Security Engineer

Posted 10 Hours Ago
Be an Early Applicant
Denver, CO, USA
Hybrid
115K-130K Annually
Mid level
eCommerce • Mobile • Payments
Make Every Purchase Rewarding
The Role
Perform application security assessments (code review, pentesting), integrate SAST/DAST/SCA into CI/CD, lead threat modeling, secure AI/ML code and model endpoints, manage cloud/container security (AWS/GCP), automate IaC security checks, mature bug bounty, and participate in incident response and on-call rotation.
Summary Generated by Built In

Ibotta is seeking a Security Engineer with a deep expertise in Application Security, Vulnerability Management, and Cloud Infrastructure to join our innovative team and contribute to our mission to Make Every Purchase Rewarding. In this role, you will be ensuring the security of our software development lifecycle (SDLC) and our cloud-native environments. A key focus of this position will be addressing the emerging security challenges posed by Artificial Intelligence (AI) technologies, specifically around secure AI coding practices and the infrastructure that supports AI/ML workloads.

 

This position is located in Denver, Colorado as a hybrid position requiring 3 days in office (Tuesday, Wednesday, and Thursday). Candidates must live in the United States.

 

Not based in Denver? We will offer a relocation bonus to help make your move to the Mile High City a smooth one.

 
What you will be doing:
  • Perform application security assessments, including manual code reviews and penetration testing.

  • Mature Ibotta’s bug bounty program to scale with AI generated submissions and attack surface.

  • Analyze Ibotta's application architecture to identify weaknesses and develop opportunities for improvement.

  • Integrate and manage SAST, DAST, and SCA tools within the CI/CD pipeline.

  • Lead threat modeling for new application features with key stakeholders across mobile, platform, infrastructure and AI enablement.

  • Develop and maintain secure coding practices, provide training to developers.

  • Work with Ibotta’s engineering team to design, implement, and monitor runtime and container security controls across cloud platforms (AWS/GCP).

  • Automate infrastructure security checks using Infrastructure as Code (IaC) scanning tools.

  • Evaluate the security of AI-generated code and implement guardrails for model-serving endpoints in the development process.

  • Stay ahead of the curve on AI-specific threats such as prompt injection, data poisoning, and model inversion.

  • Participate in a 24/7 on-call rotation and incident response.

  • Embrace and uphold Ibotta’s Core Values: Integrity, Boldness, Ownership, Teamwork, Transparency & A Good Idea Can Come from Anywhere

 
 
What we are looking for:
  • 4+ years in security engineering, application development, or application security.

  • Proficiency in languages like Python, Go, or Java; experience with Docker/Kubernetes.

  • Basic knowledge of networking security is a plus.

  • Strong knowledge of AWS security services and IaC (Terraform). Experience writing secure IAM policies and other configurations in Terraform a plus.

  • Understanding of Continuous Integrations/Testing/Delivery

  • Strong understanding of Web API security patterns and modern authentication protocols.

  • Familiarity with OWASP Top 10 and implementing technical controls to address vulnerabilities.

  • Working knowledge of web application testing tools.

  • One or some combination of the following are a plus but not required: CompTIA SecAI+, eCPPT, eWPT, GWAPT, OSCP, or similar.

  • Must have the ability to work effectively across the organization/collaborate effectively with both technical and non-technical team members, possess excellent oral & written communications skills, and demonstrate effective problem-solving skills.

  • Experience building custom security tooling or automation scripts.

 
 
 

About Ibotta ("I bought a...")

 

Ibotta (NYSE: IBTA) is a leading performance marketing platform allowing brands to deliver digital promotions to over 200 million consumers through a network of publishers called the Ibotta Performance Network (IPN). The IPN allows marketers to influence what people buy, and where and how often they shop – all while paying only when their campaigns directly result in a sale. American shoppers have earned over $2.6 billion through the IPN since 2012. The largest tech IPO in history to come out of Colorado, Ibotta is headquartered in Denver, and is continually listed as a top place to work by The Denver Post and Inc. Magazine.

 

To learn more about what our Tech teams are doing day to day, visit Building Ibotta on Medium.com.

 

Additional Details:

  • This position is located in Denver, CO and includes competitive pay, flexible time off, benefits package (including medical, dental, vision), Employee Stock Purchase Program, and 401k match. Denver office perks include paid parking, snacks, and occasional meals.

