Security Engineer II Remote US

Spotnana

Northern (KY)

Hybrid

USD 110,000 - 147,000

Full time

24 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Equity in stock options
Pre-tax and Roth 401(k) with 4% match
Comprehensive medical/dental/vision/l0
Flexible spending accounts
Flexible PTO + 10 holidays + year-end休
Parental Leave up to 26 weeks
Stipend for cell phone and internet
IATAN travel membership
Pet insurance
Financial wellness tools
Calm app access

Job summary

Spotnana is seeking a Security Engineer II to join our global Security team. This hands-on role focuses on application security, expanding our secure SDLC, owning API security and penetration testing, and advocating best practices across our codebase.

You’ll work closely with Engineering and Product teams to deliver secure, scalable solutions while communicating the business value of reducing risk. Ideal candidates have a strong engineering background, 3+ years of web/mobile security experience,

Qualifications

  • 3+ years of web and mobile application security assessment experience.
  • Experience securing Java-based, API-driven microservices deployed in a cloud environment.
  • Experience implementing secure SDLC practices and automations (SAST, DAST, RAST, IAST).
  • Ability to write code in one or more programming languages.

Responsibilities

  • Conduct application-level security assessments (threat modeling, code reviews, penetration testing) of internal tools and Spotnana web/mobile apps.
  • Provide guidance for bug-fixes on issues found via customer reports, internal testing, tools, or external pentests.
  • Incorporate AI tools to accelerate detection and address vulnerabilities.
  • Develop API security best practices and implement related controls.
  • Implement SAST, DAST, RAST, IAST to identify security bugs earlier in release cycles.
  • Deliver security training and awareness for R&D teams.

Skills

Threat modeling
Code reviews
Penetration testing
API security
Security reviews
Security tooling
Automation

Education

Bachelor's degree in Computer Science

Tools

React
Java
Cloud (AWS/Azure)

Job description

We are Spotnana. We’re on a mission to modernize the infrastructure of the $11.7 trillion travel industry to power the perfect trip for travelers everywhere. Our Travel-as-a-Service platform is designed to make every trip better, whether someone is booking for work or leisure travel, building a travel tool, or looking to offer personalized experiences at scale.

We’re not just modernizing tech, we’re rethinking how the industry works. And to get there, we’re bringing together innovative, ambitious, and open-minded people who want to build something that lasts.

At Spotnana, our values and principles guide how we work and grow together:

  • Build the future – We are leaders, we are innovators, we are ambitious.
  • Commit to excellence – We’re accountable, we are partners, we are agile.
  • Stronger together – We lead with respect and integrity, we are inclusive, we are lifelong learners.
The opportunity ahead

Spotnana is seeking an Security Engineer II to join our global Security team. As an Security Engineer II focused on Application Security, you will be responsible for improving Spotnana’s security and privacy position across our platform. As a hands-on engineer, you will work closely with Spotnana Engineering and Product teams to expand our secure SDLC, own our API security and penetration testing processes, and advocate for best-practices across our codebase including incorporation of security reviews earlier in our development cycle. The ideal candidate has a strong engineering background and is passionate about working cross-functionally with R&D teams to deliver secure, scalable solutions while being able to describe the business value provided by reducing risks.

How you'll help us build
  • Conduct application level security assessments (threat modeling, code reviews, penetration testing) of both internal tools and external Spotnana web and mobile applications
  • Provide supporting guidance for bug-fixes on issues found through various channels (customer reported, internal testing, tools, external pen tests etc)
  • Incorporate AI tools to accelerate our ability to detect and address application security vulnerabilities
  • Develop API Security best practices
  • Implement SAST, DAST, RAST, IAST and related tools to identify security bugs earlier in the release cycle
  • Deliver training and awareness forR&D on security issues
  • Be part of incident response team where application level context and triage is necessary to contain an issue
  • Collaborate with security compliance functions to align technical controls with compliance requirements
Experience you bring
  • 3+ years of previous web and mobile application security assessment experience
  • Experience securing Java-based, API -driven microservices deployed in a cloud environment
  • Experience with React (JS) for frontend and Java for backend services
  • Previous experience implementing secure SDLC practices, and automations such as SAST, DAST, RAST, IAST in at least medium scale software development organizations
  • Ability to write code in one or more programming languages
What to expect next

Selected candidates will participate in cross-functional virtual interviews exploring their relevant experience, approach to problem solving, critical thinking, and alignment with Spotnana’s core values. Interviews will include face-to-face conversations as well as coding exercises to demonstrate your ability.

