Cribl does differently. 

What does that mean? It means we are a serious company that doesn’t take itself too seriously; and we’re looking for people who love to get stuff done, and laugh a bit along the way. We’re growing rapidly - looking for collaborative, curious, and motivated team members who are passionate about putting customers first. As a remote-first company we believe in empowering our employees to do their best work, wherever they are. 

As the data engine for IT and Security many of the biggest names in the most demanding industries trust Cribl to solve their most pressing data needs. Ready to do the best work of your career? Join the herd and unlock your opportunity.

Why you’ll love this role:

Cribl Inc is looking for a Product Security Engineer with an AWS security background to join our mission to unlock the value of all machine data. Cribl provides users a new level of observability, intelligence and control over their real-time data. You will join a team of security engineers who are committed to shipping secure software and enjoying all the goat gifs the internet has to offer. This role is remote and you will report into the engineering organization where you will be responsible for both identifying security risks as well as ensuring mitigation across all Cribl products in the Cloud and on premise. The Product Security Engineers in this role will engage with development and operations teams across the Cribl products to enable and drive them to follow secure development best practices, making sure security is built into every product we ship. Our software is deployed in some of the largest organizations in the world processing 100s of TB to PB of IT & Security data.

 

As An Active Member Of Our Team, You Will...

  • Evaluate results from Cribl’s Cloud Security Posture Management (CSPM), perform root cause analysis on AWS misconfigurations, and educate engineering teams on secure AWS patterns
  • Perform application security assessments including AWS architecture review, threat modeling, secure code review, and general security consulting. 
  • Assist and enable product teams to follow secure development practices, while also empowering them to own security within their product area. 
  • Have a proven development background and can communicate with engineering teams with authority, credibility, and empathy. Product Security is complex and context-specific and, as such, will require you to learn constantly and be committed to continuous innovation, because what worked yesterday may not work tomorrow.
  • Consult with development and operations teams to provide guidance and recommend secure design patterns
  • Perform security assessments on new and existing products and services to identify security risks and establish baseline security requirements
  • Establish and drive security standards across Cribl to improve security and resiliency of software and systems architecture

 

If You Got It, We Want It

  • Experience in software development or product security engineering, with additional full-time product or information security experience
  • Proven experience performing security design reviews for complex applications, including distributed systems, APIs, and services deployed to cloud, on-premise, and hybrid environments
  • Expert knowledge and implementation experience across information security disciplines, including web application, network, and operating systems security
  • Fluency with the OWASP Top 10 and other common vulnerabilities and exploit techniques, and ability to define appropriate countermeasures
  • Deep understanding of common application and network protocols, cryptographic technologies, and authentication and authorization protocols
  • Knowledge of compliance requirements for industry-standard certifications like PCI DSS, SOC2, HIPAA, FedRAMP
  • Direct experience supporting cloud operational models, including SaaS security architecture, microservices, containers, and/or Kubernetes
  • BA/BS in computer science, a related discipline, or equivalent work experience

 

Preferred Qualifications

  • Contributions to the security community: research papers, public CVEs, conference talks, open source, etc.
  • Extensive automation and development experience in programming languages such as: C++, JavaScript/TypeScript, Python, Go
  • Familiarity with “big data” and distributed systems technology
  • OSCP or related security credentials

 

#LI-MV1

#LI-Remote

 

Bring Your Whole Self
Diversity drives innovation, enables better decisions to support our customers, and inspires change for the better. We’re building a culture where differences are valued and welcomed, and we work together to bring out the best in each other. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or any other applicable legally protected characteristics in the location in which the candidate is applying.

Interested in joining the Cribl herd? Learn more about the smartest, funniest, most passionate goats you’ll ever meet at cribl.io/about-us

Apply for this Job

* Required
resume chosen  
(File types: pdf, doc, docx, txt, rtf)


Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Cribl’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.


Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.


Enter the verification code sent to to confirm you are not a robot, then submit your application.

This application was flagged as potential bot traffic. To resubmit your application, turn off any VPNs, clear the browser's cache and cookies, or try another browser. If you still can't submit it, contact our support team through the help center.