Job Description
📋 Description Lead app security reviews, threat modeling, and secure code reviews for new features. Operate and improve SAST/DAST/SCA tooling; triage findings with engineering. Plan and execute penetration tests on web apps, APIs, and mobile clients. Own vulnerability management lifecycle from discovery to remediation validation. Develop secure coding standards, developer guidance, and training materials. Integrate security tooling into CI/CD, shift-left across the SDLC. Partner on security architecture decisions for new product capabilities. 🎯 Requirements 5+ years in application security with hands-on secure SDLC and offensive tests. Strong understanding of web app and API security (OWASP, MITRE, CIS). Experience operating SAST/DAST/SCA ASPM tools. Fluency in Python, JavaScript, Go, Ruby or similar. Experience designing and executing penetration tests for web and mobile apps. Familiarity with cloud security (AWS, GCP, OVH) and Kubernetes. 🎁 Benefits Comprehensive Medical, Dental and Vision plans starting day 1. 401(k) plan with a match. 10 paid holidays, 20 vacation days, 5 sick days, 3 floating holidays. Basic Life and AD&D Insurance covered by ButterflyMX. Short and Long Term Disability coverage. Paid Family Leave; Employee Assistance Program; Quarterly self-care stipends.