Virtru
Application Security Engineer
Washington, DC - Remote
Sponsorship not specified$180k-$200kDetected 5 days ago
GoAndroidNode.jsAWSGCPKubernetesSite Reliability EngineeringRESTCybersecurityPenetration TestingCompliancePerformance ManagementFirewallHIPAACommunication
About the role
- We're setting data free so that you can intentionally share it with others, but without sacrificing security, privacy, or control.
- Through the Trusted Data Format (TDF) open standard, we're not just protecting data; we're creating a new paradigm where security enables sharing rather than preventing it.
- Our applications are primarily built in Go and Javascript.
Responsibilities
- a robust platform with an open core that developers and partners can build upon, coupled with our own best-in-class applications that showcase what's possible when you reimagine security from the ground up.
- Backed by Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global, we're helping Fortune 500 companies and government agencies discover that true data security means having the freedom to share, collaborate, and innovate - without compromise.
- Implement, manage, and automate vulnerability management processes.
- Conduct threat modeling, code audits, design reviews with engineers to ensure effective and secure development.
- Collaborate in providing actionable recommendations to find workable solutions.
- Able to collaborate and adapt to shifting priorities as business needs evolve
- As an application security engineer you will help our engineering teams maintain and develop our product, and directly have impact in a security centric company and product.
- You should have a strong foundation in the fundamentals of cryptography, and be able to talk and collaborate with development teams.
- We use a range of security tools, and aggressively automate where we can (even if we have to code and build it).
- Collaborate with development teams, Site Reliability Engineering, and other stakeholders to strengthen the adoption of security best practices throughout the SDLC.
Requirements
- A high degree of flexibility - Have an appointment, errand, or family emergency to take care of?
Skills
- Ensure operation of security tools within the development pipeline.
- 4+ years experience in secure development or application security.
- Deep knowledge of security concepts such as authentication, web architecture, etc.
- Experience with Nodejs, Go, etc.
- Experience running bug-bounty, penetration testing, vulnerability scanning programs.
- Experience setting up and maintaining SAST, DAST, IAST and SCA tooling
- Experience using assessment tools such as Burp, ZAP, Qualys, Nessus, etc.
- Experience building and maintaining WAF solutions.
- Familiarity with industry security practices, standards, and regulations such as FedRAMP, SOC2, HIPAA, etc. a plus.
- Familiarity with GCP/AWS and Kubernetes infrastructure security a plus.
- Self-motivated and goal driven, able to find what needs to be done and do it.
- Security Engineering
Compensation
- $180,000 - $200,000/year
- Structured semi-annual 360° performance reviews
Benefits
- A Flexible PTO policy - we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge.
- A $1,500 annual Learning & Development Stipend focused on providing you the resources to continually learn and professionally grow.
- Access to Headspace, a mental health app tailored to your specific needs.
- A flat 3% contribution to your retirement account
- Generous parental, medical, and bereavement policies
- 401K contribution and stock options
- Full medical, dental, and vision benefits
- At Virtru, we believe people do their best work when their wellbeing is put first.
- In addition to wellbeing, Virtru places a strong emphasis on diversity, equity, inclusion, and belonging.
- Additional perks include:
This listing is sourced directly from Virtru's careers page and normalized into a canonical job model.