Browse
Employers / Recruiters

Staff Application Security Engineer

spanio · 30+ days ago
$160-215k
Full-time
Continue
By pressing the button above, you agree to our Terms and Privacy Policy, and agree to receive email job alerts. You can unsubscribe anytime.

Our Mission  

SPAN is enabling electrification for all ⚡

SPAN is mission-driven to design, build, and deploy products that electrify our built environment, decarbonize our world, and slow the effects of climate change.

  • Decarbonization is the process to reduce or remove greenhouse gas emissions, especially carbon dioxide, from entering our atmosphere.

  • Electrification is the process of replacing fossil fuel appliances that run on gas or oil with all-electric upgrades for a cleaner way to power our lives.

At SPAN, we believe in:

  • Enabling homes and vehicles powered by clean energy

  • Making electrification upgrades possible

  • Building more resilient homes with reliable backup

  • Designing a flexible and distributed electrical grid

The Role

We are seeking a highly skilled and experienced individual to join our Security & Privacy team at SPAN as a Staff Application Security Engineer. In this critical role, you will be instrumental in building and enhancing SPAN’s application security program. Your responsibilities will ensure the security of our applications through proactive assessment, threat modeling, code reviews and close collaboration with the development teams. Ideal candidates will have extensive experience in application security, deep understanding of secure coding practices and ability to influence and educate others on security matters.

Responsibilities include:

  • Lead and execute application security assessments, including static application security testing (SAST), dynamic application security testing (DAST), code reviews, penetration testing, and security architecture reviews.

  • Collaborate closely with development teams to integrate security best practices into the software development lifecycle (SDLC).

  • Perform threat modeling on existing and upcoming feature sets in SPAN applications to ensure appropriate security controls are built from the ground up.

  • Develop and enforce a robust Identity and Access Management posture

  • Design, implement, and maintain application security controls and solutions, leveraging hands-on coding experience.

  • Automate application security controls using scripting to minimize human interaction and increase efficiency.

  • Own the vulnerability assessment and patch triage process to support ongoing vulnerability and patch management at SPAN and provide recommendations for identified vulnerabilities

  • Ensure compliance with regulatory requirements and industry standards including risk assessments and risk mitigation strategies for application security.

  • Ensure that our production platform in AWS is hardened as per industry standards, such as CIS benchmarks 

  • Deploy and manage Security Incident and Event Management (SIEM) solutions at SPAN.

  • Participate in the evaluation, selection, and deployment of cutting-edge security tools and technologies.

  • Stay current with the latest application security threats, vulnerabilities, and best practices. Continuously evaluate and improve application security processes and technologies.

About you

  • Bachelor’s Degree in Computer Science, Information Assurance, Cyber Security, or related field of study

  • 7+ years of experience in a security engineering or operations role, with a focus on application security.

  • Hands-on experience with one or more security tools such as Burp Suite, SonarQube, OWASP ZAP and Checkmarx.

  • Strong knowledge of applied cryptography, TLS/SSL, web authentication protocols such as OAuth/SAML

  • Deep understanding of web application vulnerabilities and defenses

  • Proficient in scripting languages such as Python, Perl, PHP, or Ruby for task automation and data manipulation.

  • Experience in developing threat models (e.g., STRIDE, DREAD).

  • Hands-on experience with AWS Security best practices

  • Experience with vulnerability scanning tools like Qualys, Nessus, etc.

  • Experience with SIEM tools like Splunk, Sumo Logic, etc.

  • Certifications such as CISSP, CSSLP, or relevant industry certifications are a plus.

The U.S. base salary range for this position is $160,000 - $215,000, plus benefits and equity. This range represents SPAN’s good faith estimate of a competitively-priced salary for the role based on national, real-time industry data from companies of a similar growth stage. This range reflects minimum and maximum new hire salaries for the role in San Francisco county. Within this range, individual pay is determined by location and individual factors including relevant skills, experience and education or training. This range correlates to the relative level of the candidate we believe we need for the role and may require an adjustment for candidates of a different level.

Your recruiter can share more about the specific salary range for the location this role is based during the hiring process.

Life at SPAN

Headquartered in San Francisco’s vibrant SoMa neighborhood, we are an eclectic group of creative thinkers who value open communication, teamwork, and a ‘make it happen’ approach to addressing complex challenges. 

SPAN embraces diversity and equal opportunity in a serious way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. 

We’re hiring talented individuals who are driven by success and are passionate about shaping the future of renewable energy. If that sounds like you, we’d love for you to consider joining the rapidly growing team at SPAN.

The Perks:

⚡ Competitive compensation + equity grants at a well-funded, venture-backed company

⚡ Comprehensive benefits: 100% employee premiums for base plans on medical, dental, vision with options for additional coverage.  Parental leave up to six (6) months depending on eligibility

⚡ Comfortable, sunny office space located near BART and Caltrain public transit

⚡ Strong focus on team building and company culture: Employee Resource Groups, monthly social events, SPANcakes recognition breakfast, lunch and learns

⚡ Flexible hours, one holiday per month and unlimited PTO

 

Interested in joining our team? Submit an application today and we’ll be in touch with next steps!

 

Last updated on Aug 16, 2024

See more

About the company

More jobs at spanio

Analyzing

San Francisco, California

 · 

30+ days ago

San Francisco, California

 · 

30+ days ago

San Francisco, California

 · 

30+ days ago

San Francisco, California

 · 

30+ days ago

San Francisco, California

 · 

30+ days ago

More jobs like this

Analyzing
ELECT - IT Security Analyst 2
B
b6jdnwcpcemgg8el3r9winlpunj8hc038b1vkhowrzxn9gitznreodi38t7rirkp

Richmond, Virginia

 · 

30+ days ago

Information Security Officer
9
9xjdnwf8nt489qdiu4ab0qq7clsnet01f27n6pjaxju02yq1u697ou3dvfougsq9

Santa Clara, California

 · 

30+ days ago

Security Engineer
0
01jdnwg028j5z7sqr5v2kknizydum00361uo9lv9r7k3dur17h5v7wx2rj64vu35

Frisco, Texas

 · 

30+ days ago

Security Analyst
Q
qualis-corporation

Huntsville, Alabama

 · 

30+ days ago

KNG OF PRUSSA, Pennsylvania

 · 

30+ days ago

Fredericksburg, Virginia

 · 

30+ days ago

Burlington, Massachusetts

 · 

30+ days ago

Security Engineer | Fully remote
T
two95-international-inc-3

Remote

 · 

30+ days ago

Marinette, Wisconsin

 · 

30+ days ago

Developed by Blake and Linh in the US and Vietnam.
We're interested in hearing what you like and don't like! Live chat with our founder or join our Discord
Changelog
🚀 LaunchpadNov 27
Create a site and sell services based on your resume.
🔥 Job search dashboardNov 13
Revamped job search UI with a sortable grid, live filtering, bookmarks, and application tracking.
🫡 Cover letter instructionsSep 27
New Studio settings give you control over AI output.
✨ Cover Letter StudioAug 9
Automatically generate cover letters for any job.
🎯 Suggested filtersAug 6
Copilot suggests additional filters above the results.
⚡️ Quick applicationsAug 2
Apply to jobs using info from your resume. Initial coverage of ~200k jobs in Spain, Germany, Austria, Switzerland, France, and the Netherlands.
🧠 Job AnalysisJul 12
Have Copilot read job descriptions and extract out key info you want to know. Click "Analyze All" to try it out. Click on the Copilot's gear icon to customize the prompt.
© 2024 RemoteAmbitionAffiliate · Privacy · Terms · Sitemap · Status