- Lead our Application Security team covering a range of areas, including application security, cloud security, and internal tooling development. Your team has full ownership in ensuring our code artifacts are secure
- Lead 1st and 3rd party vulnerability management, including coordinated disclosure with external reporters and embargoed fixes
- Contribute significantly to technical discussions and direction. You should be a technical coach who can develop your team, drive incidents, and otherwise step in yourself where needed
- Define, optimize, and implement the engineering strategy in concert with the security leadership team, ICs and stakeholders across the business
- Regular 1:1s, coaching and mentoring to ensure your team members are motivated, happy and engaged. Providing continuous feedback to ensure that they can add value while maintaining high standards
- Collaborating with our engineering leaders and other organization stakeholders to help define and influence wider product strategy, roadmaps and designs
- Be actively engaged with significant incidents, including preparation, simulation, response, and affected customer notification and communications
- Contributing to and reviewing design documents for upcoming projects. Ensuring projects are well-defined and ready for development. Advise on how to break down projects into tasks
Benefits
- Vacation: Balance is key. Our team enjoys 30 days of paid vacation each year on top of national holidays, parental leave, and sick leave. We also take a breather on a number of Grafana Shutdown Days each year
- Healthcare: We’re proud to provide health coverage or stipends for our colleagues in the US, UK, Canada, the Netherlands, Sweden, Singapore, and India
- Retirement planning: There’s no time like the present to start saving for your future. We make employer contributions into the pension pots of our team members in the US, UK, Canada, the Netherlands, Sweden, and Germany
- Professional development: On top of a $1,500 annual learning and development stipend, Grafanistas have thousands of on-demand courses at their fingertips to help them grow professionally. Want to attend a conference or training? Go ahead. Just pass on what you learned
- Work location: Vast majority of our roles are fully remote, focused on hiring the best talent and allowing you to perform from the comfort of your home. If you fancy a change of scene, we’ll also reimburse you up to $175 a month for a personal co-working space
- Choice of tech: There’s no one-size-fits-all when it comes to the tech required to do your job. Choose the laptop and accessories you need when you join us, and we’ll refresh them every three years
- Mindfulness: When you join the team, you can sign up for a complimentary subscription to Headspace to take advantage of the benefits of mindfulness and meditation. Our wellbeing resource group also organize sessions run by fellow Grafanistas or external trainers
- Global Employee Assistance Program: We offer all team members a 100% confidential support service with 24/7 365 access to professionally qualified counsellors and specialists
- Paid parental leave: Grafana offers paid parental leave to all eligible new parents. This offers Grafanistas time to bond with and care for their children in the first year after birth or adoption
You are an excellent written and verbal communicator. You can articulate complex cybersecurity concepts to both technical and non-technical audiences. You are adept at translating security problems to business impactPrior experience running a security engineering teamWhile you’re great with people and adept at managing relationships, you still keep up-to-date with the latest technical trends and shifts to maintain and enhance your understanding of the challenges your teams faceYou have familiarity with securing and operating on public Cloud (AWS, GCP, Azure) providers, with Kubernetes, and with securing combined open-source software (OSS) and SaaS productsYou approach security with a DevOps mindset. You prefer security by enablement, automation, and guardrails over gates and roadblocksYou will be comfortable working with engineering teams who have a strong sense of autonomy in their decision-making, be it technical or product-focusedYou are experienced in the modern state of AI, AI tooling, and how to both apply it to securing Grafana’s code bases and in the implications it has for our security needsYou have a strong engineering background and are capable of engaging in technical conversations and challenging teams to arrive at strong technical decisions themselvesA technical background, ideally with programming or software engineering experience, before transitioning into security & leadershipWorking knowledge of Grafana Labs OSS projects and products. Experience in using observability tooling to solve security problemsExperience working with OSS communitiesExperience securing large-scale distributed systems