Mattermost is the industry’s leading open-source enterprise-grade messaging platform. Customers including Intel, Ubisoft, Samsung, Cigna, BNP, European Commission, Social Security Administration, and Affirm use Mattermost to enable their teams to collaborate securely and privately anywhere. Many of the world’s leading privacy-conscious enterprises like The US Department of Defense work better by connecting people, tools, and automation to increase developer collaboration using Mattermost. Our private cloud messaging platform offers secure, configurable, highly scalable messaging using web, mobile, and desktop applications and provides deep integrations with hundreds of SaaS and on-premises tools and applications.
We value high impact work, ownership, self-awareness and being focused on customer success. If these values match who you are, we hope you'll learn more about working at Mattermost
Mattermost is seeking a result-driven and analytical Security Engineer to help monitor, build, and maintain our security infrastructure and processes across the company. As part of our Security team you will work closely with a globally distributed team to ensure the safety of our infrastructure and services in collaboration with other internal teams.You
will be responsible for the implementation of additional security tooling and/or processes across the company and coordinate with relevant stakeholders, gather requirements, and lead the implementation.
Responsibilities:Lead security projects to increase security posture of infrastructure and companyDetect, respond to, and remediate security incidentsDevelopment and review of company-wide security policies and processesOwnership of company-wide IAM solutionSetup and maintenance of monitoring infrastructureSetup and maintenance of incident response and forensic toolkit
Requirements:Bachelor's degree in Computer Science or related fields, or significant professional security experience3+ years of demonstrated experience in security engineering, incident response and/or penetration testingExperience with security monitoring systemsExperience with security controls for cloud environments such as AWS, GCP and/or AzureExperience with identity and access management in-depth knowledge of Linux systemsExcellent written and verbal communication skillsDemonstrable teamwork skills and resourcefulness
Preferences:Experience with certifications processes such as SOC2, ISO 27000 series, FEDRamp, etc.Experience in one or more programming languages, ideally Go or PythonExperience with infrastructure automation and software delivery Certifications in the domain of penetration testing, incident response or computer forensics (e.g. OSCP, GCIH, GCFA, etc.)Familiarity with Kubernetes and DockerExperience working in open source communities