1 day ago
Remote, United StatesMid Level / Senior
Base Salary
$145k - $245k/yr
Responsibilities
- Partner with engineering teams throughout the software development lifecycle to identify and mitigate security risks and implement secure deployment practices.
- Support threat modeling and help engineering teams implement appropriate security controls.
- Define and promote secure coding standards, security policies, best practices, and secure-by-design principles.
- Improve security testing programs and coordinate internal and external application and penetration testing initiatives.
- Validate vulnerability findings, prioritize remediation based on risk, and perform root cause analysis.
- Collaborate with Security Operations on application and service monitoring and detection capabilities.
- Triage and oversee remediation of security researcher disclosures through the bug bounty program.
- Develop security training, technical guidance, and documentation.
- Consult with other SailPoint organizations on security-related matters.
- Assess and optimize the SDLC, security tooling, deployment pipelines, product inventories, and third-party dependency inventories.
- Implement AI-assisted scanning, scalable vulnerability prioritization and remediation metrics, security champions programs, secure architectural improvements, and standardized secure deployment configurations.
- Provide hands-on mentorship and scale product security capabilities across teams.
Requirements
- 4–5 years of experience in product security, application security, software engineering, or a related field.
- Experience with SAST, SCA, DAST, and container security scanners.
- Experience with CI/CD security controls and DevSecOps practices.
- Familiarity with one or more of Python, Go, Java, JavaScript/TypeScript, or Ruby.
- Ability to use AI-powered tools and automation to improve security engineering productivity, research, analysis, and remediation.
- Knowledge of emerging AI security risks and practices for securing AI-enabled applications, services, and development workflows.
- Deep expertise in threat modeling, secure architecture design, and vulnerability management.
- Experience influencing engineering organizations and driving security initiatives across multiple teams.
- Strong analytical, problem-solving, written communication, oral communication, documentation, collaboration, and business-risk translation skills.
- Preferred knowledge of OWASP AI Security and Privacy Guide, NIST AI Risk Management Framework, Cybersecurity AI (CAI), or Open SSF AI/ML Security Framework.
Benefits
- Remote work from anywhere within the continental United States.
- Medical, dental, and vision insurance.
- Short-term and long-term disability coverage.
- Life insurance, accidental death and dismemberment coverage, and supplemental life insurance options.
- Flexible spending accounts, limited-purpose flexible spending accounts, and a health savings account with employer contribution.
- 401(k) Savings and Investment Plan with company matching.
- Flexible vacation policy, eight paid holidays annually, and sick leave.
- Paid parental leave.
- Employee Assistance Program and Care Counselors.
- Voluntary legal assistance, critical illness, accident, hospital indemnity, and pet insurance options.
- Potential eligibility for the SailPoint Corporate Bonus Plan, role-specific commission, and equity participation.
Tech Stack
Categories
About SailPoint
SailPoint builds identity security software for large enterprises, covering identity governance, access management, automated provisioning, and compliance controls across cloud and on‑prem systems. It sells primarily via subscription licenses and enterprise services. Founded in 2005 and headquartered in Austin, Texas, SailPoint is owned by Thoma Bravo and serves complex, security‑sensitive organizations that need to manage workforce and machine identities at scale.
