- Help clients secure their mission-critical applications
- Perform security code review
- Perform web, mobile, and network security tests
- Help clients with security design reviews
- Help clients with threat modeling
- Help clients with remediation strategies
A Penetration Testing as a Service company that helps high-growth SaaS Based companies continuously push secure code to production
This company operates with a remote-first culture, allowing team members to work from anywhere. Team members are distributed across the U.S. and Canada.
Software Secured pioneers Penetration Testing as a Service (PTaaS), helping high-growth SaaS companies continuously push secure code. You will help development teams get ahead of hackers with expert manual penetration testing across web, mobile, API, and network infrastructure. They offer recurring tests, unlimited retesting, and integrations with tools like Jira and Slack for seamless security. Their services ensure clients meet compliance for SOC 2, ISO 27001, HIPAA, and more, protecting mission-critical applications.
Software Secured embraces a remote-first philosophy. You can work from anywhere in Canada, with the option to use their Ottawa office if you prefer. You also have the flexibility to work from anywhere in the world for up to two months each year. They foster a culture of continuous learning, growth, determination, empathy, and integrity, empowering you with a professional development budget and dedicated time annually. Team members are encouraged to be self-driven and take ownership.
As an engineer here, you'll dive deep into security code reviews and advanced penetration tests for web, mobile, and network systems. You'll tackle complex business logic flaws and chained vulnerabilities, going beyond automated scans. Your insights will directly shape security design reviews and threat modeling early in the SDLC. They value a background in Python, .NET, Ruby, Java, or Objective C/Swift, as understanding how software is built is key to breaking it effectively. You'll contribute to methodology improvements, tooling, and internal playbooks, constantly pushing the boundaries of application security.