Application Security Engineer

Hard Yaka

United States

On-site

USD 150,000 - 173,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive medical, dental, and vision insurance
Competitive compensation package and equity
Monthly work from home stipend of $50
Flexible work schedule
Paid time off
Unlimited growth opportunities

Job summary

A technology company is hiring an Application Security Engineer III to lead in building secure systems. You will design scalable security measures and integrate security into product development. A Bachelor's degree in Computer Science and 5+ years of experience in application security are required. The position offers a salary between $150,000 and $173,000 a year, alongside comprehensive benefits and a collaborative work culture.

Qualifications

  • 5+ years of related experience or master's degree and 3+ years of experience.
  • Ability to design systems that are simple to understand and maintain.
  • Prior experience securing large-scale web applications and APIs.

Responsibilities

  • Design, build, and maintain scalable security systems.
  • Partner with teams to integrate security into the product lifecycle.
  • Champion 'shift-left' methodologies in security.

Skills

Python
Ruby
Go
Rust

Education

Bachelor's degree in computer science or related field

Tools

AWS
GCP
Azure
Linux
Windows
Mac OS

Job description

🧡📦💙Founded in 2012, EasyPost is a YC unicorn whose mission is to make shipping simple for businesses—from garage startups to the Fortune 500. Shipping, now more than ever, is the backbone of the global economy, but integrating the technology-enabled operations of a modern business with the low-tech and complex shipping industry has always been a challenge. EasyPost solves this problem with the first developer-friendly REST API for shipping, and we continue to push boundaries and discover new ways to simplify shipping for all. Our team is rapidly growing, and this is the perfect time to get on board. Join us and help build the shipping infrastructure of the future. We’re builders, problem-solvers, and “there has to be a better way” people. We like elegant architecture, fast decisions, and shipping (pun intended) improvements that power millions of deliveries every day. We stay scrappy, we move fast, and we don’t wait for permission to innovate in an industry that desperately needs it. If you want to work on systems that actually move the world—literally—you’re in the right place.

Position Summary:

The Application Security Engineer III will serve as a technical leader dedicated to helping us build an even more secure software ecosystem for our customers. Beyond identifying and mitigating vulnerabilities, you will architect comprehensive defense strategies and embed security into the fabric of our development lifecycle. Your efforts will help drive our application security posture forward, safeguarding sensitive data and ensuring compliance with industry standards while also preserving engineering velocity.

