2 months ago
Remote, United States +3 moreStaff+
Base Salary
$220k - $270k/yr
Responsibilities
- Set technical direction for application security standards, patterns, guardrails, and reference architectures across the product portfolio.
- Lead threat modeling for distributed, cloud-native, and mobile architectures and influence security decisions before implementation.
- Perform manual secure code review and application security testing across Java and C++ codebases.
- Scale security analysis using AI-assisted analysis and custom CodeQL queries, and conduct variant analysis across the codebase.
- Triage externally reported vulnerabilities, assess exploitability and severity, and drive remediation across teams.
- Define and evolve the SDL, feature security review program, product penetration testing program, and security champions program.
- Create training, mentor engineers, establish security metrics, and drive systemic improvements in security posture and remediation.
- Improve security workflows and partner-facing processes to reduce friction for development teams.
Requirements
- 12+ years of hands-on application security experience with demonstrated technical depth and influence beyond individual work.
- Deep knowledge of application security vulnerabilities and mitigation techniques, with sound prioritization based on business and customer impact.
- Proven ability to lead threat modeling, secure design, and security architecture for complex distributed and cloud-native systems.
- Proficiency in Java or C++ sufficient to read, reason about, and review production code.
- Security breadth across application, system, cloud, and mobile domains.
- Demonstrated history of driving technical change, raising security standards across teams, and mentoring senior engineers.
- Excellent documentation, communication, and influence skills, with the ability to work independently through ambiguity.
- Preferred bachelor’s degree in computer science or a related field, or an equivalent combination of education and relevant professional experience.
- Preferred experience testing agentic AI systems, using AI tooling in security workflows, building scalable security automation, or penetration testing for a multi-tenant SaaS provider.
Benefits
- Typical base salary is USD $220,000–$270,000 per year, with possible corporate bonus eligibility.
- Benefits include employee ownership, health insurance, 401(k) matching, disability insurance, paid time off, and growth opportunities.
- Hybrid work requires three days per week in the Atlanta, Georgia or Mountain View, California office, with remaining days remote; candidates must live within reasonable commuting distance.
- Travel to remote offices is expected twice per year.
