Staff Application Security Engineer
Company: Ironclad Inc.
Location: San Francisco
Posted on: February 1, 2025
Job Description:
Ironclad is the #1 contract lifecycle management platform for
innovative companies. Every company, in every country, in every
industry runs on contracts, but managing these contracts slows
companies down and costs them millions of dollars. L'Or--al,
Staples, Mastercard, and other leading innovators use Ironclad to
collaborate and negotiate on contracts, accelerate contracting
while maintaining compliance, and turn contracts into critical
carriers of operational business intelligence. It's the only
platform flexible enough to handle every type of contract workflow,
whether a sales agreement, an HR agreement or a complex
NDA.Ironclad is seeking a skilled Application Security Engineer
with a passion for securing modern software platforms and
protecting sensitive data. We are looking for someone with strong
experience in automated vulnerability scanning and penetration
testing to strengthen our application security program. The ideal
candidate will have experience in software development or testing
at SaaS companies or in regulated fields.This role will be
responsible for conducting security assessments, identifying and
mitigating risks, and implementing security best practices and
process improvements across Ironclad's Product, Platform and
Engineering teams.Roles & Responsibilities:
- Develop and implement secure coding practices, procedures, and
standards for software development teams.
- Conduct application security assessments and vulnerability
testing to identify and mitigate risks.
- Perform security reviews of code changes and ensure that
security issues are addressed.
- Collaborate with cross-functional teams to remediate software
vulnerabilities and implement secure coding practices.
- Integrate security review processes into Ironclad's CI/CD
pipeline.
- Conduct threat modeling and risk analysis to protect sensitive
data.
- Provide domain expertise on protective controls including
system, network, encryption, and authentication services.
- Work closely with members of the SRE, Development, IT, and
Security teams to drive impactful changes to Ironclad's
cybersecurity posture.
- Work closely with the risk and governance teams to implement
compliance and security requirements.
- Contribute to secure coding and other cybersecurity training
programs.
- Stay up-to-date with the latest security trends,
vulnerabilities, and attack techniques.
- Provide technical leadership and mentorship to other members of
the engineering and security teams.Key Skills:
- BA/BS/MS in Computer Science or related field or equivalent
experience.
- 3+ Years of experience working in application security or
software development, preferably with SaaS companies or in
regulated fields.
- In-depth knowledge of application security concepts and
practices, including OWASP Top 10 and SANS Top 25.
- Experience with SAST and SCA tools such as Snyk, Checkmarx,
Veracode, WhiteSource, or Black Duck.
- Experience with security testing tools such as Burp Suite,
AppScan, and Nessus.
- Experience with SOC 2, ISO 27001, NIST, and CIS standards and
frameworks.
- Experience operating in any cloud provider (AWS, GCP, Azure,
Digital Ocean etc.).
- Ability to appropriately prioritize and respond to different
escalations.
- Experience working collaboratively with cross-functional
teams.
- Strong desire to take ownership of problems.
- Comfort working in a rapidly evolving environment and dealing
with ambiguity.
- Excellent communication, analytical and problem-solving
skills.
- Team and goal-oriented.
- High output, low ego.Nice to Have:
- Strong proficiency in scripting and any programming languages
(TypeScript, Java, Python, Ruby etc.).
- Experience with git and software branching and workflow
strategies.
- Experience working with modern, microservice architectures
including in Kubernetes or other containerized environments.
- Experience with enterprise observability platforms such as ELK,
Datadog, Prometheus, Grafana, etc.
- Knowledge of Terraform or other infrastructure-as-code and
configuration management solutions.Benefits:
- Health, dental, and vision insurance
- 401k
- Wellness reimbursement
- Take what you need vacation policy
- Generous parental leave for both primary and secondary
caregiversBase Salary Range: $190,000 - $210,000The base salary
range represents the minimum and maximum of the salary range for
this position based at our San Francisco headquarters. The actual
base salary offered for this position will depend on numerous
factors, including individual proficiency, anticipated performance,
and the location of the selected candidate. Our base salary is just
one component of Ironclad's competitive total rewards package,
which also includes equity awards (a new hire grant, along with
opportunities for additional awards throughout your tenure),
competitive health and wellness benefits, and a commitment to
career growth and development.Pursuant to the San Francisco Fair
Chance Ordinance, we will consider for employment qualified
applicants with arrest and conviction records.
#J-18808-Ljbffr
Keywords: Ironclad Inc., Rancho Cordova , Staff Application Security Engineer, Engineering , San Francisco, California
Didn't find what you're looking for? Search again!
Loading more jobs...