  • Base compensation range: $115,000 - $130,000. Equity is included in overall compensation package. This compensation range is specific to the United States labor market and may be adjusted based on actual experience.

  • Ibotta is an Equal Opportunity Employer. Ibotta’s employment decisions are made without regard of race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, sexual orientation, or any other legally protected status.

  • Applicants must be currently authorized to work in the United States on a full-time basis.

  • Applicants are accepted until the position is filled.

  • For the security of our employees and the business, all employees are responsible for the secure handling of data in accordance with our security policies, identifying and reporting phishing attempts, as well as reporting security incidents to the proper channels.

 

Recruiting Agency Notice
Ibotta does not accept agency resumes and is not responsible for any fees related to unsolicited resumes. Please do not forward resumes to any Ibotta employees.

 

#LI-Hybrid

#BI-Hybrid

Skills Required

  • 4+ years in security engineering, application development, or application security.
  • Proficiency in Python, Go, or Java.
  • Experience with Docker and Kubernetes.
  • Strong knowledge of AWS security services and Infrastructure as Code (Terraform).
  • Experience writing secure IAM policies and other configurations in Terraform.
  • Understanding of Continuous Integration, Testing, and Delivery (CI/CD).
  • Strong understanding of Web API security patterns and modern authentication protocols.
  • Familiarity with OWASP Top 10 and implementing technical controls.
  • Working knowledge of web application testing tools and penetration testing/manual code review experience.
  • Experience building custom security tooling or automation scripts.
  • Ability to participate in a 24/7 on-call rotation and incident response.
  • Ability to collaborate effectively across technical and non-technical teams; strong oral and written communication skills.
  • Applicants must be currently authorized to work in the United States full-time.
  • Willingness/ability to work hybrid in Denver, CO (in-office Tuesday, Wednesday, Thursday).
  • Basic knowledge of networking security.
  • Security certifications such as CompTIA SecAI+, eCPPT, eWPT, GWAPT, OSCP or similar.

What the Team is Saying

Kate
Prachi
Shelby
Mandy
Nick
Tim
Natalie
Tiffany
Minh

Ibotta Compensation & Benefits Highlights

  • Healthcare Strength Healthcare coverage is emphasized and considered solid, spanning medical, dental, vision, and mental‑health support.
  • Leave & Time Off Breadth Flexible time off (including unlimited/FTO) and paid parental leave are included alongside a Denver‑based hybrid work setup.
  • Wellbeing & Lifestyle Benefits Lifestyle perks such as an onsite gym, a recurring dinner perk, wellness stipends/reimbursements, and regular team events add tangible day‑to‑day value.

Ibotta Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Denver, CO
830 Employees
Year Founded: 2012

What We Do

Ibotta (NYSE: IBTA) is a leading performance marketing platform allowing brands to deliver digital promotions to over 200 million consumers through a network of publishers called the Ibotta Performance Network (IPN). The IPN allows marketers to influence what people buy, and where and how often they shop – all while paying only when their campaigns directly result in a sale. American shoppers have earned over $1.8 billion through the IPN since 2012. The largest tech IPO in history to come out of Colorado, Ibotta is headquartered in Denver, and is continually listed as a top place to work by The Denver Post and Inc. Magazine.

Why Work With Us

We help people in a very tangible way – we pay them. The more we give back, the more we earn. We don’t have to choose between doing good and doing well. Our company goals keep us on track as we build a highly profitable business that maximizes a positive impact on the world around us.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Ibotta Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Ibotta empowers our employees to achieve our mission and values from anywhere within the continental U.S. with our flexible hybrid work schedule.

Typical time on-site: Flexible
HQDenver, CO
Currently hybrid - our headquarters are located in central Downtown Denver - convenient access to public transportation and Denver's best restaurants!

Similar Jobs

Ibotta Logo Ibotta

Account Management Director

eCommerce • Mobile • Payments
Remote or Hybrid
Denver, CO, USA
830 Employees
133K-160K Annually

Ibotta Logo Ibotta

Analytics Engineer

eCommerce • Mobile • Payments
Hybrid
Denver, CO, USA
830 Employees
113K-132K Annually

Ibotta Logo Ibotta

Sr. Director, UX

eCommerce • Mobile • Payments
Hybrid
Denver, CO, USA
830 Employees
225K-265K Annually

Ibotta Logo Ibotta

Senior Director, Product Management

eCommerce • Mobile • Payments
Hybrid
Denver, CO, USA
830 Employees
209K-239K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account