SeatGeek believes live events are powerful experiences that unite humans. With our technological savvy and fan-first attitude we’re simplifying and modernizing the ticketing industry.
We are looking for an information security professional to lead our application security program (open to varying levels of experience). As a Senior Application Security Engineer, you’ll partner with product teams to help improve the security posture and design of both our enterprise and consumer-facing products.
You’ll be part of a team developing a modern AppSec program with a highly automated approach to security coupled with a collaborative approach to working with Engineering partners. You’ll be operating in a fast paced, agile environment, with a goal of making security a key part of the product. It is a great opportunity to apply your years of AppSec experience in making SeatGeek products secure by default. As a foundational member of this team, you will have a huge impact on the product roadmap, and in building a trusting relationship with the engineering community.
What you’ll do
- Provide security guidance to engineering teams on new products and technologies
- Taking ownership and driving the application security and privacy initiatives
- Perform threat modeling and architecture review on upcoming features and products
- Perform regular security assessments through penetration testing and code reviews of SeatGeek products
- Encourage and train developers in secure coding practices
- Develop security features in our product and scale security tools and processes through automation
- Protect SeatGeek from bot attacks by tuning our edge protection and implementing app level protections
- Continuously improve the Application Security Program and actively take part influencing its roadmap
Who you are
- You’ve worked in an AppSec role and have a solid understanding of security fundamentals
- You’re proficient in one or more coding languages (Python, C#, Go) i.e you can code and perform security code reviews
- You’re experienced in working with highly technical engineering teams
- You have performed threat modeling and architectural review for years
- You like bug hunting and penetration testing (bonus points if you share your Bugcrowd/HackerOne profiles)
- Experience in AWS is a plus
- Experienced contributing to the security community (public research, blogging, presentations, etc.)
- Equity stake
- Flexible work environment, allowing you to work as many days a week in the office as you’d like or 100% remotely
- A WFH stipend to support your home office setup
- Flexible PTO
- Up to 16 weeks of paid family leave
- 401(k) matching program
- Health, vision, dental, and life insurance
- Annual subscriptions to Headspace, Ginger.io, and One Medical
- $120 a month to spend on tickets to live events
- Annual subscription to Spotify, Apple Music, or Amazon music
The salary range for this role is $130,000- $240,000. Actual compensation packages within that range are based on a wide array of factors unique to each candidate, including but not limited to skill set, years and depth of experience, certifications, and specific location.
SeatGeek is committed to providing equal employment opportunities to all employees and applicants for employment regardless of race, color, religion, creed, age, national origin or ancestry, ethnicity, sex, sexual orientation, gender identity or expression, disability, military or veteran status, or any other category protected by federal, state, or local law. As an equal opportunities employer, we recognize that diversity is a positive attribute and we welcome the differences and benefits that a diverse culture brings. Come join us!
Originally posted on Himalayas
Remote jobs from Himalayas