Senior Application Security Engineer
Posted Updated
You will embed security throughout the software development lifecycle and partner with engineers and product managers to design and implement secure products. You will assess, triage, document, and remediate vulnerabilities; conduct threat modeling, design reviews, security testing, and code reviews; validate patches; and build automation and security controls to prevent recurring issues.
Responsibilities
- Determine the root cause and severity of bug bounty vulnerabilities
- Interface with ethical hackers, triage reports, and guide engineering teams to resolution
- Document identified vulnerabilities for engineering action
- Write code for security engineering projects and vulnerability fixes
- Develop AI tooling for vulnerability determination and resolution
- Assess application vulnerabilities and ensure remediation within established SLAs
- Conduct design reviews, threat modeling, security testing, and code reviews
- Identify and address gaps in the secure software development lifecycle
- Participate in team meetings, roadmap planning, and discussions
- Validate security patches and test for potential bypasses
- Develop automation and security controls and educate developers to prevent recurring vulnerabilities
Requirements
- 6+ years of experience building and securing software, including product or application security experience
- Experience securing modern backend systems, web applications, and APIs
- Experience performing threat modeling, security design reviews, and vulnerability assessment
- Experience securing JavaScript-based web or mobile applications
- Strong coding skills
- Familiarity with blockchain technology, Ethereum, decentralized applications, and crypto wallets
- Understanding of web and mobile security attack vectors and mitigations
- Strong communication and remote collaboration skills
- Ability to overlap with EU and US-Pacific time zones