Quora
Staff Infrastructure Security Software Engineer (Remote)
Job Summary
This role involves working as a key member of Quora's Security Engineering Team to safeguard the company's products, infrastructure, and personnel. The position requires hands-on experience in securing large-scale cloud environments, particularly with AWS, and automating security processes through code. Responsibilities include reviewing architecture designs, implementing security policies, developing automation tools, and participating in incident response activities. The role emphasizes collaboration with engineering teams and applies expertise in security best practices, threat modeling, and incident management to maintain a secure platform.
Required Skills
Benefits
Job Description
[Quora is a privately held, "remote-first" company.This position can be performed remotely from multiple countries around the world. Please visitcareers.quora.com/eligible-countries for details regarding employment eligibility by country.]
About Quora:
Quora’s mission is to grow and share the world’s knowledge. To do so, we have two knowledge sharing products:
Quora: a global knowledge sharing platform with over 400M monthly unique visitors, bringing people together to share insights on various topics and providing a unique platform to learn and connect with others.
Poe: a platform providing millions of global users with one place to chat, explore and build with a wide variety of AI language models (bots), including GPT-4, Claude 3, Gemini Pro, DALL-E 3 and more. As AI capabilities rapidly advance, Poe provides a single platform to instantly integrate and utilize these new models.
Behind these products are passionate, collaborative, and high-performing global teams. We have a culture rooted in transparency, idea-sharing, and experimentation that allows us to celebrate success and grow together through meaningful work. Join us on this journey to create a positive impact and make a significant change in the world.
This role will be working on both Quora and Poe.
About the Team and Role:
You will be a key member of the newly created Security Engineering Team, with a mission to keep Quora safe from security problems by building robust protections around our products, infrastructure and people. Our small engineering team works on challenging problems every day. We have a culture that's rooted in constantly learning and improving, and our engineers are encouraged to think big and experiment with new ideas.
What We’re Looking For:
Sweat The Right Details: you thrive in understanding the details but will also know to ruthlessly prioritize the critical issues.
Right-Size The Solution: you recognize guidelines and framework do not always fit the problem and know how to adjust the solution for scalability not always at-scale.
Ownership: you are outcome focused and can deftly navigate obstacles, decompose complexities, manage your time and can communicate your vision to peers and management.
An Ideal Candidate Would…
...be acapable software engineer while also spiking in at least one of the following domain expertise:
Cloud Infrastructure Security: You have hands-on experience securing large-scale cloud environments, particularly with AWS. You are passionate about building secure infrastructure-as-code (IaC) pipelines using tools like Terraform or CloudFormation. You understand IAM policies, network segmentation, and VPC design and have a thorough grasp of monitoring and logging in cloud-native environments. You are skilled in identifying misconfigurations, mitigating risks, and driving remediation processes. Bonus points if you’ve implemented security in Kubernetes clusters or serverless architectures.
Automation and Secure Development Practices: You believe in "security as code" and are skilled at automating security processes. You can develop and integrate security tools into CI/CD pipelines to ensure secure code delivery. Tools like SAST, DAST, and dependency scanning are part of your daily toolkit, and you have experience integrating them into workflows to catch vulnerabilities early. You also advocate for secure coding practices and are skilled at mentoring teams to write resilient, secure applications.
Linux/System Security: You are well versed in AWS infrastructure security but also are passionate about scalability, reliability and operational rigor. Beyond that, you know that root does not mean root and are passionate about container security, POSIX Capabilities, SECCOMP and have a favorite flavor of LSM. In your spare time, you love playing around with OSQuery and eBPF.
Responsibilities:
Availability for meetings and impromptu communication during Quora's "coordination hours" (Mon-Fri: 9am-3pm Pacific Time)
Partner with engineering teams to review cloud and compute architecture design changes.
Establish threat models for cloud and compute paved roads to identify security risks.
Develop or adopt open-source tools to monitor and harden our cloud Infrastructure, harden our OS, develop security logging pipelines and detect intrusions
Apply your expert knowledge of security best practices for AWS and Kubernetes to inform remediations and the team’s control roadmap.
Drive the definition and implementation of security policies and monitor in conformance to the policies
Write code for automations that support security requirements like threat detection, incident containment, and network access management.
Conduct initial incident triage; determine scope, urgency, and potential impact of security incidents; participate in the incident response process
At Quora, we value diversity and inclusivity and welcome individuals from all backgrounds, including marginalized or underrepresented groups in tech, to apply for our job openings. We encourage all candidates who share a passion for growing the world’s knowledge, even those who may not strictly meet all the preferred requirements, to apply, as we know that a diverse range of perspectives can have a significant impact on our products and our culture.
Additional Information:
We are accepting applications on an ongoing basis.
Quora offers a wide range of benefits including medical/dental/vision coverage, equity refreshers, remote work reimbursement, paid time off, employee assistance programs, and more. Benefits are country-specific and may vary. For more information on benefits, visit this link:https://www.careers.quora.com/benefits
There are many factors that will determine the starting pay, including but not limited to experience, location, education, and business needs.
US candidates only: For US based applicants, the salary range is $155,656 - $267,615 USD + equity + benefits.
Canada candidates only: For Canada based applicants, the salary range is $188,760 - $278,168 CAD + equity + benefits.
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Job Applicant Privacy Notice:https://www.careers.quora.com/applicant-privacy-notice
#LI-RJ1
#LI-REMOTE
Quora
Quora is a place where you can ask questions that matter to you and get answers from people who have been there and done that. Quora is where scientists, artists, entrepreneurs, mechanics, and homemakers take refuge from misinformation and incendiary arguments to share what they know.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.