Job Description
Responsibilities
- Embed application security into every phase of the SDLC and conduct security-by-design engagements for features, APIs, platform initiatives, and infrastructure changes.
- Perform secure code reviews and provide actionable remediation guidance, documentation, workshops, and secure coding standards.
- Establish secure REST and GraphQL API patterns and maintain security architectural patterns for engineering teams.
- Integrate and maintain security tooling and quality gates across CI/CD pipelines, including hardening GitHub Actions and runner environments.
- Partner with DevOps engineers to secure AWS infrastructure defined through Terraform and Kubernetes and to protect containerized workloads.
- Support application-layer network security controls such as Web Application Firewalls and CDN security.
- Operate the application vulnerability management lifecycle, triage findings by business impact and exploitability, and address systemic risks.
- Track security KPIs such as MTTR, vulnerability density, and CI/CD security coverage and communicate actionable insights to engineering and business leadership.
- Participate in the weekly on-call rotation.
Requirements
- At least 3 years of application security engineering experience.
- Experience building and operating internal security developer platforms or tooling that reduces developer friction.
- Ability to use AI/ML-driven tools to improve security effectiveness and scalability.
- Hands-on experience leading threat-modeling engagements and designing secure paved roads.
- Experience integrating security tooling into CI/CD pipelines.
- Working knowledge of OWASP Top 10 for web, mobile, API, and LLM security.
- Hands-on experience securing AWS deployments with container and Kubernetes security, infrastructure-as-code scanning, and policy-as-code approaches.
- Expertise in security-by-design using TypeScript, Swift, and/or Kotlin.
- Experience implementing secure primitives in iOS and Android ecosystems.
- Beneficial certifications include AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent.
- Strong communication, collaboration, coaching, automation, and cross-functional risk-management skills.
Benefits
- Remote work throughout the US or from the Manhattan, NY office.
- Unlimited vacation policy and paid volunteer opportunities.
- Technology stipend of $4,000 every two years after start and a $500 annual work-from-home stipend.
- Monthly physical, mental, wellness, learning, and lifestyle stipends.
- Medical, dental, vision, prescription, FSA, HRA, HSA, and family/dependent health coverage.
- Traditional and Roth 401(k) plans through Vanguard with an immediate company match.
- Basic, supplemental, and dependent life insurance plus short- and long-term disability leave.
- Company-paid parental leave of up to 20 weeks for birthing parents and 12 weeks for non-birthing parents.
- Family-building benefits through Progyny and a DICK'S Sporting Goods family-of-brands teammate discount.
Job Tags
Full time, Temporary work, Work at office, Immediate start, Remote work, Work from home