Job Description
Job Overview
CaptivateIQ is seeking a Senior Security Engineer focusing on Application & Product Security to enhance their security framework as they scale services. This role is pivotal in embedding security into product development, with responsibilities spanning threat modeling, secure architecture design, and offensive security testing. The ideal candidate will possess a blend of offensive and defensive security expertise, shaping a modern AppSec program that builds customer trust.
Technical Requirements
Required Skills
- • Application Security
- • Penetration Testing
- • Vulnerability Management
- • Secure SDLC Integration
- • Incident Response
Preferred Skills
- • Certifications such as OSCP, GCIH, GWAPT, or CISSP
- • Experience with commercial security tools
- • Knowledge of privacy-by-design principles
Experience Level
7+ years in a security engineer role with a focus on web application and API security
Responsibilities
- • Conduct threat modeling and architecture reviews
- • Perform offensive security testing including penetration tests for web applications and APIs
- • Integrate security into the secure SDLC and CI/CD pipelines
- • Manage vulnerability triage and remediation processes
- • Deliver developer training for secure coding practices
- • Oversee the Bug Bounty program
- • Lead incident response for application-layer security incidents
- • Support compliance audits for SOC 2 and ISO 27001
Benefits & Perks
- • 100% of medical, dental, and vision covered including 75% for dependents
- • Flexible vacation days and quarterly mental health days
- • One-time expense on 1-year work anniversary
- • 401k plan participation
- • Newest Apple products for work
- • Employee Resource Groups (ERGs) for community support
Additional Information
- Location
-
Remote - North America / Canada
- Type
-
Full-time
- Compensation
-
$154,500 - $184,713 a year