6 months ago
Responsibilities
- Identify systemic security gaps in the codebase and engineering workflows and drive durable solutions with engineering teams.
- Build security tooling, automation, custom linters, static analysis rules, and automated checks to address vulnerability classes at scale.
- Conduct in-depth code reviews and security design reviews for significant product initiatives.
- Drive threat modeling and security assessments and translate security requirements into actionable engineering guidance.
- Help develop the security team’s approach to AI-assisted development and changing security risks.
- Triage, track, and drive remediation of vulnerabilities and contribute to penetration testing and bug bounty programs.
Requirements
- 5+ years of hands-on experience in application security and security engineering.
- Experience shipping security tooling or automation that improves outcomes across multiple teams.
- Ability to read, reason about, and review code deeply enough to identify real bugs and root causes.
- Productive working proficiency in TypeScript and Python.
- Strong application security fundamentals, including threat modeling, secure code review, vulnerability classes, and durable remediation approaches.
- Ability to work independently, prioritize effectively, communicate security concepts clearly to engineers, and exercise sound judgment.
- Pragmatic experience and judgment regarding the use of AI tooling in security work and developer workflows.
- Preferred experience includes bug bounty, CTF, red team, penetration testing, SAST pipelines, custom static analysis rules, automated security testing infrastructure, or work at a startup or high-growth company.