Product Security Engineer (GRC)
Red Hat, Inc.
Remote
About the Job:
At Red Hat, we connect an innovative community of customers, partners, and contributors to deliver an open source stack of trusted, high-performing solutions. We offer cloud, Linux, middleware, storage, and virtualization technologies, together with award-winning global customer support, consulting, and implementation services. Red Hat is a rapidly growing company supporting more than 90% of Fortune 500 companies.
The team is growing and we have a big vision particularly as it relates to increasingly complex compliance standards and burgeoning digital sovereignty laws worldwide. The Red Hat Product Security Compliance team is seeking a proactive Product Security Engineer to achieve our security and compliance objectives.
Red Hat embraces a remote working culture and promotes work flexibility. This team, and many of the people you would work with, are remote and you would be welcome to work from home as well.
What will you do?
-
Responsible for the security and compliance of systems related to our Government Certifications program, to include FIPS, Common Criteria, ITSAR, etc.
-
Comfortable leading technical discussions across multi-functional engineering teams and third party auditors.
-
Support the continuous improvement of the Red Hat environments through automation and maturation of processes.
-
Support the downstream integration of open-sourced projects; collaborate to develop and implement Red Hat specific capabilities from the upstream.
-
Research and analyze new tools, technologies and services for technical suitability within a containerized environment.
-
Serve as an evangelist of security and compliance both inside Red Hat and externally, with partners or within the open-source community.
What will you bring?
-
Experience supporting products go through compliance audits such as ISO 27001, ITSAR, Common Criteria, etc.
-
Knowledge of cloud security practices and technologies.
-
Knowledge of how cryptographic modules operate.
-
Experience securing and supporting compliance efforts in cloud environments.
-
Proven track record of being effective when working remotely and in a self-directed capacity.
-
Strong communication skills; capable of presenting technical compliance concepts to both technical and non-technical audiences.
-
Experience with AI assisted development tools like Claude, Cursor, etc.
The follwing are considered a plus:
-
Ability to analyze security controls, assess risks, and design control measures in alignment with different compliance standards.
-
Experience with Kubernetes, OpenShift, or similar technologies.
-
Experience with programming, scripting and markup languages, such as Go, Python, and XML, as well as automation tools.
-
Familiarity with cloud service provider environments (e.g., AWS, Azure) and relevant security tools (e.g.,vulnerability management).
-
Experience with open-source software.
#LI-AK1
About Red Hat
Red Hat is the world’s leading provider of enterprise open source software solutions, using a community-powered approach to deliver high-performing Linux, cloud, container, and Kubernetes technologies. Spread across 40+ countries, our associates work flexibly across work environments, from in-office, to office-flex, to fully remote, depending on the requirements of their role. Red Hatters are encouraged to bring their best ideas, no matter their title or tenure. We're a leader in open source because of our open and inclusive environment. We hire creative, passionate people ready to contribute their ideas, help solve complex problems, and make an impact.
Inclusion at Red Hat
Red Hat’s culture is built on the open source principles of transparency, collaboration, and inclusion, where the best ideas can come from anywhere and anyone. When this is realized, it empowers people from different backgrounds, perspectives, and experiences to come together to share ideas, challenge the status quo, and drive innovation. Our aspiration is that everyone experiences this culture with equal opportunity and access, and that all voices are not only heard but also celebrated. We hope you will join our celebration, and we welcome and encourage applicants from all the beautiful dimensions that compose our global village.
Equal Opportunity Policy (EEO)
Red Hat is proud to be an equal opportunity workplace and an affirmative action employer. We review applications for employment without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, citizenship, age, veteran status, genetic information, physical or mental disability, medical condition, marital status, or any other basis prohibited by law.