4 days ago
Remote, WorldwideSenior
Base Salary
$160k - $210k/yr
Responsibilities
- Implement and deploy SAST, SCA, secrets scanning, DAST, and container/IaC checks in CI/CD workflows.
- Partner with development teams on threat modeling, critical pull request reviews, and secure-by-default practices.
- Drive shift-left vulnerability detection and remediation across the software development lifecycle.
- Coordinate application security issues spanning application and infrastructure layers with DevOps teams.
- Support incident response for product security issues and incorporate lessons into code, documentation, and processes.
Requirements
- At least 5 years of experience in application or product security.
- Hands-on experience securing web applications and automating application security workflows.
- Familiarity with DevSecOps practices and container security and patching.
- Experience with GitHub Actions, Python, and TypeScript/JavaScript.
- Ability to communicate clearly and translate security risk for engineers.
- Preferred: experience securing LLM workflows, familiarity with the NIST Risk Management Framework, software security experience at a U.S. defense contractor, and an active security clearance or ability to obtain one.
- Willingness to travel onsite.
Benefits
- Health, dental, and vision insurance.
- 100% remote work from anywhere in the United States.
- 401(k) matching.
- Mental health benefits.
- Flexible work environment with employee-managed schedules.
- Pet and child care reimbursement during travel.
- Unlimited paid time off.
