This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are hiring an Application Security Engineer to join our Infrastructure & Security team. You’ll report to our Director of Infrastructure and work closely with fellow SREs, Software Engineers, DevOps Engineers, Platform Engineers, Customer Relations, and Cybersecurity Analysts. You will be helping identify, triage and fix security issues within the Onebrief application and related platform and deployed infrastructure.
Job Responsibility:
Find Vulnerabilities in our Software: Bring an attacker’s mindset to review PRs, perform code audits, and utilize static analysis to identify vulnerable code patterns
Fix Vulnerabilities Across the Full Stack: Think like an adversary to find, fix, prevent or patch vulnerabilities from browser to kernel
Improve the Security Posture of Infrastructure: Review identity and access management, logging, auditing, monitoring to help craft a layered defense
Make the Team Stronger: Mentor other engineers on best security practices, share news of vulnerable libraries and compromises, engage with community on active threats and trends
Requirements:
5+ years of experience in Application Security, Cybersecurity Engineering, Software Engineering or a related field
U.S. citizenship required
A strong understanding of Linux, containerization and orchestration, and virtual machines
Networking fundamentals: core protocols and secure configurations
A deep understanding of incident response processes
Clear, concise writing
strong documentation habits and async communication
Core skills and technologies: Javascript/Browser security, Network Security, Firewalls, Intrusion Detection, Static Analysis, Dynamic Analysis, Container Scanning, Kubernetes, Docker, Helm, Ansible, Terraform, Linux, AWS, DoD compliance, Monitoring and Observability tools
5+ years experience in Cybersecurity, Software Engineering and/or DevOps
Familiarity with DevOps practices, CI/CD
Familiarity with security tooling such as Static & Dynamic Analysis (SAST/DAST)
Familiarity with networking, web protocols
Working grasp of PKI, TLS and cryptographic primitives