Responsibilities
- Develop and execute an application security strategy aligned with business objectives and industry standards.
- Maintain secure coding standards, security documentation, and application security processes.
- Deliver application security and privacy training to development teams.
- Review source code for vulnerabilities, insecure patterns, exposed secrets, and risks from AI-generated code.
- Triage, reproduce, and support remediation of vulnerabilities identified through automated tools and manual analysis.
- Manage application security workflows, including prioritization, ticket tracking, and coordination with development and DevOps teams.
- Maintain and improve the responsible disclosure and vulnerability reporting program.
- Partner with developers on encryption, hashing, and secure key management practices.
- Perform threat modeling, attack-path analysis, application risk assessments, and security validation.
- Lead investigation and mitigation of application-level security incidents with SOC and engineering teams.
- Advise on security and privacy controls for AWS cloud infrastructure, application development, and IoT hardware.
- Research emerging cybersecurity risks and recommend mitigation strategies.
- Secure LLM integrations and implement appropriate security guardrails using cloud-native security tools.
Requirements
- 4–6 years of experience in application security, including developing and maintaining security policies and collaborating with engineering and release teams.
- Experience identifying and remediating application vulnerabilities in Elixir, JavaScript, Ruby, Python, or similar languages.
- Strong knowledge of the OWASP Top 10, OWASP API Top 10, JWT, and OAuth.
- Hands-on experience with SAST, DAST, and SCA platforms such as GHAS, Burp Suite, or Fortra.
- Experience with cloud security controls, AWS-native tools, web application firewalls, or similar technologies.
- Experience managing or supporting vulnerability disclosure or bug bounty programs.
- Strong written and verbal communication skills for explaining security requirements to technical teams.
- Demonstrated problem-solving and analytical skills in identifying and mitigating application security risks.
- Preferred certifications include CSSLP, GIAC GWAPT, CEH, or equivalent security certifications.
- Preferred experience includes CloudFlare, AWS security services, SDLC security integration, threat modeling, and application security architecture reviews.
Benefits
- Medical, dental, vision, and life insurance for US employees with low deductibles and 75–100% employer contributions.
- Flexible and generous paid time off.
- 401(k) plan with employer contributions.
- Paid parental leave.
- Discounted pet insurance and legal services plans.
- Employee stock purchase plan.
- Candidates outside Arizona may apply.
Tech Stack
Categories
About SmartRent
SmartRent is the leading provider of smart communities and smart operations solutions for the rental housing industry. SmartRent's platform, comprised of smart hardware and cloud-based SaaS solutions, gives operators seamless visibility and control over real estate assets, empowering them to simplify operations, automate workflows, benefit from additional revenue opportunities and deliver exceptional site team and resident experiences. We serve 15 of the top 20 multifamily owners and operators, and our solutions enable millions of users to live smarter every day. For more information, please visit www.smartrent.com. Awards: Deloitte Technology Fast 500 List, 2023, 2024 Phoenix Business Journal Largest Phoenix-Area Software Firms, 2024 MHN Excellence Awards, 2204 HousingWire Tech 100, 2021, 2022, 2023 #1 on Growjo's 100 Fastest Growing Companies in Arizona, 2021 Best Places to Work in Multifamily®, 2021 AZ Central Top Companies to Work for in AZ, 2020
