Apply

Senior Application Security Engineer

Posted 15 days agoViewed

View full description

💎 Seniority level: Senior, 5 years

📍 Location: US, Europe

💸 Salary: 175000.0 - 210000.0 USD per year

🔍 Industry: Cloud computing, AI

🏢 Company: CoreWeave💰 $642,000,000 Secondary Market about 1 year agoCloud ComputingMachine LearningInformation TechnologyCloud Infrastructure

🗣️ Languages: English

⏳ Experience: 5 years

🪄 Skills: PythonSQLCybersecurityKubernetesCommunication SkillsCollaborationCI/CDLinuxWritten communicationDocumentation

Requirements:
  • Bachelor’s degree in Computer Science or a related field or equivalent experience.
  • 5 years of experience in Application Security engineering and vulnerability testing.
  • Strong knowledge of authorization, authentication, and encryption protocols.
  • Experience with development teams delivering commercial software.
  • Familiarity with threat modeling and system security vulnerabilities.
  • Scripting skills in languages such as Perl or Python.
  • Proficiency in security engineering methodologies including static and dynamic code analysis.
Responsibilities:
  • Provide security consultations with engineering peers.
  • Conduct architecture reviews of new and existing code changes.
  • Perform full and complete threat models as part of the permit process.
  • Configure and manage automated and manual code reviews.
  • Lead ongoing security testing, audits, and risk analysis.
  • Engage in security incident response, risk documentation, and remediation verification.
Apply

Related Jobs

Apply

📍 New York City, California, Colorado, Washington

💸 160000 - 200000 USD per year

🔍 Visual collaboration software

  • 5+ years experience in a product security focused role.
  • Experience with product security at a multi-tenant SaaS company preferred.
  • Experience with vulnerability management.
  • Deep understanding of web application and mobile application security risks.
  • Deep understanding of Linux, Networking, Cryptography, and Cloud Architecture fundamentals.
  • Software development experience with Node.JS or other frameworks like React, Angular, etc. is preferred.
  • Familiarity with MongoDB, Node.JS, Ruby, and/or Python is preferred.
  • Excellent command of English, both written and verbal.

  • Performing security reviews of Mural product features and architecture.
  • Manage and operate our bug bounty program.
  • Lead penetration testing and manage any risks to remediation.
  • Implementation and operation of SAST and DAST technologies in the CI workflow.
  • Working closely with Engineering teams to track and manage product risks to remediation.
  • Working closely with Engineering to increase coverage of security testing.
  • Communicating and nurturing relationships with security researchers, customers, and other stakeholders.
  • Producing metrics to help track the health of our product vulnerability management strategy.
  • Educating and evangelizing secure coding best practices.

Node.jsSoftware DevelopmentMongoDBRubyStrategyAngularReactLinuxNetworking

Posted about 2 months ago
Apply
Apply

📍 Australia, Austria, Bangladesh, Belgium, Brazil, Canada, Colombia, Costa Rica, Croatia, Czech Republic, Denmark, Egypt, Estonia, Finland, France, Germany, Ghana, Greece, India, Indonesia, Ireland, Israel, Italy, Kenya, Mexico, Netherlands, Nigeria, Peru, Poland, Singapore, South Africa, Spain, Sweden, Switzerland, Uganda, United Arab Emirates, United Kingdom, United States of America, Uruguay

🧭 Full-Time

💸 109047 - 169455 USD per year

🔍 Nonprofit, Technology, Open Source

  • Two or more years of application security experience, with knowledge of OWASP Top Ten and CWE Top 25
  • Strong understanding of modern, object-oriented PHP development
  • In-depth experience developing or auditing JavaScript
  • Demonstrated ability to exploit and mitigate application-level vulnerabilities
  • Experience conducting software security reviews using source code inspection, manual testing, and automated scanning
  • Ability to explain security issues to non-technical audiences
  • Sensitivity to security challenges in large, international projects
  • Strong understanding of cryptography in web application security
  • Experience using Linux for web application development and deployment tasks
  • Ability to maintain focus while working remotely

  • Triage and remediate reported security issues
  • Review and deploy features developed by the Foundation and community members
  • Work with other development teams to ensure safe architectural and implementation choices
  • Test and evaluate software to find bugs before attackers do
  • Provide application security concept reviews and promote application security best practices
  • Provide support for application security incidents and operations

PHPSoftware DevelopmentBashCybersecurityJavaJavascript*NixOAuthC (Programming language)Linux

Posted 4 months ago
Apply