This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Biotechnology is rewriting life as we know it, from the medicines we take, to the crops we grow, the materials we wear, and the household goods that we rely on every day. But moving at the new speed of science requires better technology. Benchling’s mission is to unlock the power of biotechnology. The world’s most innovative biotech companies use Benchling’s R&D Cloud to power the development of breakthrough products and accelerate time to milestone and market. Come help us bring modern software to modern science. As an Application Security Engineer at Benchling you’ll be joining a team responsible for maintaining a best-in-class security program. Our focus is on providing value to the organization by emphasizing real world security and embracing automation. We’re looking for engineers who are excited to apply their expertise to our mission of securing some of society's most sensitive data.
Job Responsibility:
Building and integrating external and internal security tools and automation into development and build environments
Developing lightweight processes to embed security in the SDLC workflow
Collaborating with engineers on the best ways to mitigate vulnerabilities and reduce risk
Performing code reviews of our services and apps
Partnering with both the Product Design and Software Engineering organization's security and privacy initiatives, leading security design reviews, and threat modeling
Participating in our incident response and vulnerability remediation efforts
Developing secure coding and design practices and training engineering teams
Performing black-box and gray-box penetration testing of our applications and services
Requirements:
2+ years work experience in an application security or product security role including experience with secure code reviews, threat modeling, pentesting, application security tooling and automation
Strong communicator with the ability to translate technical security requirements and risks into terms that anyone can understand
Experience finding AND fixing web application security vulnerabilities including those found in the OWASP Top 10 and CWE Top 25
Experience with at least one scripting language, preferably Python
Nice to have:
Knowledge of the browser security model, modern network security, AI and cloud (AWS ideally) security
Experience with vulnerability management and risk assessment processes
What we offer:
Competitive total rewards package
Broad range of medical, dental, and vision plans for employees and their dependents
Fertility healthcare and family-forming benefits
Four months of fully paid parental leave
401(k) + Employer Match
Commuter benefits for in-office employees and a generous home office set up stipend for remote employees
Mental health benefits, including therapy and coaching, for employees and their dependents