Startups

Lead Product Security Engineer

Aalyria · Remote (United States) · Remote

← All jobs
About Aalyria

Aalyria is a leading technology company that supplies laser communications technology and temporospatial software-defined networking platforms to the aerospace industry. Backed by Battery.

About the role

You'll be the technical voice of product security across Aalyria, reporting to the Director of Security & IT. You'll own application security, CI/CD and supply-chain security, our Kubernetes-based product infrastructure, product-side authentication and PKI, and you'll partner closely with hardware engineering on Tightbeam.

What they're looking for

  • Senior- or staff-level hands-on experience in product security or security engineering, with significant depth in software/AppSec
  • Production experience securing cloud environments such as IAM, org policy, VPC Service Controls, KMS, and Kubernetes at depth
  • Strong cryptographic foundations, PKI architecture, key management, signing, mTLS, and secrets handling at scale
  • Hands-on coding ability in Python, Bash, and Go, you can write tooling, automate controls, and ship Terraform/scripts when the situation calls for it. Comfort reviewing code is a plus
  • A track record of building security programs, not just operating tools someone else stood up
  • Experience leading product incident response, triage, response, coordination with engineering teams, customer comms, and post-mortem ownership
More about this role

You'll be the technical voice of product security across Aalyria, reporting to the Director of Security & IT. You'll own application security, CI/CD and supply-chain security, our Kubernetes-based product infrastructure, product-side authentication and PKI, and you'll partner closely with hardware engineering on Tightbeam.

This is a senior to staff level individual contributor role with room to grow into management as the function scales. We need someone who's genuinely happy in a terminal and equally comfortable leading an architecture review.

  • Application & software security. SAST/DAST/SCA, secure SDLC, threat modeling, and software vulnerability management across our codebase.
  • CI/CD and supply-chain security. Hardening our GitLab pipelines, build provenance, dependency integrity, signing, and SLSA-aligned controls.
  • Product infrastructure security. GKE and Kubernetes hardening, container security, workload identity, network policy, and runtime protection.
  • Product PKI. Certificate lifecycle, issuance, rotation, and mTLS architecture across distributed services and remote assets.
  • Vulnerability management. Triage, prioritization, remediation tracking, and exception...

Read the full posting on Aalyria's site ↗

Internal Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.