Enable job alerts via email!

Staff Application Security Engineer

SPAN

San Francisco (CA)

On-site

USD 160,000 - 215,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a mission-driven company at the forefront of electrification and decarbonization. As a Staff Application Security Engineer, you will play a vital role in enhancing SPAN's application security program. This position involves proactive assessments, threat modeling, and collaboration with development teams to ensure the security of innovative products. With a focus on secure coding practices and a deep understanding of application vulnerabilities, you will help shape the future of renewable energy. If you are passionate about security and want to make a significant impact, this is the opportunity for you.

Benefits

Competitive compensation
Equity grants
100% employee premiums for medical, dental, vision
Parental leave up to six months
Comfortable office space near public transit
Employee Resource Groups
Monthly social events
Unlimited PTO
Flexible hours

Qualifications

  • 7+ years in a security engineering role focused on application security.
  • Deep understanding of web and mobile application vulnerabilities.

Responsibilities

  • Developing application security strategies aligned with company goals.
  • Performing secure design and code reviews to mitigate vulnerabilities.

Skills

Application Security
Secure Coding Practices
Threat Modeling
Web Security
Mobile Security
API Security
Communication Skills
Production-quality Code

Education

Bachelor's Degree in Computer Science
Bachelor's Degree in Cyber Security

Tools

Application Security Scanning Tools
AWS Security Best Practices

Job description

Our Mission
SPAN is enabling electrification for all

SPAN is mission-driven to design, build, and deploy products that electrify our built environment, decarbonize our world, and slow the effects of climate change.

  • Decarbonization is the process to reduce or remove greenhouse gas emissions, especially carbon dioxide, from entering our atmosphere.

  • Electrification is the process of replacing fossil fuel appliances that run on gas or oil with all-electric upgrades for a cleaner way to power our lives.

At SPAN, we believe in:

  • Enabling homes and vehicles powered by clean energy

  • Making electrification upgrades possible

  • Building more resilient homes with reliable backup

  • Designing a flexible and distributed electrical grid

The Role

We are seeking a highly skilled and experienced individual to join our Security & Privacy team at SPAN as a Staff Application Security Engineer. In this critical role, you will be instrumental in building and enhancing SPAN’s application security program. Your responsibilities will ensure the security of our applications through proactive assessment, threat modeling, code reviews, and close collaboration with the development teams. Ideal candidates will have extensive experience in application security, a deep understanding of secure coding practices, and the ability to influence and educate others on security matters.

Responsibilities include:

  • Developing a comprehensive application security strategy aligned with company objectives.

  • Performing secure design and code reviews to identify, mitigate, and prevent security vulnerabilities, enabling SPAN teams to deliver secure, high-quality products.

  • Leading and executing SAST/DAST/SCA efforts.

  • Collaborating closely with development teams to integrate security best practices into the software development lifecycle (SDLC).

  • Performing threat modeling on existing and upcoming feature sets in SPAN applications to ensure appropriate security controls are built from the ground up.

  • Developing and enforcing a robust authentication and authorization posture.

  • Designing, implementing, and maintaining application security controls and solutions, leveraging hands-on coding experience.

  • Ensuring compliance with regulatory requirements and industry standards including risk assessments and risk mitigation strategies for application security.

  • Staying current with the latest application security threats, vulnerabilities, and best practices. Continuously evaluating and improving application security processes and technologies.

About You

  • Bachelor’s Degree in Computer Science, Information Assurance, Cyber Security, or related field of study.

  • 7+ years of experience in a security engineering or operations role, with a focus on application security.

  • Deep understanding of web and mobile application vulnerabilities and defenses.

  • Hands-on experience with one or more application security scanning tools.

  • Expertise in web, mobile, and API security.

  • Ability to effectively communicate with technical and non-technical audiences.

  • Proficient in writing production-quality code in one or more languages such as Python, Kotlin, or NodeJS.

  • Experience in developing threat models (e.g., STRIDE, DREAD).

Nice-to-Have

  • Hands-on experience with AWS Security best practices.

  • Experience with vulnerability management.

  • Certifications such as CISSP, CSSLP, or relevant industry certifications.

The U.S. base salary range for this position is $160,000 - $215,000, plus benefits and equity. This range represents SPAN’s good faith estimate of a competitively-priced salary for the role based on national, real-time industry data from companies of a similar growth stage. This range reflects minimum and maximum new hire salaries for the role in San Francisco county. Within this range, individual pay is determined by location and individual factors including relevant skills, experience, and education or training. This range correlates to the relative level of the candidate we believe we need for the role and may require an adjustment for candidates of a different level.

Your recruiter can share more about the specific salary range for the location this role is based during the hiring process.

Life at SPAN

Headquartered in San Francisco’s vibrant SoMa neighborhood, we are an eclectic group of creative thinkers who value open communication, teamwork, and a ‘make it happen’ approach to addressing complex challenges.

SPAN embraces diversity and equal opportunity in a serious way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills.

We’re hiring talented individuals who are driven by success and are passionate about shaping the future of renewable energy. If that sounds like you, we’d love for you to consider joining the rapidly growing team at SPAN.

The Perks:

Competitive compensation + equity grants at a well-funded, venture-backed company.

Comprehensive benefits: 100% employee premiums for base plans on medical, dental, vision with options for additional coverage. Parental leave up to six (6) months depending on eligibility.

Comfortable, sunny office space located near BART and Caltrain public transit.

Strong focus on team building and company culture: Employee Resource Groups, monthly social events, SPANcakes recognition breakfast, lunch and learns.

Flexible hours, one holiday per month, and unlimited PTO.

Interested in joining our team? Submit an application today and we’ll be in touch with next steps!

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Staff+ Application Security Engineer

Verkada

San Mateo

On-site

USD 200,000 - 300,000

11 days ago

Staff, Application Security Engineer

Twilio

Remote

CAD 143,000 - 178,000

30+ days ago

Staff Application Security Engineer

IDENTIFY SECURITY

San Francisco

On-site

USD 120,000 - 180,000

30+ days ago

Staff Security Engineer Pasadena, California, United States; Remote; San Francisco, California,[...]

Primer

San Francisco

Remote

USD 175,000 - 235,000

30+ days ago

Staff Security Engineer

Mozilla

Remote

USD 138,000 - 217,000

6 days ago
Be an early applicant

Senior/Staff Application Security Engineer

Crusoe

San Francisco

Hybrid

USD 180,000 - 300,000

17 days ago

Staff Security Engineer

Cadence

Remote

USD 180,000 - 220,000

8 days ago

Staff Security Engineer Remote US

Mozilla Corporation

Remote

USD 138,000 - 217,000

7 days ago
Be an early applicant

Staff Security Engineer

Multi Media LLC

Remote

USD 175,000 - 240,000

8 days ago