At iHerb, we believe that living a healthy and balanced life should be easy and accessible to everyone. As a team member, you’ll empower this promise each day while making a truly global impact in your career. We constantly strive for innovation, transforming and improving the online shopping experience for our customers. Whether you work in a logistics center, technology hub, corporate office, or from home, your role will take you beyond expectations, turning challenges into change.
Responsibilities
- Lead cross‑functional projects and establish cutting‑edge security development lifecycle practices.
- Direct security design reviews and threat modeling for new and existing services at iHerb.
- Evaluate, prototype, implement, and operate security‑focused tools and services.
- Create secure architecture standards, frameworks, and patterns spanning multiple layers.
- Discover and analyze emerging security threats, determining applicability to iHerb, and proactively implement centralized mitigations.
- Maintain knowledge of current security threats and operational best practices.
- Drive security assessment, penetration testing, and bug bounty programs.
- Participate in security incident response.
Qualifications
- Demonstrated technical foundation (Computer Science / Engineering degree or equivalent experience) with the ability to translate technical vulnerabilities into organizational risks.
- 8+ years of technical security leadership at a top‑tier software company, including experience with security products, threat modeling, security design, security architecture, cryptography, mobile security, and cloud computing technologies.
- Solid understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE, etc.).
- Proficiency implementing SDL process, technology, and automation in a DevOps environment.
- Experience with large‑scale web applications and microservices, including API design, access management, authorization, authentication, data protection, and encryption.
- Knowledge of major programming languages and frameworks (e.g., Python, C# .NET, JavaScript, Node.js, Java).
- Excellent problem‑solving, critical thinking, collaboration, and communication skills.
- Bonus: Experience with Cloudflare security, AWS VPCs, EC2 instances, and Docker.
- Ability to drive data‑driven decisions with great attention to detail and deliver KPIs.
- Experience driving application security training, security champions, and awareness campaigns.
- Active contributor to the security community (research, open source, publications…) with the ability to attract and hire great talent.
- Must reside in the Pacific Standard Time zone and be able to work fully remotely within the United States.
Compensation: Expected salary range of $177,000.00–$225,000.00 USD, subject to experience, education, location, and internal equity.
iHerb is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. We provide equal employment opportunities and prohibit discrimination and harassment.