23 hours ago
Remote, United StatesSenior
Base Salary
$180k - $200k/yr
Responsibilities
- Collaborate with development teams, Site Reliability Engineering, and other stakeholders to strengthen security practices throughout the software development lifecycle.
- Identify and implement security improvements independently.
- Implement, manage, and automate vulnerability management processes.
- Prioritize and remediate vulnerabilities found through internal scans, penetration tests, and bug bounty programs.
- Conduct threat modeling, code audits, and design reviews, and provide actionable security recommendations.
- Establish and automate threat-hunting capabilities and enhance security-event logging.
- Integrate and manage static and dynamic code-analysis tools within development pipelines.
Requirements
- 4+ years of experience in secure development or application security.
- Deep knowledge of authentication, web architecture, cryptography fundamentals, and related security concepts.
- Experience with Node.js, Go, and security-focused development.
- Experience running bug-bounty, penetration-testing, and vulnerability-scanning programs.
- Experience setting up and maintaining SAST, DAST, IAST, and SCA tooling.
- Experience with Burp, ZAP, Qualys, Nessus, or similar assessment tools.
- Experience building and maintaining WAF solutions.
- Familiarity with security practices, standards, and regulations such as FedRAMP, SOC 2, and HIPAA is a plus.
- Familiarity with GCP, AWS, and Kubernetes infrastructure security is a plus.
- Ability to work independently, collaborate effectively, and adapt to shifting priorities.
Benefits
- Flexible PTO plus 14 holidays.
- $1,500 annual learning and development stipend.
- Company-sponsored team celebrations.
- Employee Assistance Program and Headspace access.
- Flat 3% retirement-account contribution, 401(k) contribution, and stock options.
- Flexible work practices and generous parental, medical, and bereavement policies.
- Full medical, dental, and vision benefits.
- New hire swag and IT welcome boxes.
- Structured semi-annual 360-degree performance reviews.