Essential Duties and Responsibilities:
  • Lead Security Architecture: Design, build, and maintain scalable security systems and infrastructure that align with the organization's evolving business goals.
  • Embed Security by Design: Partner with cross-functional teams to integrate security and privacy controls into the product lifecycle, from project inception to final delivery.
  • Scale Security Operations: Build automated systems and programs that allow security at EasyPost to scale efficiently in both breadth and depth of coverage.
  • Drive DevSecOps Adoption: Champion "shift-left" methodologies, utilizing Infrastructure-as-Code and CI/CD design patterns to move security feedback to the earliest phases of development.
  • Product Innovation: Architect and build competitive customer-facing security features that support business growth and appeal to security-conscious markets.
  • Intelligent Notifications: maintain high-fidelity alerting/notification infrastructure that delivers timely, relevant, and actionable intelligence to internal staff and customers.
  • Enablement & Education: Create self-service documentation, training materials, and knowledge base resources that empower developers to write safer code and increase productivity.
  • M&A Integration: Collaborate directly with M&A entities to assess risks, integrate products, and unify diverse environments under our security standards.
Minimum Education & Experience Qualifications:
  • Bachelor's degree in computer science, management information systems, or related field.
  • 5+ years of related experience, master's degree and 3+ years of related experience, or equivalent related work experience.
  • Ability to code proficiently in at least two of the following programming languages: Python, Ruby, Go, and Rust.
  • Ability to design systems that are simple to understand, maintainable, scalable, and resilient.
  • Prior experience securing large-scale web applications and/or Application Programming Interfaces (APIs), including performing security design reviews, vulnerability assessments, and building testing strategies for logic flaws.
  • The ability to understand and communicate concepts around threat modeling and risk management, including to both technical and non-technical stakeholders.
  • Proven history of building strong partnerships with Engineering and Product teams to deliver world-class products and features.
  • Working knowledge of several compliance and regulatory frameworks (SOC2, ISO 27001, SOX/ITGC, HIPAA, GDPR, CCPA, etc…)
  • Experience in assessing risk and selecting key objectives during the vendor management lifecycle for software, hardware, cloud, and software-as-a-service vendors.
  • Deep knowledge of how to build and maintain mixed computing environments (Linux, Windows, Mac OS, and mobile devices).
  • Past experience with migrating applications and services to public cloud providers (AWS, GCP, Azure, etc…)
Core Competencies Required:
  • Knowledge and Application: Complete knowledge and full understanding of areas of specialization, principles and practices within a professional discipline. Assesses unusual circumstances and uses sophisticated analytical and problem solving techniques to identify causes. Resolves and assesses a wide range of issues in creative ways and suggests variations in approach. This job is a fully qualified, experienced professional, journey-level position.
  • Complexity & Problem Solving: Works on problems of diverse scope where analysis of information requires evaluation of identifiable factors. Devises solutions based on limited information and precedent and adapts existing approaches to resolve issues. Uses evaluation, judgment, and interpretation to select the right course of action. Work is done independently and is reviewed at critical points.
  • Collaboration & Interaction: Enhances relationships and networks with senior internal/external partners who are not familiar with the subject matter, often requiring persuasion. Adapts style to different audiences and often advises others on difficult matters.

$150,000 - $173,000 a year

What We Offer:
  • Comprehensive medical, dental, vision, and life insurance.
  • Competitive compensation package and equity.
  • Monthly work from home stipend of $50.
  • Flexible work schedule and paid time off.
  • Collaborative culture with a supportive team.
  • A great place to work with unlimited growth opportunities.
  • The opportunity to make massive contributions at a hyper-growth company.
  • Make an impact on a product helping ship millions of packages per day.
Data Privacy Notice for Job Applicants:

For information on personal data processing, please see our Privacy Policy: https://www.easypost.com/privacy

EasyPost is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.

To be considered for this position, you must be authorized and based in the United States.

If you have any questions or concerns you can reach out to me directly on LinkedIn @KristinaPerna :).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

EasyPost • United States

Remote
USD 150,000 - 173,000
Comprehensive medical, dental, and vision insurance
Competitive compensation package
Monthly work from home stipend
+2
Strategic Partnerships Lead for Global Growth
Strategic Partnerships Lead for Global Growth

Socket.dev • United States

Remote
Staff Software Engineer
Staff Software Engineer

Hard Yaka • United States

Hybrid
USD 182,000 - 238,000
Comprehensive medical, dental, and vision insurance
Flexible work schedule
Monthly work from home stipend
Senior Partnerships Account Executive
Senior Partnerships Account Executive

EasyPost • United States

Hybrid
USD 90,000 - 150,000
Comprehensive medical, dental, vision,
Life insurance
Monthly work from home stipend of $50
+5
Application Security Engineer
Application Security Engineer

Packsize • Salt Lake City (UT)

Hybrid
USD 120,000 - 150,000
Application Security Engineer
Application Security Engineer

Awardco • Lindon (UT)

On-site
USD 140,000 - 170,000
Staff Application Security Engineer
Staff Application Security Engineer

Triwill Group • United States

On-site
USD 120,000 - 145,000
Fully remote work arrangement
Product Security Engineering Manager
Product Security Engineering Manager

Bugcrowd • United States

On-site
USD 176,000 - 242,000
Performance-based bonuses
Product Security Engineering Manager
Product Security Engineering Manager

Bugcrowd • Bedford (NH)

On-site
USD 176,000 - 242,000
Application Security Engineer
Application Security Engineer

Awardco, Inc. • Lindon (UT)

On-site
USD 110,000 - 140,000