Skip to main content
Virtru

Application Security Engineer

RemoteUnited States, United Kingdom only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Mid-size
$180k–$200k/yr
Check eligibility

Open to US, GB only. Set where you work from to check your eligibility.

No BS summary

Application Security Engineer with 4+ years of experience in secure development. Requires deep knowledge of security concepts, experience with Nodejs/Go, and running vulnerability management programs. Must be self-motivated and able to collaborate with development teams.

Core skills

application securitysecure developmentvulnerability management

Required skills

Node.jsGoSASTDASTIASTSCABurpZAPQualysNessusWAF

Optional skills

FedRAMPSOC2HIPAAGCPAWSKubernetes

What you'll do

  • Collaborate with development teams, Site Reliability Engineering, and other stakeholders to strengthen the adoption of security best practices throughout the SDLC.
  • Independently identify security improvements and implement them.
  • Implement, manage, and automate vulnerability management processes.
  • Prioritize and remediate vulnerabilities discovered through internal scans, penetration tests, and bug bounties.
  • Conduct threat modeling, code audits, design reviews with engineers to ensure effective and secure development.
  • Collaborate in providing actionable recommendations to find workable solutions.
  • Establish a threat hunting capability and automate where appropriate.
  • Enhance logging capabilities related to security events.
  • Integrate and manage dynamic and static code analysis tools.
  • Ensure operation of security tools within the development pipeline.

What they require

  • 4+ years experience in secure development or application security.
  • Deep knowledge of security concepts such as authentication, web architecture, etc.
  • Experience with Nodejs, Go, etc.
  • Experience running bug-bounty, penetration testing, vulnerability scanning programs.
  • Experience setting up and maintaining SAST, DAST, IAST and SCA tooling
  • Experience using assessment tools such as Burp, ZAP, Qualys, Nessus, etc.
  • Experience building and maintaining WAF solutions.
  • Familiarity with industry security practices, standards, and regulations such as FedRAMP, SOC2, HIPAA, etc. a plus.
  • Familiarity with GCP/AWS and Kubernetes infrastructure security a plus.
  • Self-motivated and goal driven, able to find what needs to be done and do it.
  • Thinking outside of the box to respectfully challenge your teammates and managers in the pursuit of excellence
  • Strong sense of urgency with an action-oriented mindset
  • Able to collaborate and adapt to shifting priorities as business needs evolve
  • Comfortable with asynchronous communication including slack, email, zoom, etc.

Benefits

  • A Flexible PTO policy — we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge.
  • A $1,500 annual Learning & Development Stipend focused on providing you the resources to continually learn and professionally grow.
  • Frequent company-sponsored team celebrations that provide ample opportunities to connect with teammates and be social!
  • Access to an Employee Assistance Program
  • Access to Headspace , a mental health app tailored to your specific needs.
  • A flat 3% contribution to your retirement account
  • A high degree of flexibility — Have an appointment, errand, or family emergency to take care of? Hop to it! We give you the time and space to take care of you and your own first.
  • Competitive compensation
  • Generous parental, medical, and bereavement policies
  • 401K contribution and stock options
  • Full medical, dental, and vision benefits
  • New Hire Swag and IT Welcome boxes
  • Structured semi-annual 360° performance reviews
Data SecurityMid-sizevirtru.com
$180k–$200k/yr