6 months ago
Base Salary
$240k - $330k/yr
Responsibilities
- Conduct regular security reviews, code audits, penetration testing, threat modeling, and holistic security assessments
- Set application security priorities, scope work, determine appropriate investment and risk levels, and contribute to hiring plans
- Respond to security incidents with on-call engineers and produce detailed post-event analyses
- Evaluate emerging security concerns using risk ratings and assessments such as OWASP
- Design and implement security automation across the software development lifecycle, product, and cloud hosting environments
- Establish secure coding standards and best practices, including effective AI tools
- Mentor development teams and integrate current security threats, vulnerabilities, and industry practices into company strategy
- Review and implement security patches and production hotfixes
- Improve pre-launch security feedback, uploaded and downloaded file security, and protection of PHI and PII
- Improve third-party security concern notification and escalation processes
- Integrate logging and alerting systems with centralized or decentralized SIEM platforms
- Assess application security backlogs and recommend remediation
- Support evidence collection for SOC 2 Type II and HIPAA compliance
- Partner with a vendor to establish a bug bounty program and engage external security researchers
- Drive completion of critical security tasks, sometimes implementing fixes directly and sometimes overseeing full-stack engineers
Requirements
- Proven experience as an Application Security Engineer or in a similar role
- Strong technical background in full-stack development, cloud computing, and scalable architecture
- Proficiency in one or more object-oriented programming languages such as Ruby, Python, or Java is strongly preferred
- Strong understanding of web application security principles, common vulnerabilities, and best practices
- Ability to communicate complex security concepts, risks, and trade-offs to technical and non-technical stakeholders
- Experience cultivating a scalable security-aware development culture through mentorship and automation
- Pragmatic, resourceful approach to advancing security goals with a relatively small team
- Genuine interest in using technology to address social challenges
- Prior GovTech or FedRAMP experience is a plus
- Final selected candidates may be required to complete background and reference checks, including employment and education verification, criminal history review, and fingerprinting where applicable
Benefits
- Above-market compensation package including salary and equity
- Medical, dental, vision, and life insurance with 99% of premiums covered for the employee and dependents
- Flexible vacation time
- 13 paid holidays, including Juneteenth, Election Day, and the day after Thanksgiving
- 16 weeks of paid parental bonding leave
- Separate sick and mental health time accruing up to 80 hours
- Four-week sabbatical after four years of service
- 401(k), commuter benefits, FSA, and DCFSA administration
- $5,000 annual bonus for employees who volunteer as a CASA
- $2,500 annual learning and development reimbursement
- Training, conference, speaker series, and lunch-and-learn opportunities
- $300 reimbursement for initial office setup
- $50 monthly effective-work reimbursement
- Paid jury duty
About Binti
Binti builds SaaS for state and county child welfare and social service agencies, offering a modular CCWIS with licensing, placements, family finding/engagement, and service referrals. Privately held and founded in 2016 in San Francisco, it serves 550+ agencies across 38 U.S. states, including 15 statewide deployments, and sells cloud software with implementation services to government customers.
