Ibotta

Ibotta

Security Engineer

Hybrid - Denver · Full-time

Work authorization required$115k-$130kDetected 43 days ago
PythonJavaGoCode ReviewAWSGCPCloud PlatformsDockerTerraformCI/CDMachine LearningCybersecurityPerformance MarketingCommunicationProblem Solving

About the role

  • In this role, you will be ensuring the security of our software development lifecycle (SDLC) and our cloud-native environments.
  • This position is located in Denver, Colorado as a hybrid position requiring 3 days in office (Tuesday, Wednesday, and Thursday).
  • Candidates must live in the United States.

Responsibilities

  • IBTA) is a leading performance marketing platform allowing brands to deliver digital promotions to over 200 million consumers through a network of publishers called the Ibotta Performance Network (IPN).
  • To learn more about what our Tech teams are doing day to day, visit Building Ibotta on https://medium.com/building-ibottaMedium.com http://Medium.com.
  • Perform application security assessments, including manual code reviews and penetration testing.
  • Analyze Ibotta's application architecture to identify weaknesses and develop opportunities for improvement.
  • Integrate and manage SAST, DAST, and SCA tools within the CI/CD pipeline.
  • Lead threat modeling for new application features with key stakeholders across mobile, platform, infrastructure and AI enablement.
  • Develop and maintain secure coding practices, provide training to developers.
  • Work with Ibotta's engineering team to design, implement, and monitor runtime and container security controls across cloud platforms (AWS/GCP).
  • Evaluate the security of AI-generated code and implement guardrails for model-serving endpoints in the development process.

Requirements

  • 4+ years in security engineering, application development, or application security.
  • Proficiency in languages like Python, Go, or Java
  • experience with Docker/Kubernetes.
  • Strong understanding of Web API security patterns and modern authentication protocols.
  • Familiarity with OWASP Top 10 and implementing technical controls to address vulnerabilities.
  • Working knowledge of web application testing tools.

Nice to have

  • Basic knowledge of networking security is a plus.
  • Strong knowledge of AWS security services and IaC (Terraform).
  • Experience writing secure IAM policies and other configurations in Terraform a plus.

Compensation

  • Applicants must be currently authorized to work in the United States on a full-time basis.
  • Applicants are accepted until the position is filled.
  • For the security of our employees and the business, all employees are responsible for the secure handling of data in accordance with our security policies, identifying and reporting phishing attempts, as well as reporting security incidents to the proper channels.
  • $115,000 - $130,000.
  • Equity is included in overall compensation package.
  • This compensation range is specific to the United States labor market and may be adjusted based on actual experience.

Benefits

  • This position is located in Denver, CO and includes competitive pay, flexible time off, benefits package (including medical, dental, vision), Employee Stock Purchase Program, and 401k match.
  • Denver office perks include paid parking, snacks, and occasional meals.

Equal opportunity

  • Ibotta is an Equal Opportunity Employer.

Visa & Work Authorization

  • Applicants must be currently authorized to work in the United States on a full-time basis.

This listing is sourced directly from Ibotta's careers page and normalized into a canonical job model.