Job Summary:
Pure Storage is fundamentally reshaping the data storage industry and is seeking a Senior Security Engineer to enhance application security across the enterprise. The role involves designing automated security solutions, collaborating with various teams, and establishing security standards to ensure secure software development practices.
Responsibilities:
• Own the CI/CD and GitOps security integration lifecycle, building automated, paved-road application security controls (including SAST, DAST, SCA, and secrets scanning) to eliminate manual engineering friction and ensure frictionless, secure-by-default code deployment across all Everpure product teams.
• Develop scalable automation and API-driven tooling using Python to streamline vulnerability detection, compliance reporting, and remediation tracking, directly scaling the operational capability of the GISO without impeding developer velocity.
• Establish and drive company-wide AppSec standards, baselines, and metrics in partnership with Security Architecture, translating abstract compliance guidelines into practical, uniform development baselines that measurably mature Everpure's engineering risk posture.
• Collaborate as a trusted security partner with product, platform, and DevOps teams at our Santa Clara headquarters to champion secure coding practices, support large-scale vulnerability prioritization, and architect robust protection across core applications, APIs, and microservices.
Qualifications:
Required:
• Demonstrated mastery in embedding security controls natively into modern CI/CD pipelines, Git-based workflows, and GitOps environments to automate risk detection.
• Advanced proficiency in Python or equivalent programming languages to construct custom automation, interface with web APIs, and integrate security tooling directly into developer platforms.
• Deep technical understanding of secure coding practices, modern cloud-native architectures (including microservices, APIs, and containerized workloads), and industry-standard software vulnerability frameworks (such as OWASP).
• Proven ability to build consensus, drive engineering alignment, and influence the adoption of uniform security baselines across distributed engineering, product, and DevOps teams.
• Location: We are primarily an in-office environment and therefore, you will be expected to work from the Santa Clara, CA office in compliance with Everpure’s policies, unless you are on PTO, or work travel, or other approved leave.
Company:
Pure Storage is an all-flash enterprise storage company that enables broad deployment of flash in data centers. Founded in 2009, the company is headquartered in Santa Clara, USA, with a team of 5001-10000 employees. The company is currently Late Stage.