Mattermost provides an open source enterprise-grade messaging platform to the world’s leading organizations that allows teams to collaborate securely and privately anywhere. With over 10,000 server downloads / month our customers include Intel, Samsung, Affirm, The US Department of Defense and more. Our private cloud solutions offer secure, configurable, highly-scalable messaging across web, phone and PC with archiving, search, and deep integrations with hundreds of SaaS and on-premises technologies. Headquartered in Palo Alto, California, our company serves customers around the world with a distributed organization spanning the globe.
We value high impact work, ownership, self-awareness and being focused on customer success. If these values match who you are, we hope you'll learn more about working at Mattermost
Mattermost is seeking a result-driven and analytical Security Engineer to help monitor, build, and maintain our security infrastructure and processes across the company. As part of our Security team you will work closely with a globally distributed team to ensure the safety of our infrastructure and services in collaboration with other internal teams.You
will be responsible for the implementation of additional security tooling and/or processes across the company and coordinate with relevant stakeholders, gather requirements, and lead the implementation.
Responsibilities:Lead security projects to increase security posture of infrastructure and companyDetect, respond to, and remediate security incidentsDevelopment and review of company-wide security policies and processesOwnership of company-wide IAM solutionSetup and maintenance of monitoring infrastructureSetup and maintenance of incident response and forensic toolkit
Requirements:Bachelor's degree in Computer Science or related fields, or significant professional security experience3+ years of demonstrated experience in security engineering, incident response and/or penetration testingExperience with security monitoring systemsExperience with security controls for cloud environments such as AWS, GCP and/or AzureExperience with identity and access managementIn-depth knowledge of Linux systemsExcellent written and verbal communication skillsDemonstrable teamwork skills and resourcefulness
Preferences:Experience with certifications processes such as SOC2, ISO 27000 series, FEDRamp, etc.Experience in one or more programming languages, ideally Go or PythonExperience with infrastructure automation and software delivery Certifications in the domain of penetration testing, incident response or computer forensics (e.g. OSCP, GCIH, GCFA, etc.)Familiarity with Kubernetes and DockerExperience working in open source communities