8 часов назад
Senior Application Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Application Security Engineer (AWS/Java/TypeScript): Building security tooling and automation while protecting applications handling customer data, payments, and multi-tenant authorization boundaries with an accent on threat modeling, secure design, and vulnerability remediation. Focus on strengthening AWS IAM and cloud-native security, preventing authorization flaws, and establishing secure engineering standards and developer guardrails.
Location: Austin, Texas — hybrid, with in-office work on Monday, Wednesday, and Friday. U.S.-based candidates must reside in one of ’s approved states; hiring is also available in Canada.
Company
operates an AI-native platform for charter transportation, shuttle, transit, and emerging autonomous vehicle operations.
What you will do
- Own security tooling and vulnerability management across SAST, dependency and container scanning, secret detection, and penetration testing.
- Lead security design reviews, threat modeling, and targeted manual code reviews for authentication, authorization, payment, and customer-data systems.
- Identify and prevent multi-tenant authorization vulnerabilities across quoting, booking, and trip workflows.
- Strengthen AWS security through IAM, account boundaries, secrets management, workload protection, and comprehensive logging.
- Build secure defaults, reusable libraries, automation, developer guardrails, and a security champions practice.
Requirements
- 5+ years of experience in software engineering or security, including 3+ years in application or product security.
- Strong software engineering skills in Java and/or TypeScript, including production-grade security tooling and automation.
- Deep knowledge of threat modeling, secure system design, authentication, authorization, access control, injection, SSRF, and manual code review.
- Hands-on AWS and cloud-native security experience, including IAM, multi-account architecture, containerized workloads, CI/CD security, and vulnerability management.
- Strong technical judgment and influence, with the ability to define standards, prioritize risk, and drive remediation without direct authority.
Nice to have
- Familiarity with SOC 2, PCI DSS, and GDPR.
Culture & Benefits
- Remote-first company with role-specific in-office requirements.
- Medical, dental, and vision insurance, mental health support, virtual care, gym discounts, and family-building benefits.
- Paid time off and paid holidays; policies vary by country.
- Life and disability insurance where available, plus region-specific financial planning programs.
- Mac or PC with a monitor, keyboard, and mouse.
Hiring process
- Talent Acquisition video interview.
- Technical video interview followed by team interviews.
- Offer and reference check.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →