8 months ago
Remote, United StatesStaff+
Responsibilities
- Establish and continuously improve the Application Security program’s strategy, processes, and tooling.
- Collaborate with engineering teams on secure design reviews, threat modeling, code reviews, and penetration testing.
- Conduct or support security reviews of web, mobile, and API products.
- Deliver security training and promote security awareness across the engineering organization.
- Assist with incident response, risk assessment, and use of SAST/DAST tools.
- Mentor junior AppSec team members.
Requirements
- 10+ years of experience in application security or a related field.
- Experience leading the initial inception of an Application Security program from the ground up.
- Strong understanding of security fundamentals and vulnerabilities such as XSS, CSRF, and SQL injection.
- Ability to identify risks, collaborate with engineers on effective solutions, and communicate security concepts to technical and non-technical audiences.
- Preferred familiarity with C#, React, JavaScript, and REST APIs for code review and vulnerability analysis.
- Preferred active participation in B-sides conferences, OWASP chapter activities, and contributions to GitLab repositories.
Benefits
- Competitive base and incentive plan.
- Stock options.
- Health and welfare plans, life and disability plans, and a retirement plan.
- Unlimited flexible paid time off, including the employee’s birthday off.
- Benefits for international employees outside the US vary by country.