Work Authorization

This position is not eligible for employment-based visa sponsorship. Candidates must be legally authorized to work in the United States and must not require current or future employment sponsorship.

Let’s talk compensation

Spotnana strives to offer fair, industry-competitive, and equitable compensation. Our total compensation package includes base salary, an annual performance bonus, company equity, and comprehensive benefits . We use trusted third-party market data to establish compensation ranges that are competitive for the role, industry, company size, and geographic market, while maintaining internal equity across our team.

Compensation is determined based on a variety of factors, including skills, experience, qualifications, and work location. The anticipated annual base salary hiring ranges for this role are:

  • California, New Jersey, Washington, New York, Washington, D.C., Massachusetts, Connecticut: $120,500-$163,000
  • All other U.S. states: $109,500-$147,000
Actual compensation may vary based on individual qualifications and the applicable geographic market.

We care for the people who make everything possible - our benefits offerings include:

  • Equity in the form of stock options, which provides partial ownership in the company, so you can share in the success of the company as it grows
  • Pre-tax and ROTH 401(k) options via Fidelity with up to a 4% company match
  • Comprehensive benefit plans covering medical, dental, vision, life, and disability effective on your hire date. We cover 100% of your employee premiums and 85% of your eligible dependents
  • Pre-tax flexible spending account options for health, dependent care, and commuter expenses
  • Flexible PTO in addition to 10 company holidays and an end-of-year company shutdown
  • Up to 26 weeks of Parental Leave
  • Monthly cell phone/internet stipend
  • Extra perks - IATAN travel membership, pet insurance, financial wellness tools, Calm app access, and more

We are committed to fostering a diverse, inclusive environment and to encourage these values in everyone on our team. We provide an environment of mutual respect where opportunities are available without regard to race, color, religion, sex, pregnancy (including childbirth, lactation and related medical conditions), national origin, age, physical and mental disability, marital status, sexual orientation, gender identity, gender expression, genetic information (including characteristics and testing), military and veteran status, and any other characteristic protected by applicable law. We believe that diversity and inclusion for people from all walks of life is key to our success as a company.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Security Engineer II — App Security & API
Remote Security Engineer II — App Security & API

Spotnana • Northern (KY)

Hybrid
USD 110,000 - 147,000
Equity in stock options
Pre-tax and Roth 401(k) with 4% match
Comprehensive medical/dental/vision/l0
+8
Customer Experience (CX) Enablement Specialist
Customer Experience (CX) Enablement Specialist

Spotnana • United States

Remote
USD 57,000 - 85,000
Equity in stock options
Pre-tax and ROTH 401(k) options with 4
Comprehensive medical/dental/vision/li
+6
Security Operations Engineer (Europe - Remote)
Security Operations Engineer (Europe - Remote)

SpotMe • Indiana

Remote
USD 81,000 - 139,000
Sr. Security Engineer
Sr. Security Engineer

ButterflyMX, Inc. • United States

Remote
USD 170,000 - 200,000
Medical, Dental and Vision plans
401(k) plan with a match
Paid holidays and vacation
+4
Application Security Engineer
Application Security Engineer

Omnissa • Time (IL)

On-site
USD 112,000 - 186,000
Employee ownership
Health insurance
401k with matching contributions
+3
Technical Compliance Analyst New New York City, NY (Hybrid); San Francisco, CA (Hybrid)
Technical Compliance Analyst New New York City, NY (Hybrid); San Francisco, CA (Hybrid)

Snorkel AI, Inc. • New York (NY)

On-site
USD 120,000 - 185,000
Security Scientist
Security Scientist

United States Digital Space LLC • United States

Remote
USD 140,000 - 348,000
Health, dental, and vision coverage
Retirement benefits with company/401(k
Parental leave and family planning
+2
Senior Technical Compliance Analyst
Senior Technical Compliance Analyst

Snorkel AI • New York (NY)

On-site
USD 150,000 - 220,000
Senior Application Security Engineer [Remote-US]
Senior Application Security Engineer [Remote-US]

Quanata • United States

On-site
USD 220,000 - 350,000
Monthly wellness allowance
401(k) plan with company match
Professional development budget of $5,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

Inmar Inc. • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+2