Senior Application Security Engineer (SaaS)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Application Security Engineer (SaaS): Building and hardening security infrastructure for a practice management platform with an accent on cloud security, identity management, and software supply chain integrity. Focus on implementing zero-trust architectures, enhancing observability, and integrating AI-powered security tooling to defend against evolving threats.
Location: Must be based in Utah (fully remote)
Company
is a fast-growing SaaS company building powerful practice management software for accounting firms.
What you will do
- Design and execute a multi-year security roadmap covering cloud infrastructure, identity, and network security.
- Harden AWS and Kubernetes environments through IAM, workload identity, and network segmentation.
- Build out security observability, including audit logging, runtime threat detection, and posture monitoring.
- Embed security into the SDLC, including CI/CD gates, secret scanning, and software supply chain integrity.
- Evaluate and adopt AI-powered security tooling for automated pentesting, code review, and anomaly detection.
- Serve as a security resource for engineering teams, reviewing designs and raising security literacy across the organization.
Requirements
- 8+ years of professional experience in application security or security engineering.
- Deep expertise in AWS, IAM, Kubernetes, and container security.
- Strong understanding of network security, zero-trust access, and web application security.
- Experience with secure SDLC practices, including SAST, DAST, and SBOM management.
- Ability to threat model new features and influence engineering design decisions.
- Must be based in Utah.
Nice to have
- Experience securing multi-tenant SaaS platforms.
- Relevant certifications such as OSCP, GWAPT, or GCSA.
- Experience operating detection engineering programs.
- Background in regulated or compliance-heavy environments like SOC 2 or ISO 27001.
- Hands-on experience securing AI/LLM-powered features.
Culture & Benefits
- Flexible Paid Time Off and 10 company holidays.
- Comprehensive health benefits including Medical, Dental, Vision, and HSA match.
- 401(k) plan with 100% company match up to 3%.
- Mental health support via Impact Suite and Employee Assistance Program.
- Paid new parent and birthing parent leave.
- Peer-to-peer recognition program and regular company events.
Hiring process
- Initial review followed by a 20-minute phone call with the People Team.
- 45-60 minute video or in-person interview with the Hiring Manager.
- 1-3 additional rounds of interviews depending on the role.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →