6 months ago
Base Salary
$170k - $190k/yr
Responsibilities
- Develop and implement secure coding practices, procedures, and standards for software development teams.
- Conduct application security assessments, vulnerability testing, and penetration testing.
- Review code changes and ensure identified security issues are addressed.
- Collaborate with cross-functional teams to remediate vulnerabilities and implement secure coding practices.
- Integrate security review processes into the CI/CD pipeline.
- Conduct threat modeling and risk analysis to protect sensitive data.
- Provide expertise on system, network, encryption, and authentication controls.
- Partner with SRE, Development, IT, Security, risk, and governance teams to improve cybersecurity posture and meet compliance requirements.
- Contribute to secure coding and cybersecurity training programs.
- Monitor emerging security trends, vulnerabilities, and attack techniques.
- Provide technical leadership and mentorship to engineering and security team members.
Requirements
- BA/BS/MS in Computer Science or a related field, or equivalent experience.
- At least 3 years of experience in application security or software development, preferably in SaaS companies or regulated fields.
- In-depth knowledge of application security practices, including OWASP Top 10 and SANS Top 25.
- Experience with security testing tools such as Burp Suite, AppScan, and Nessus.
- Strong proficiency in TypeScript or JavaScript.
- Experience operating in a cloud provider such as AWS, GCP, Azure, or DigitalOcean.
- Ability to prioritize and respond to escalations and collaborate across teams.
- Preferred experience includes AI penetration testing, Git workflows, Kubernetes or other containerized environments, observability platforms, Terraform, security and compliance frameworks, and SAST/SCA tools.
- Strong communication, analytical, problem-solving, ownership, adaptability, teamwork, and goal orientation are required.
Benefits
- Hybrid work with required office attendance on Tuesdays and Thursdays, plus possible additional team or company event days.
- Base salary range of $170,000-$190,000, plus equity awards and competitive health and wellness benefits.
- 100% health coverage for employees and 75% dependent coverage, with medical, dental, vision, and buy-up options.
- Gender-neutral parental leave, compassionate leave, family-forming support through Maven, and paid time off.
- Monthly wellbeing, hybrid-work, and applicable cell-phone stipends.
- Mental health support through Modern Health.
- Pre-tax commuter benefits and a 401(k) plan with Fidelity employer match for US employees.
- Regular team events and career growth and development opportunities.
Tech Stack
AWSAzureDatadogDigitalOceanGitGoogle Cloud PlatformGrafanaJavaScriptKubernetesPrometheusTerraformTypeScript
About Ironclad
Ironclad provides a SaaS contract lifecycle management platform for legal, sales, procurement, and finance teams, using AI to automate drafting, workflows, and analytics. It sells enterprise subscriptions that centralize contract creation, negotiation, e-signature, and a searchable repository with reporting. The company is privately held and headquartered in San Francisco, with customers including the Associated Press and Rivian.
