11 hours ago
Base Salary
$232k - $379k/yr
Responsibilities
- Partner with product portfolios and engineering teams to manage product security, including AI/ML security considerations and cross-functional security consulting.
- Lead security design reviews and threat modeling for APIs, web features, and service integrations.
- Integrate SAST, SCA, and DAST capabilities into CI/CD pipelines and developer workflows.
- Review source code and deployment configurations, then help developers triage, remediate, and validate vulnerabilities.
- Maintain application security guidance and support secure development, security awareness, and enablement programs.
- Develop and deploy AppSec automation and integrations, including ASVS scanning and Burp Suite Enterprise.
- Conduct application security integration reviews, SaaS security assessments, and open-source software reviews.
- Participate in cross-functional incident response and remediation planning.
Requirements
- Bachelor’s degree or equivalent relevant experience.
- 6–8 years of experience in application security or full-stack development with security expertise.
- Strong understanding of secure coding in Python, JavaScript/TypeScript, Node.js, and web standards.
- Knowledge of OWASP Top 10 web and GenAI LLM risks, API security, SSRF, and related application security concerns.
- Experience with code-scanning tools such as CodeQL, Wiz, SonarQube, or Snyk.
- Ability to read and debug complex codebases across the technology stack.
- Clear communication skills and the ability to guide engineers at all levels.
- Preferred qualifications include GraphQL security experience, security champions or secure SDLC rollout participation, open-source security tooling contributions, infrastructure-as-code and container security familiarity, and AI/ML automation or development experience.
Benefits
- Medical, dental, vision, life insurance, supplemental income plans, Headspace subscription, monthly wellness allowance, and a 401(k) plan with company match.
- One-time $2,000 payment for home office equipment and furniture, plus a fully provisioned MacBook Pro.
- Four weeks of PTO accrued in the first year and twelve weeks of fully paid parental leave for new parents.
- Up to $5,000 annually for professional learning and development, LinkedIn Learning, and BetterUp coaching opportunities.
- Remote-first work from anywhere in the U.S. excluding U.S. territories; occasional travel may be requested but is generally not required.
- Employees in the San Francisco Bay Area or Providence, Rhode Island may use local offices, and core meeting hours are 9 AM–2 PM Pacific time.
Tech Stack
Categories
About Quanata
Quanata builds insurance technology that uses telematics, behavioral data, and AI to predict and prevent risk and to power context-based insurance products. It develops and supports a flexible, full-stack digital insurance platform and risk-focused acquisition capabilities for State Farm and HiRoad. Headquartered in San Francisco, Quanata is privately held and wholly owned and funded by State Farm.
