Ironcladhq

Ironcladhq

Staff Application Security Engineer

San Francisco · Staff+ · Full-time

Sponsorship not specified$170k-$190kDetected 34 days ago
TypeScriptGitAWSGCPAzureKubernetesTerraformCI/CDPrometheusGrafanaDatadogSite Reliability EngineeringCybersecurityPenetration TestingComplianceLeadershipCommunicationCollaborationProblem SolvingMentoring

About the role

  • Contracts move faster, insights surface instantly, and agents push work forward, all with you in control.
  • That's why the world's most transformative organizations, from Rivian to the World Health Organization and the Associated Press, trust Ironclad to accelerate their business.
  • Ironclad has also been named to Forbes' AI 50 and Business Insider's list of Companies to Bet Your Career On.

Responsibilities

  • Develop and implement secure coding practices, procedures, and standards for software development teams.
  • Perform security reviews of code changes and ensure that security issues are addressed.
  • Collaborate with cross-functional teams to remediate software vulnerabilities and implement secure coding practices.
  • Work closely with members of the SRE, Development, IT, and Security teams to drive impactful changes to Ironclad's cybersecurity posture.
  • Work closely with the risk and governance teams to implement compliance and security requirements.
  • the opportunity to help build the company you want to work at
  • Family forming support through Maven for you and your partner

Requirements

  • Office attendance is required at least twice a week on Tuesdays and Thursdays for collaboration and connection.

Nice to have

  • AI penetration testing.
  • Experience with git and software branching and workflow strategies.
  • Experience working with modern, microservice architectures including in Kubernetes or other containerized environments.
  • Experience with enterprise observability platforms such as ELK, Datadog, Prometheus, Grafana, etc.
  • Knowledge of Terraform or other infrastructure-as-code and configuration management solutions.
  • Experience with SOC 2, ISO 27001, NIST, and CIS standards and frameworks.
  • Experience with SAST and SCA tools such as Snyk, Checkmarx, Veracode, WhiteSource, or Black Duck.

Skills

  • Strong proficiency in either Typescript or Javascript.
  • 3+ Years of experience working in application security or software development, preferably with SaaS companies or in regulated fields.
  • In-depth knowledge of application security concepts and practices, including OWASP Top 10 and SANS Top 25.
  • Experience with security testing tools such as Burp Suite, AppScan, and Nessus.
  • Experience operating in any cloud provider (AWS, GCP, Azure, Digital Ocean etc.).
  • Ability to appropriately prioritize and respond to different escalations.
  • Experience working collaboratively with cross-functional teams.
  • Strong desire to take ownership of problems.
  • Comfort working in a rapidly evolving environment and dealing with ambiguity.
  • Excellent communication, analytical and problem-solving skills.
  • High output, low ego.

Compensation

  • The base salary range represents the minimum and maximum of the salary range for this position based at our San Francisco headquarters.
  • The actual base salary offered for this position will depend on numerous factors, including individual proficiency, anticipated performance, and the location of the selected candidate.
  • $170,000 - $190,000
  • Our base salary is just one component of Ironclad's competitive total rewards package, which also includes equity awards (a new hire grant, along with opportunities for additional awards throughout your tenure), competitive health and wellness benefits, and a commitment to career growth and development.
  • Family forming support through Maven for you and your partner
  • 401(k) plan with Fidelity with employer match (US Employees)

Benefits

  • 100% health coverage for employees (medical, dental, and vision), and 75% coverage for dependents with buy-up plan options available
  • Market-leading leave policies, including gender-neutral parental leave and compassionate leave
  • Paid time off - take the time you need, when you need it
  • Mental health support through Modern Health, including therapy, coaching, and digital tools
  • Pre-tax commuter benefits (US Employees)
  • Monthly stipends for wellbeing, hybrid work, and (if applicable) cell phone use

This listing is sourced directly from Ironcladhq's careers page and normalized into a canonical job model.