Stord
Staff Site Reliability Engineer, Security
Remote, United States · Staff+
Sponsorship not specified$18k-$22kDetected 31 days ago
PythonGoCode ReviewGitBigQueryGCPKubernetesTerraformCI/CDGitHub ActionsSite Reliability EngineeringRESTMachine LearningCybersecurityDetection EngineeringComplianceSalesforceAuditingSupply ChainCadenceFirewallInternal AuditNmap
About the role
- Stord is The Consumer Experience Company, powering seamless checkout through delivery for today's leading brands.
- Stord is rapidly growing and is on track to double our revenue in the next 18 months.
- Stord's end-to-end commerce solutions combine best-in-class omnichannel fulfillment and shipping with leading technology to ensure fast shipping, reliable delivery promises, easy access to more channels, and improved margins on every order.
Responsibilities
- Build security capabilities that the broader
- A clear charter with a foundation to build on.
- Build the program, then scale it through the team.
Requirements
- You know where the sharp edges are and which knobs actually matter.
- You can reason about how the platform pieces fit together (GKE workloads, networking, edge, CI/CD) and debug security-relevant infrastructure problems alongside the broader SRE team.
- Track record of designing for operability.
- Required Soft Skills
- You can explain technical decisions and trade-offs to engineers, PMs, and stakeholders.
- You work well with others, give constructive code review feedback, and actively seek input from teammates.
- Production experience integrating image scanners into CI/CD and registry workflows, with thoughtful handling of vulnerability data freshness and triage.
Nice to have
- Prior experience standing up a security program inside an SRE or platform team, taking partial foundations and making them coherent.
- Familiarity with the current supply-chain threat landscape and recent CISA guidance (post-Shai-Hulud token guidance, M-22-18 / SSDF, etc.).
- Contributions to open-source security tooling or published security research.
- What Success Looks Like
- 30 days: You've ramped on Stord's GCP footprint, GitHub configuration, and existing security tooling.
- You've identified the top three posture gaps and the top three CI/CD supply chain risks, and you've socialized them with SRE leadership.
- 90 days: The vulnerability and dependency remediation workflow is live with at least one engineering team as a pilot, including triage cadence, ownership model, and remediation tracking against documented SLAs.
- 6-12 months: The remediation workflow is rolled out across engineering.
Compensation
- Stord manages over $10 billion of commerce annually through its fulfillment, warehousing, transportation, and operator-built software suite including OMS, Pre- and Post-Purchase, and WMS platforms.
This listing is sourced directly from Stord's careers page and normalized into a canonical job model.