What are the responsibilities and job description for the Staff Product Security Engineer, CartaX position at Carta?
The Team You’ll Work With
You will work with one of the most exciting startup businesses in the world: CartaX. Our mission is to remove restrictions on when and how employee's of pre-IPO companies have access to liquidity.The CartaX team is responsible for building a private stock market from the ground up that allows employees and early investors to trade their shares of pre-IPO companies. CartaX is the world’s first vertically integrated financial marketplace for private assets and we’ve just started. The CartaX team is composed of experts in building and operating marketplaces and brokerages, as well as a diverse set of team members with backgrounds in capital markets and SaaS platforms.
The security team is responsible for building security policies for a greenfield marketplace that operates in a heavily regulated environment. The security team ensures the confidentiality, integrity, and availability of CartaX’s systems and data. You get to work in an environment that uses infrastructure-as-code, Kubernetes, role-based access, and with engineers who care about the integrity and security of our data and products.
The Problems You’ll Solve
With the power to change the product, the pipeline, and our developers on-boarding, you’ll be able to help us design and evolve our product security program. We are the partners of engineering and SRE and need curious minds to help us keep paving the way.
Some of the problems you’ll help us solve are:
- How do you build a program that ties application security, container security, and cloud security together instead of treating them as separate specialities?
- How do we change the application framework to make security the easiest path?
- What techniques and games will enable development teams to threat model their products?
- What tools and information can we provide to ensure developers can effectively peer review code themselves?
- How do you encourage developers to continuously think about security using gamification and giving them results where they live - in the pipeline?
About You
You have demonstrated experience in finding non-standard ways to solve interesting problems. You speak to risks around application, container, or cloud security vulnerabilities, remediations, and preventions. You have strong understanding of Threat Modeling and general software development practices, the associated risks, and the components of a modern product security program. Experience with creating automation in higher level scripting language (Python, Ruby, Javascript, etc), bonus points for using AWS Lambda. Experience securing products built using containerization (specifically, Docker and Kubernetes)
Most importantly you're excited to work on a product that will fundamentally change the way private companies view liquidity, going public and how employees exercise their options.