Senior Software Engineer (Security Domain)
Job Summary
Join the Security Engineering team as Senior Software Engineer and help secure NetApps flagship storage operating system ONTAP. As a Cybersecurity Development Engineer you will design develop and enhance security capabilities that protect critical customer data across enterprise cloud and AI environments.
You will work on technologies spanning authentication authorization encryption key management secure communications vulnerability mitigation and security hardening. You will collaborate closely with kernel networking cloud storage and product security teams to build secure-by-design solutions while helping ONTAP meet evolving regulatory and customer security requirements.
This role combines deep systems software engineering with modern cybersecurity practices including vulnerability discovery threat modeling secure development incident response support and AI-assisted security analysis.
Design and develop security features including:
- Authentication and authorization
- RBAC and privilege management
- TLS/mTLS and secure communications
- IPsec and secure networking
- PKI and certificate management
- Encryption and key management
- Data-at-rest and data-in-transit protection
- Cryptographic services
- Conduct security architecture reviews threat modeling risk assessments and attack-tree analysis for administrative operations credential paths and role boundaries.
- Translate security findings and threat models into product requirements actionable test plans and automated security tests.
- Investigate vulnerabilities affecting ONTAP and third-party components; assess exploitability and customer impact; and drive remediation validation release readiness and regression test coverage.
- Develop AI-assisted security automation for vulnerability discovery triage detection validation remediation suspicious-behavior investigation and security response.
- Partner with Product Security and PSIRT teams to improve security assessment workflows and respond to customer-reported vulnerabilities security disclosures emerging threats and technical escalations.
- Support compliance and certification programs including FIPS 140-3 Common Criteria NIST security standards and the EU Cyber Resilience Act (CRA).
- Translate regulatory and security requirements into product capabilities engineering controls security evidence and release criteria.
- Participate in customer security reviews and incident response activities.
- Mentor junior engineers and contribute to technical excellence across the organization.
Required Qualifications
- Strong programming skills in C C and Python.
- Solid knowledge of:
- Operating systems
- Computer architecture
- Data structures and algorithms
- Networking fundamentals
- Concurrency and multithreaded programming
- Experience with security assessment methodologies and tools including static and dynamic analysis fuzzing dependency analysis and CVE triage.
- Experience conducting red-team offensive security vulnerability research or security assessment activities on systems or products including documenting findings evaluating risk and providing actionable remediation guidance.
- Proven experience building security automation vulnerability assessment workflows or automated security test frameworks.
- Strong debugging skills using tools such as GDB DTrace packet analyzers and Linux/Unix development tools.
- Experience in one or more of the following areas:
- Authentication and identity management including Kerberos
- TLS/mTLS and IPsec
- PKI cryptography and key management
- OpenSSL OpenSSH and StrongSwan
- FIPS 140-3 and Common Criteria
- Post-Quantum Cryptography
- OWASP MITRE ATT&CK and STRIDE
- Secure Software Development Lifecycle (SDL)
- Storage distributed systems or cloud infrastructure
- Ability to solve complex technical problems independently.
- Proven ability to collaborate across multiple engineering disciplines including systems networking storage cloud and product security teams.
Ideal Candidate
- Security-focused systems engineer passionate about protecting customer data.
- Comfortable working across storage networking operating systems distributed systems and cybersecurity domains.
- Self-motivated curious and driven to solve complex technical challenges.
- Excited to shape the future of ONTAP Security through innovation automation and secure-by-design principles.
- Bachelors degree in Computer Science Computer Engineering Cybersecurity or related field and 5 years of relevant experience; or
- Masters degree and 8 years of relevant experience; or
- Equivalent combination of education and industry experience.
Required Experience:
Senior IC
About Company
At NetApp, our top priority is the health and safety of our event attendees and employees, including every community around the world being impacted by COVID-19. As a result, we have decided to reimagine our annual NetApp INSIGHT Paris and Berlin events to be fully digital. We’re als ... View more