Cato Networks

Cato Networks

Cato Networks is the world's leading single vendor SASE platform that converges SD WAN, security, global backbone, and remote access into a global cloud-native service. Their robust platform optimizes and secures application access for all users and lo...

Diversified Telecommunication Services
251-1K
Founded 2015
$770M raised

Description

  • Design, implement, and improve the Secure SDLC across R&D from design to deployment.
  • Build and maintain security automation in CI/CD pipelines, including scanning for code, dependencies, secrets, and infrastructure issues.
  • Own the vulnerability management program, including triage, prioritization, tracking, and remediation follow-up.
  • Manage software supply chain security, including dependency risk, SBOM generation, and artifact integrity.
  • Own runtime application security, including detection of runtime dependencies, CVEs, exploitation, and CADR.
  • Secure application infrastructure across Docker containers, Kubernetes, and AWS environments.
  • Define and operate application security detection and response processes, including alerting, playbooks, triage, and response.
  • Partner with developers on secure coding practices, training, threat modeling, and security design reviews.
  • Define security policies, guardrails, and standards as code, and measure their effectiveness.
  • Stay current on emerging threats, tooling, and best practices to continuously improve security.

Requirements

  • At least 3 years of experience in application security, DevSecOps, or a related security engineering role.
  • Hands-on experience integrating and operating security tools in CI/CD pipelines.
  • Strong understanding of Secure SDLC principles and experience driving them across engineering teams.
  • Experience with software supply chain security and dependency/vulnerability management at scale.
  • Experience with runtime application security concepts, including runtime CVE/dependency detection, exploitation detection, and CADR.
  • Solid programming or scripting skills such as Python, Go, or Java.
  • Hands-on experience securing AWS cloud environments and containerized workloads such as Docker and Kubernetes.
  • Familiarity with microservices architectures and infrastructure as code such as Terraform.
  • Experience defining alert scope, building playbooks, and operating security detection and response processes.
  • Strong problem-solving and communication skills, with the ability to work independently and cross-functionally.
  • Understanding of network security and encryption protocols.
  • Preferred: experience with vulnerability management or ASPM platforms.
  • Preferred: experience with policy as code tools such as OPA or Kyverno.
  • Preferred: knowledge of secure coding practices across multiple languages and frameworks.
  • Preferred: experience with threat modeling methodologies.
  • Preferred: security certifications such as CKS, AWS Security Specialty, or OSCP.
  • Preferred: experience working in Agile teams and collaborating across departments.
  • Preferred: BSc in Computer Science.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Manager, Product Research

Huntress 251-1K Professional Services

Huntress is hiring a remote US Product Research Manager to lead cybersecurity research efforts that improve threat detection and prevention for customers.

Cybersecurity
4 days, 14 hours ago

Lead Application Security Engineer

Zeta Global 1K-5K Media

Zeta Global is hiring a Lead Application Security Engineer to strengthen application and platform security across its AI-powered marketing platforms through automated, AI-native security practices and cross-functional security engineering.

AWS Azure Burp Suite CI/CD Cybersecurity DevSecOps Django Docker FastAPI GCP JWT Kubernetes Microservices Node.js OAuth OpenID Connect React SonarQube
5 days, 13 hours ago

Principal Security Architect (Product Security)

Anaplan 1K-5K Internet Software & Services

Anaplan is hiring a Senior Security Architecture IC to define and drive secure-by-design architecture across its enterprise planning platform and AI products.

Encryption Machine Learning OWASP
1 week, 1 day ago

Principal Security Architect (Product Security)

Anaplan 1K-5K Internet Software & Services

Anaplan is hiring a Senior Security Architect to define and drive secure architecture across its enterprise planning platform, including legacy and AI-enabled products.

Encryption LLM Machine Learning OWASP
1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers