Senior Site Reliability Engineer, Security

Remote·Posted today
saasinfrastructurelogisticskubernetesawsgcpterraform
About AuthZed: We are the creators and maintainers of SpiceDB and the authorization infrastructure that companies around the world depend on to keep their engineering teams focused on what matters most - their own product. We are a Series A company, fixing broken access control with products that eliminate complex permission management while delivering enterprise-scale performance and consistent access control. AuthZed is a fully remote company with employees across the US, Canada, and Europe. We’re a hardworking and close-knit group with a software-driven culture (yep, even our GTM team understands and loves this technology)! We bring integrity to all our interactions, fostering confidence in decision making - trusting and respecting each voice on our team, every day. Company Values: Agency: Everyone should have the capability, freedom, and confidence to bring about changes to our business and product. Organizational processes exist to clearly define our goals, but not restrict how progress is made. Collaboration: Success is defined in various dimensions and no single person can be an expert in all of them. Without valuing the opinions of others, finding compromises, and sharing mutual trust and respect, you cannot arrive at the best possible solution. Open-mindedness: Without asking questions, testing assumptions, and questioning our pre-existing biases we risk operating within an echo-chamber. We celebrate the representation of diverse perspectives and backgrounds as a catalyst for creating an inclusive work environment that everyone can appreciate. About the Role: This is an engineering role at the intersection of site reliability, cloud infrastructure, distributed systems, and security . You’ll help operate our production platform while bringing deep security expertise to how we design infrastructure, deploy software, manage access, detect threats, and respond to incidents. As a senior engineer on a small team, you’ll have significant ownership and influence. You’ll work across engineering to make security scalable: building automation, secure defaults, and platform-level guardrails that allow engineers to move quickly while maintaining the level of security expected from critical authorization infrastructure. What you’ll do: Operate AuthZed's production infrastructure. Build, operate, and evolve the Kubernetes and cloud infrastructure that powers our managed services, with a focus on availability, scalability, performance, and security. Advance our infrastructure security. Help evolve our approach to Kubernetes, cloud infrastructure, networking, IAM, secrets management, encryption, and service-to-service communication as our platform and customer base grow. Secure the software supply chain. Continue strengthening security throughout the path from source code to production, including CI/CD, dependencies, container images, build artifacts, provenance, vulnerability scanning, and deployment controls. Build security into the platform. Develop automated guardrails, policies, and secure defaults that make strong security practices part of the engineering platform rather than an additional manual process. Evolve vulnerability management. Help us continuously improve how we identify, prioritize, and address vulnerabilities across containers, dependencies, infrastructure, and cloud services based on exposure and risk. Improve detection and response. Expand security telemetry, logging, alerting, and detection capabilities and help develop and exercise security incident-response playbooks. Respond to incidents. Participate in the SRE on-call rotation, lead or contribute to production incidents, and help continuously improve our operational practices. Partner with engineering. Collaborate on architecture and infrastructure design, contribute to threat modeling, and help teams make strong security decisions early in the engineering lifecycle. Help shape our security engineering strategy. Bring technical security expertise to engineering priorities, architecture decisions, customer security requirements, and the continued evolution of AuthZed's security posture. What you bring: Significant experience operating production systems as a Site Reliability Engineer, Platform Engineer, Infrastructure Engineer, or Security Engineer . Deep hands-on experience with Kubernetes and containerized production environments. Strong experience with at least one major cloud provider (AWS, GCP, Azure) and its security model. Strong understanding of IAM, workload identity, networking, TLS/PKI, encryption, secrets management, and cloud-native security. Experience with Infrastructure as Code; we use Pulumi, but experience with equivalent tooling such as Terraform or AWS CDK is welcome Experience designing, operating, and securing CI/CD and software delivery pipelines. Strong understanding of Linux and container security fundamentals. Experience with observability, monitoring, logging, and production incident response. Strong software engineering skills and an inclination to solve operational and security challenges through automation. Strong security judgment and the ability to evaluate risk in the context of real-world distributed systems. Ability to operate independently, drive projects across engineering boundaries, and provide technical leadership in a small, highly technical organization. Extra shine: Experience operating distributed databases or other stateful distributed systems in production. Experience securing multi-tenant SaaS or cloud infrastructure. Experience contributing to security architecture, threat modeling, penetration testing, or security assessments. Relevant certifications such as Certified Kubernetes Administrator (CKA), Certified Kubernetes Security Specialist (CKS), AWS Certified Security – Specialty, Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP) Life at AuthZed: Opportunity to work with cutting-edge technology in a rapidly growing sector. A supported environment where your ideas lead to real impact. Competitive salary based on experience and location Stock options at an early-stage startup. Comprehensive benefits including healthcare (US-based) and other insurance. A full remote and flexible schedule to accommodate different time zones Twice-yearly travel for team off-sites focused on team bonding, collaboration, and having fun!