with technologies from at least one public cloud (AWS, GCP, Azure)
  • Experience in securing containerization (Docker, K8s, etc) and API
  • Experience with modern DevSecOps practices including implementing automated security in IaC and CI/CD pipelines
  • Strong scripting skills Python/Shell Scripting experience
  • Mid to advanced level Linux knowledge in a physical, virtual, or public cloud environment.
  • Exceptional verbal and written communication skills are necessary to effectively collaborate with peers, and to present and explain highly technical information to stakeholders who may have limited technical knowledge.
Bonus Points:
  • CISSP, CASP+, GSLC, CISM certified.
Don’t meet every single requirement? Studies have shown that women, marginalized genders and people of color are less likely to apply to jobs unless they meet every single qualification. At Uplight we are dedicated to building a diverse, inclusive and authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles      
      
Why Join Uplight in Leading the Fight Against Climate Change?
At Uplight, we're not just offering a job – we're offering a chance to be part of the solution to one of the world's biggest challenges. As a certified B Corporation, we're deeply committed to both social and environmental responsibility. Here's why you should join our team of passionate Uplighters:
  • Make a Meaningful Impact: Your work directly impacts our mission of decarbonization and building a more sustainable future.
  • Grow Your Career: We offer ample advancement opportunities, robust learning and development programs, and a supportive team environment that fosters collaboration and innovation.
  • Thrive:  We offer comprehensive benefits, including flexible time off, generous parental leave, a wellness stipend, and work flexibility to help you thrive both personally and professionally.
  • Belong to an Inclusive Community: We celebrate diversity and foster an inclusive workplace where everyone feels respected, empowered, and heard. Our Employee Resource Groups offer opportunities to connect with colleagues who share your interests and backgrounds.
  • Be Part of a Growing Movement: Join a team of dedicated individuals who are passionate about creating a more sustainable future. We offer a collaborative environment where your ideas are valued and your contributions
Salary Range: $140,000 to $165,000 + bonus
      
In accordance with the Colorado Equal Pay for Equal Work Act, the approximate annual base compensation range is listed above. The actual offer, reflecting the total compensation package and benefits, will be determined by a number of factors including the applicant's experience, knowledge, skills, and abilities, as well as internal equity among our team.      
      
Uplight provides equal employment opportunities to all employees and applicants and prohibits discrimination and harassment of any type without regard to race (including hair texture and hairstyles), color, religion (including head coverings), age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.