UK remote
Software Engineer - Platform Security
About this role
About Neo4j: Neo4j is the graph intelligence platform that transforms data into knowledge to power the next generation of intelligent applications and AI systems. It includes enterprise-ready knowledge graphs for accurate, explainable, and governed AI; the most comprehensive, trusted, and easy-to-deploy graph capabilities across any environment and data source; and an unmatched ecosystem trusted by 84 of the Fortune 100 and supported by the world’s largest graph community.
Intelligence that works. Results that matter. Built to work everywhere and integrate with everything across every cloud for dynamic, personalized, and autonomous AI systems. We deliver quicker results, contextual knowledge, and solutions that impact customers and employees across the business. Our Vision: At Neo4j, we have always strived to help the world make sense of data. As business, society and knowledge become increasingly connected, our technology promotes innovation by helping organizations to find and understand data relationships.
We created, drive and lead the graph database category, and we’re disrupting how organizations leverage their data to innovate and stay competitive. The Team: Aura is Neo4j’s managed cloud platform, operating at scale with 800+ Kubernetes clusters across multiple clouds. At its core is Omni, the platform that powers Aura. Within it, the Platform Security team ensures developers have the tools and documentation to ship secure code and create services using a secure-by-design ethos.
We’re hiring experienced engineers with a security mindset to expand our tooling, add new guardrails, and partner with Aura teams on secure design. The Role: Develop cloud-native controls in Azure, AWS and/or GCP to enforce the security baseline at scale, integrating with open-source and vendor tools as needed. Enhance product security along the software development lifecycle by creating “ paved roads ” and defining additional security and software excellence requirements for containerised services running on multiple managed Kubernetes clusters.
Act as a subject matter expert for the Platform and Engineering teams by providing guidance on cloud and k8s services, secure infrastructure-as-code, modern secure AuthZ/AuthN techniques (i.e. SPIFFE) and secrets management solutions. Collaborate with other teams to define and implement Cloud/K8s native policies and procedures (i.e. Kyverno, Pod Security Standards). Conduct security assessments, audits and architecture reviews in order to introduce new cloud controls in the platform and make recommendations to improve the overall security posture.