3 hours ago
Remote, United States or Jersey City, NJ, USASenior
Responsibilities
- Partner with Engineering and Product on threat modeling, secure design, launch reviews, and ongoing production operation.
- Review application code, APIs, architectures, infrastructure as code, cloud environments, Kubernetes workloads, deployment pipelines, and production configurations.
- Identify vulnerabilities and design weaknesses, communicate risk, and drive pragmatic remediation.
- Develop secure patterns, guidance, review checklists, engineering standards, and reusable security controls.
- Administer and improve SAST, DAST, software composition analysis, container and infrastructure-as-code scanning, CSPM, security monitoring, and related tools.
- Integrate security controls into developer workflows and CI/CD pipelines, tuning rules and reducing false positives.
- Design, implement, test, document, and tune detection logic and security alert rules using application, cloud, identity, network, and infrastructure telemetry.
- Investigate security detections and incidents, determine scope and impact, and coordinate containment, eradication, recovery, and evidence preservation with the SOC and internal teams.
- Lead or contribute to post-incident reviews and convert lessons learned into durable security and operational improvements.
- Own vulnerability management intake, validation, prioritization, remediation tracking, exceptions, verification, and reporting.
- Support third-party penetration tests, code reviews, architecture assessments, vendor assessments, and other independent security engagements.
- Build automation and metrics to improve security visibility and shorten investigation and remediation time.
- Contribute to product security, platform security, detection engineering, vulnerability management, and incident-readiness roadmaps.
Requirements
- At least 5 years of hands-on experience in product security, application security, cloud security, or a closely related security engineering role.
- Strong software engineering fundamentals and ability to review application code, with relevant experience in TypeScript, Node.js, JavaScript, or another modern language.
- Experience reviewing web applications, backend services, REST APIs, authentication and authorization systems, and relational database designs.
- Knowledge of application and API vulnerabilities, threat modeling, secure design principles, and modern identity patterns.
- Experience securing AWS environments, containerized workloads, Kubernetes, infrastructure as code, and CI/CD or GitOps workflows.
- Hands-on experience with security tools such as SAST, DAST, SCA, CSPM, container scanning, secrets detection, infrastructure-as-code scanning, SIEM, or cloud-native detection platforms.
- Experience developing or tuning security detections and analyzing application, cloud, identity, network, and infrastructure telemetry.
- Strong investigation skills, including log and system-activity analysis, hypothesis testing, timeline development, and impact assessment.
- Experience working with a SOC on alert escalation, investigation handoffs, runbooks, and detection-quality improvement.
- Experience participating in security incident response and coordinating with engineering and operational teams under time pressure.
- Experience operating a vulnerability management process and driving remediation across multiple engineering teams.
- Ability to evaluate findings by exploitability, confidence, and business impact rather than relying solely on automated severity.
- Experience working with external penetration testers, auditors, or specialist security reviewers.
- Strong written and verbal communication, autonomy, judgment, and collaborative stakeholder management.
- Preferred experience includes fintech, payments, digital assets, blockchain systems, smart contracts, custody, signing infrastructure, cryptographic key management, incident-response tooling, security data pipelines, detection-as-code, security automation, and relevant security certifications.
Benefits
- Preferred location is close to Eastern Time, with exceptional Pacific Time candidates considered through ET+2.
- Working hours must have a majority overlap with Eastern Time business hours.
- Agora describes its workplace as diverse, inclusive, and equitable and is an equal employment opportunity employer.
