Security Software Engineer
The job description
Tech stack. Application security, threat modeling, OWASP Top 10, authentication/authorization design, cryptography fundamentals, SAST/DAST tooling, penetration testing basics, secure code review
About the role
You will build security into the software development lifecycle at a company where customer trust is the foundation of the business. Security engineers here do not merely audit finished work: they build the guardrails, libraries, and automation that make the secure path the easiest path for every engineer. You will threat-model new features before they are built, review security-critical code, run security testing in CI, and respond to vulnerabilities with urgency and precision. Your work is measured in incidents that never happened and in a development culture where security is a daily habit, not a release gate.
What you will achieve
- Embed security testing into CI pipelines: SAST, dependency scanning, and secret detection running on every pull request with clear, actionable results
- Deliver threat models for major features identifying genuine risks, with mitigations tracked to verified completion before launch
- Reduce vulnerability remediation time through clear severity ratings, explicit owner assignment, and automated verification that fixes actually work
- Build security libraries and patterns including auth helpers, input validation utilities, and crypto wrappers that make secure implementation the default
- Lead incident response for security events with calm coordination, thorough root-cause analysis, and preventive follow-through that sticks
What you will bring
Must-haves
- 2 to 5 years in application security, security engineering, or software engineering with a demonstrated strong security focus
- Deep understanding of web security: OWASP Top 10, injection attacks, XSS, CSRF, SSRF, and their practical, proven mitigations
- Experience with authentication and authorization design: OAuth/OIDC flows, session management, RBAC/ABAC models, and token security
- Familiarity with cryptography fundamentals: TLS configuration, hashing versus encryption choices, key management, and common implementation pitfalls
- Ability to perform security code reviews that identify subtle vulnerabilities in unfamiliar codebases quickly and accurately
- Knowledge of security testing tools: Burp Suite, OWASP ZAP, or commercial SAST/DAST platforms used effectively in real workflows
- BS in Computer Science or equivalent experience
Nice-to-haves
- Experience with cloud security: IAM hardening, network segmentation design, and CSPM tooling
- Familiarity with compliance frameworks such as SOC 2, ISO 27001, or PCI DSS and their engineering implications
- Knowledge of offensive security: penetration testing methodology or CTF experience that informs stronger defensive work
- Experience with bug bounty program management, triage, and researcher communication
Google
Meta
Apple
Microsoft
Amazon
Oracle
Netflix
NVIDIA