21 hours ago
Raleigh, NC, USASenior
Responsibilities
- Conduct security architecture, product design, and feature reviews to identify risks early and recommend mitigations.
- Drive risk-based application security assessments and communicate security risk in business terms.
- Serve as an application security subject matter expert for product, engineering, legal, and leadership stakeholders.
- Partner with development teams throughout the software development lifecycle and mentor engineers on secure development practices.
- Mature the SSDLC through secure coding standards, security requirements, developer education, and security champions programs.
- Assess and manage security risks related to AI tools, agentic systems, MCP, and LLM-powered workflows.
- Develop scalable security tooling and automation to integrate security controls into CI/CD pipelines.
- Conduct white-box penetration testing and help manage application security vulnerabilities.
Requirements
- At least 5 years of combined experience in software engineering, application security, product security, or a closely related field in a SaaS environment.
- Experience building trusted relationships with product and engineering teams.
- Experience securing web applications using modern frameworks and cloud-native architectures, particularly AWS.
- White-box penetration testing experience and knowledge of common application vulnerabilities, OWASP Top 10, API security, and authentication or authorization flaws.
- Strong understanding of SSDLC principles and experience implementing or maturing secure development programs.
- Experience integrating security tooling into CI/CD pipelines.
- Familiarity with AI security risks, agentic systems, MCP, and LLM-powered workflows.
- Strong written and verbal communication skills.
- Preferred: experience with modern technology stacks, OWASP ASVS, NIST 800-53, SOC 2, GDPR, bug bounty program management, and security certifications such as OSCP, BSCP, GWEB, PNPT, or similar.
- Preferred: bachelor’s degree in Computer Science, Information Security, or a related field.
Benefits
- Lucid offers a hybrid workplace with remote work, office work, or a combination depending on the role and team.
- The company emphasizes work-life balance and an inclusive, respectful workplace culture.
About Lucid
Lucid builds a visual collaboration suite—Lucidchart for diagramming, Lucidspark for virtual whiteboarding, and Lucidscale for cloud architecture visualization—sold as SaaS to individuals and enterprises. Founded in 2010 and headquartered in South Jordan, Utah, the privately held company integrates with Google Workspace, Microsoft 365, Atlassian, and Slack to support team planning and documentation across engineering, product, and operations.
