Application Security Engineer (SaaS)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Application Security Engineer (SaaS): Building and maturing an application security program for a scaling employee experience platform with an accent on secure SDLC, threat modeling, and AI-assisted security tooling. Focus on integrating security checkpoints into CI/CD pipelines, mentoring developers through a Security Champions program, and ensuring multi-tenant isolation.
Location: Onsite in Lindon, Utah
Company
is a fast-growing SaaS company reimagining the workplace through employee recognition and rewards.
What you will do
- Embed security checkpoints into the entire SDLC, from planning and design to release.
- Facilitate threat modeling for new services, APIs, and integrations to ensure secure-by-design features.
- Configure and optimize SAST, DAST, and container scanning tools, including AI-assisted tools like Snyk and Wiz.
- Develop and maintain secure coding standards and provide pragmatic training for engineering teams.
- Lead a Security Champions program to mentor developers and foster a security-first culture.
- Triage and track remediation of vulnerabilities across the application stack.
Requirements
- 6+ years of experience in application security or software engineering with a strong security focus.
- Hands-on experience securing cloud-hosted, multi-tenant SaaS applications.
- Deep understanding of OWASP Top 10, API security, authentication, and encryption.
- Proficiency in modern languages such as JavaScript/TypeScript, Java, C#, Python, or Go.
- Experience integrating security testing into automated CI/CD pipelines.
- Must be based in or able to work from Lindon, Utah.
Nice to have
- Experience with external pen tests or bug bounty programs.
- Knowledge of compliance frameworks like SOC 2, ISO 27001, or PCI DSS.
- Security certifications such as OSWE, OSCP, GWAPT, or CSSLP.
Culture & Benefits
- Awarded as a Great Place to Work and one of the Best Places to Work by Glassdoor.
- Fast-paced, high-growth environment backed by renowned national investors.
- Culture focused on rewarding, supportive, and fun workplace experiences.
- Commitment to equal opportunity and a non-discriminatory work environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →