Senior Product Security Engineer
Listed on 2026-03-09
-
IT/Tech
Crypto & DeFi, Cybersecurity, Blockchain / Web3, Data Security
Red Hat's products form the foundation of the enterprise IT landscape, and the trust in those products is built on cryptography. As the cryptographic landscape faces its greatest shift in a generation—the transition to Post-Quantum Cryptography (PQC)—Red Hat is building out our portfolio team to govern our cryptographic future.
We are forming a Portfolio Crypto Team, a strategic partnership between Product Security (Prod Sec) and RHEL Security. As a Senior Product Security Engineer, your mission is to own and execute key cryptographic modernization initiatives and act as the primary enabler for product teams across Red Hat. You will be the recognized go-to person for cryptographic implementation outside of RHEL, helping teams adopt new policies, integrate modern libraries, and audit their applications.
This role expects you to be an expert and owner of cryptography, build relationships across teams, and enable others by scaling your expertise to drive portfolio-wide adoption.
What You Will Do:Primary
Job Responsibilities
- Own Cryptographic Discovery and Inventory Tooling:
- Act as the primary technical owner responsible for continuing the implementation and integration of Red Hat's cryptographic inventory tools (e.g., Crypto Scanner).
- You will partner with the Principal Product Security Engineer to define and implement scanner policies for detecting cryptographic assets in our build pipelines.
- You will work directly with pipeline and data teams to integrate these tools and produce a sustainable Cryptographic Bill of Materials (CBOM).
- Act as the Portfolio's Crypto Enablement Partner:
- Serve as the primary go-to technical consultant for product teams (like Open Shift, Ansible, and Middleware) navigating cryptographic migrations (e.g., PQC, FIPS).
- You will consult directly with engineers to help them audit their code, understand their dependencies (e.g., python-cryptography), and build migration plans that align with the portfolio-wide policy.
- You will enable other teams by creating documentation, best-practice guides, and office hours to scale your expertise.
- Drive Foundational Crypto Integration and Dependency Management:
- Define the functional requirements for and partner on the integration of new cryptographic tools, such as runtime instrumentation for core libraries.
- You will track and manage critical cryptographic dependencies across the portfolio, working with RHEL Security and other teams to resolve blockers and ensure the successful, sequential delivery of modern crypto capabilities.
Required Skills
- Technical Expertise:
Broad knowledge in applied cryptography (PKI, TLS, digital signatures) and hands‑on experience with core libraries (OpenSSL, NSS, libcrypto). Strong understanding of modern cryptographic challenges, including Post‑Quantum Cryptography (PQC). - Project Ownership:
Proven experience owning and delivering complex, cross‑team technical projects from design to completion. - Collaborative Leadership: A track record of building relationships across teams and acting as a recognized go-to person. You must be able to enable others to succeed.
- Problem Solving:
Strong analytical skills to diagnose complex dependencies and technical blockers in a large‑scale software portfolio. - Bonus
Skills:
Hands‑on experience with Python or Go cryptographic libraries, runtime analysis tools, and familiarity with FIPS validation processes.
The salary range for this position is $ - $. Actual offer will be based on your qualifications.
Pay TransparencyRed Hat determines compensation based on several factors including but not limited to job location, experience, applicable skills and training, external market value, and internal pay equity. Annual salary is one component of Red Hat’s compensation package. This position may also be eligible for bonus, commission, and/or equity. For positions with Remote‑US locations, the actual salary range for the position may differ based on location but will be commensurate with job duties and relevant work experience.
AboutRed Hat
Red Hat is the world’s leading provider of enterprise open source software solutions, using a community-powered approach to deliver…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).