Senior Product Security Engineer, MongoDB

Detection & Response

$118-231k

Salary is benchmarked on US rates and may vary by other locations

MongoDB
AWS
Docker
Kubernetes
GCP
JavaScript
Python
Java
Linux
Azure
Golang
Senior and Expert level
Remote in Canada, US
New York
MongoDB

Developer data platform

Open for applications

MongoDB

Developer data platform

1001+ employees

B2BEnterpriseBig dataCloud Computing

Open for applications

$118-231k

Salary is benchmarked on US rates and may vary by other locations

MongoDB
AWS
Docker
Kubernetes
GCP
JavaScript
Python
Java
Linux
Azure
Golang
Senior and Expert level
Remote in Canada, US
New York

1001+ employees

B2BEnterpriseBig dataCloud Computing

Company mission

To empower innovators to create, transform, and disrupt industries by unleashing the power of software and data.

Role

Who you are

  • With a strong security engineering background, you’re looking for a role that gives you the freedom to increase MongoDB’s resonance with customers by strengthening our products
  • You’re passionate about building a security program that puts a heavy emphasis on customer and engineer experience, leveraging your own extensive experience
  • You enjoy collaborating with different teams to innovate and implement pragmatic solutions
  • 7 years of experience in security incident detection and response engineering or similar role
  • Broad knowledge across the Security disciplines. Deep focus in one or more core product security concerns such as software security, cloud (AWS, GCP, or Azure), or Platforms (Linux, Containers, Supporting services)
  • Can plan and develop code for security team tooling. Can collaborate with engineering teams on code and architecture for our production services
  • Able to Communicate complex technical issues in a simple manner that builds trust with a variety of audiences
  • A strong sense of ownership and delivery
  • Can facilitate a conversation rather than dominate it
  • Can lead post-incident analysis and facilitate postmortems

Desirable

  • Knowledge of one or more core project languages (Golang, Java, Javascript, Python)
  • Docker and Kubernetes operation and security
  • Working knowledge of one or more major cloud providers (AWS, GCP, or Azure)
  • Experience with large scale environments

What the job involves

  • The MongoDB Product Security organization is a diverse collection of individuals working together to scale MongoDB’s security, both security of the products themselves and the security features we offer to customers
  • The team is responsible for several products including MongoDB Atlas Cloud, Ops Manager, Kubernetes Operator, and the MongoDB Server (Community and Enterprise editions)
  • The MongoDB Product Security organization works with software engineers to design, implement, and operate systems in a manner that protects customer data
  • It is a multidisciplinary team that covers product, software, cloud, infrastructure, detection/response, and operational security concerns
  • Builds an engineering driven security program where there is tight integration with engineering artifacts, process, and tooling. Applies sound engineering to the practice of security
  • Proactively leverages software architecture, coding patterns, security capabilities built into our products to reduce the impact of security issues
  • Acts as security subject matter experts for our tech stack and products
  • You will take ownership, define strategy, and drive improvement of our product detection and response program. This team is primarily focused on D&R engineering for the Atlas suite of products and supporting supply chain
  • Advocate for and lead complex security projects from inception through completion
  • Build frameworks and services that enable engineering teams to build and own detection capability for their products. Be a security subject matter expert and a trusted partner for those teams
  • Integrate with our engineering processes like architecture review to drive new telemetry, detections, or containment as part of feature development
  • Research and drive architecture, patterns, and processes across engineering that make unexpected behavior obvious and traceable. Build in context so that response workflows can be scaled and automated
  • Partner closely with engineering teams to design and build new capability throughout our technology stack
  • Research and monitor the threat landscape and facilitate feedback loops back in to security and engineering
  • Design and implement attack testing automation to validate detection coverage
  • Lead cross-team incident investigations and manage the IR process
  • Success in this role means
  • Taking ownership of one or more security programs such as application security, cloud security, or incident detection and response
  • Seeing projects through from conception to completion in order to deliver new services or capabilities for the team
  • Partnering with and collaborating with other engineering teams
  • Establishing yourself as a go-to person for discussing security topics

Our take

MongoDB is an open-source, cross-platform, document-oriented database system. It stores data as JSON-like documents and is written in C++, Go, JavaScript and Python.

Essentially, the company develops tools and blueprints to help businesses and organisations modernise their legacy applications, migrating them to the MongoDB database and the MongoDB Atlas cloud database. With this initiative, MongoDB is particularly taking aim at Oracle customers with ageing applications running on the Oracle relational database system.

Since its release, MongoDB has become one of the most popularly used NoSQL database systems due to its ease of use and efficiency. It is also the fastest-growing database ecosystem, and boasts hundreds of millions of downloads. Recently, the company announced a partnership with Patronus AI, an automated evaluation and security platform, through which it will bring automated LLM evaluation and testing capabilities to enterprise customers.

Freddie headshot

Freddie

Company Specialist

Insights

Top investors

Some candidates hear
back within 2 weeks

13% employee growth in 12 months

Company

Funding (last 2 of 8 rounds)

Jan 2015

$80m

SERIES G

Oct 2013

$150m

SERIES F

Total funding: $311.1m

Company benefits

  • Rich health insurance coverage
  • Virtual & on-site fitness classes
  • Health screenings & telemedicine
  • Access to transgender-inclusive health insurance coverage
  • Global and internal mobility opportunities
  • Equity & Employee Stock Purchase Program
  • Pension & retirement programs
  • Income Protection
  • Flexible PTO is offered to every US employee & competitive time off policies for non-US employees
  • Employee Assistance Program
  • Mental health counseling
  • Free meditation app access
  • Fertility & adoption financial assistance
  • Parental counseling for new parents
  • 20 weeks of fully paid gender neutral parental leave & flexible work arrangements
  • 4 weeks of emergency care leave

Company values

  • Think Big, Go Far
  • Build Together
  • Embrace the Power of Differences
  • Be Intellectually Honest
  • Own What You Do
  • Make it Matter

Company HQ

Theater District, New York, NY

Leadership

Dwight Merriman

(Co-Founder)

Previously CTO and Co-founder at DoubleClick for 10 years, and Chairman at AlleyCorp for 15 years.

Salary benchmarks

We don't have enough data yet to provide salary benchmarks for this role.

Submit your salary to help other candidates with crowdsourced salary estimates.

Share this job

View 161 more jobs at MongoDB