Binti
Staff/Principal Application Security Engineer
Binti HQ - San Francisco, CA · Principal
Sponsorship not specifiedDetected 109 days ago
PythonJavaRubyFull-Stack DevelopmentObject-Oriented ProgrammingCybersecurityPenetration TestingSIEMComplianceLeadershipCommunicationMentoring
About the role
- We have expanded our product offerings in child welfare, moving more to the root of the problem, helping families stay together and avoid separation, and are now expanding horizontally across other areas in social services.
- Investors include Founders Fund, First Round Capital, Kapor Capital, and others.
- We're a team of ~90 people and growing quickly.
Responsibilities
- Conduct Security Assessments: Provide holistic assessments of Binti's security stance, including performing regular security reviews, code audits, penetration testing, and threat modeling to maintain the highest standard of application security.
- This includes scoping and prioritizing work, determining what levels of investment and risk we should take on given our scale and capacity, contributing to job descriptions and hiring plans for the next team members, and building relationships across teams and with company leadership to effectively communicate and advocate for these goals.
- Respond To Incidents: Respond promptly to security incidents, collaborate with engineers on-call, and provide detailed post-event analyses. Evaluate the applicability of emergent security concerns through risk rating and assessment (such as OWASP).
- Improve Security Architecture: In a leadership capacity with the Engineering team, identify, design, and implement technologies to enhance security automation, during the software development lifecycle, within the product itself, and in cloud hosting environments.
- Set Security Standards: Lead efforts to design and implement secure coding standards and best practices across the development lifecycle, with an eye toward automation, including effective AI tools
- Review and implement security patches and hotfixes in production applications.
- Implement streamlined feedback of security recommendations for new products before launch into the Binti platform.
- Improve the security of documents and files uploaded and downloaded on the platform.
- Support evidence collection for compliance frameworks such as SOC 2 Type II and HIPAA.
- In partnership with a vendor, stand up a bug bounty program and drive engagement from external security researchers
Requirements
- Strong understanding and knowledge of web application security principles, common vulnerabilities, and best practices.
- Excellent communication skills with the ability to simply convey complex security concepts to non-technical stakeholders and clearly articulate the relative risks and trade-offs.
- Deep Understanding: Strong understanding and knowledge of web application security principles, common vulnerabilities, and best practices.
Nice to have
- Proven experience as an Application Security Engineer or in a similar role.
- Strong technical background with experience in full-stack development, cloud computing, and scalable architecture.
- Proficiency in one or more OOP coding languages (Ruby, Python, Java, etc) is strongly preferred.
- Big plus - prior experience with GovTech or FedRamp
- Technical Expertise: Proven experience as an Application Security Engineer or in a similar role.
Compensation
- An above-market compensation package (salary + equity)
Benefits
- An above-market compensation package (salary + equity)
- Excellent medical, dental, vision, and life insurance
- Flexible vacation time to promote a healthy work-life blend
- 16 weeks of paid parental bonding leave for the arrival of a newborn or newly placed infant
- Sick/mental health time separate from vacation days (accrue up to a cap of 80 hours)
- 401k, Commuter benefits, FSA, and DCFSA with administration paid for
- $5,000 annual bonus for employees who volunteer as a CASA https://nationalcasagal.org/ (court-appointed special advocates)
- $300 reimbursement for initial office setup
- $50 a month effective work reimbursement to cover internet, electricity, office setup costs, or lunch/snacks with coworkers
- $2,500 annual reimbursement for ongoing learning and development, with opportunities to attend trainings/conferences, on-site speaker series, and lunch and learns
Company info
- Help Binti chart a specific and pragmatic course of action to achieve a strong security posture.
- Stay up to date on the latest security threats, vulnerabilities, and industry best practices, and ensure the integration of this knowledge into Binti's security strategies.
- Act as our company's expert on application security matters, providing mentorship to development teams and fostering a scalable, security-aware culture.
- Product Orientation: Focused on keeping the company secure while ensuring the team can still ship products and deliver value to customers and users.
- Focused on keeping the company secure while ensuring the team can still ship products and deliver value to customers and users.
- At Binti, we celebrate having a diverse team and believe our differences make us stronger.
Equal opportunity
- We welcome all qualified applicants to apply without regard to race, color, religion, gender, sexual orientation, age, national origin, disability, or protected Veteran status.
This listing is sourced directly from Binti's careers page and normalized into a canonical job model.