Brain Corp is looking to strengthen the security posture of its robotics platform and cloud services to protect against evolving threats and ensure the security of its systems, including embedded systems, cloud infrastructure, and application development.
Requirements
- Strong understanding of security principles for distributed systems, embedded devices, and cloud platforms.
- Proficiency with Linux security features (SELinux, AppArmor), secure boot, encryption, and cryptographic primitives.
- Experience with CI/CD security, SBOM integration, and secure software supply chains.
- Experience with GCP IAM/RBAC, containerization (Docker, Kubernetes), and network security practices.
- Strong coding skills in languages used across Brain Corp systems (C++, Python, Go, Typescript).
- Experience conducting audits, pen tests, or preparing for external product security reviews.
- Familiarity with SOC1, SOC2, GDPR, ISO27001, SIL2, or UL security/safety standards.
Responsibilities
- Design, implement, and maintain robust security practices across embedded systems, cloud infrastructure, webapps, CI/CD pipelines, and manufacturing workflows.
- Implement privilege separation, secure boot, key management, and authentication mechanisms to strengthen system-level protections.
- Ensure compliance with SOC2 and other customer security and data privacy requirements through audits, documentation, and proactive safeguards.
- Enforce policies for source control, cloud RBAC, data access, and software supply chain security.
- Develop monitoring and alerting systems for data access, network traffic, and cloud resources to quickly detect suspicious activity.
- Deploy tools and processes to detect exploitation attempts, respond to incidents, and minimize impact.
- Provide security insights on design reviews and code reviews, guide developers on secure coding standards, vulnerability remediation, and best practices.
Other
- Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related technical field.
- 5+ years of professional software development experience, with at least 3 years focused on security engineering or applied cybersecurity.
- Ability to communicate complex technical concepts with clarity and precision to diverse audiences, including executives, engineers and non-technical stakeholders
- Excellent communication and documentation abilities, with experience influencing cross-functional teams.
- Applicants must be authorized to work in the United States without current or future sponsorship.