3 days ago
Chicago, IL, USA +2 moreSenior
Responsibilities
- Lead secure code reviews and threat modeling for web, mobile, and API surfaces.
- Own application vulnerability discovery, triage, remediation guidance, and verification.
- Build internal AppSec tooling and security libraries for developers.
- Own iOS and Android application security, including secure storage, certificate pinning, anti-tampering, and secure app-to-API communication.
- Assess mobile applications against OWASP MASVS and MASTG and review third-party SDKs and dependencies.
- Perform penetration tests and red-team-style assessments against applications, APIs, and supporting services.
- Test authentication, authorization, session handling, OAuth/OIDC, GraphQL/REST, IDOR, privilege escalation, and business-logic flows.
- Operate the bug bounty program, including scope, researcher communication, triage, deduplication, severity, and payout coordination.
- Own CI/CD and deployment-toolchain security, including the custom DSL, Kubernetes, and Terraform workflows.
- Integrate and tune SAST, DAST, dependency/SCA scanning, secrets scanning, build integrity, artifact signing, SBOMs, and provenance controls.
- Automate manual deployment steps and harden the build and release process end to end.
Requirements
- 8+ years of focused application security and/or offensive security experience, including penetration testing or exploit development.
- Strong software-development skills with the ability to read, write, and review production code.
- Experience with Kotlin and Gradle and/or Swift or Android development, plus Python for automation and custom tooling.
- Deep iOS and Android application security expertise, including OWASP MASVS/MASTG, certificate pinning, secure storage, anti-tampering, reverse engineering, and mobile testing tools.
- Hands-on penetration testing experience across web applications, mobile applications, and APIs.
- Strong API security knowledge covering OAuth/OIDC, REST, GraphQL, authentication, authorization, and business-logic vulnerabilities.
- CI/CD security experience with GitHub Actions, including SAST, DAST, SCA, secrets scanning, and build/release pipeline security.
- Strong security fundamentals and applied cryptography knowledge, including certificates, PKI, encryption, key management, and HSMs.
- Preferred experience running or scaling a bug bounty or vulnerability disclosure program using HackerOne, Bugcrowd, or similar platforms.
- Preferred offensive security certifications such as OSCP, OSWE, or GMOB, or equivalent demonstrated skill.
- Preferred experience with software supply-chain security, including SBOMs, artifact signing, and provenance.
- Preferred reverse engineering or binary analysis experience with Ghidra, Hopper, or IDA.
- Experience with consumer fintech, gaming, or reels applications and related regulatory expectations is preferred.
Benefits
- Competitive salary.
- Medical, dental, vision, and company-paid life insurance through Blue Cross Blue Shield.
- Company contributions to employee Health Savings Accounts.
- 401k plan with Safe Harbor company matching.
- Flexible vacation policy and paid company holidays.
- Company-provided technology package.
- Relocation assistance where applicable, including travel and company-provided housing for the first 90 days.
- Work location options are on-site, hybrid, or remote in New York, the Bay Area, Chicago, or Greenville.