Full Stack Security Engineer (Application & Product)
R
RunpodCloud Computing AI
Remote - USAFull-TimeSenior
Salary$152,000 - $175,000
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years
- Required Skills
- GraphQLPythonJavascriptOAuthTypeScriptGoRESTful APIs
Requirements
- 5+ years of experience in application security, product security, or as a software engineer with a heavy security focus.
- Strong programming and code-review skills in languages like Python, Go, JavaScript/TypeScript.
- Deep understanding of web application vulnerabilities (OWASP Top 10).
- Deep understanding of API security (REST/GraphQL).
- Deep understanding of modern authentication flows (OAuth, OIDC, JWT).
- Hands-on experience with offensive web security testing tools (e.g., Burp Suite, ZAP).
- Experience building and maintaining automated security pipelines (DevSecOps).
- Ability to translate complex security risks into actionable engineering tasks.
Responsibilities
- Lead threat modeling, architecture reviews, and code reviews for web applications, APIs, and microservices.
- Actively develop and commit code to fix security flaws in Python, Go, or JavaScript/TypeScript codebases.
- Implement, tune, and manage security testing tools (SAST, DAST, SCA) within CI/CD pipelines.
- Configure and manage application-layer security controls, including Web Application Firewalls (WAF), bot protection, and API gateways.
- Provide security guidance, secure coding training, and standard operating procedures to development teams.
- Collaborate with operations on product-level adherence to frameworks like SOC 2, ISO 27001, and GDPR.
- Participate in bug bounty triage.
View Full Description & ApplyYou'll be redirected to the employer's site