Staff Application Security Engineer

Posted 4 Days Ago
Be an Early Applicant
San Francisco, CA, USA
Hybrid
170K-190K Annually
Mid level
Information Technology • Consulting
The Role
Lead application security efforts across product and platform teams by performing security assessments, vulnerability testing, code reviews, threat modeling, and CI/CD integration. Collaborate with SRE, development, IT, and risk teams to remediate vulnerabilities, implement secure coding practices, provide training, and drive security process improvements. Mentor engineers and stay current on threat techniques and protective controls.
Summary Generated by Built In

Ironclad is the leading AI contracting platform that transforms agreements into assets. Contracts move faster, insights surface instantly, and agents push work forward, all with you in control. Whether you’re buying or selling, Ironclad unifies the entire process on one intelligent platform, providing leaders with the visibility they need to stay one step ahead. That’s why the world’s most transformative organizations, from Rivian to the World Health Organization and the Associated Press, trust Ironclad to accelerate their business.


We’re consistently recognized as a leader in the industry: a Leader in the Forrester Wave and Gartner Magic Quadrant for Contract Lifecycle Management, a Fortune Great Place to Work, and one of Fast Company’s Most Innovative Workplaces. Ironclad has also been named to Forbes’ AI 50 and Business Insider’s list of Companies to Bet Your Career On. We’re backed by leading investors including Accel, Y Combinator, Sequoia, BOND, and Franklin Templeton. For more information, visit www.ironcladapp.com or follow us on LinkedIn.

This is a hybrid role. Office attendance is required at least twice a week on Tuesdays and Thursdays for collaboration and connection. There may be additional in-office days for team or company events.

Ironclad is seeking an experienced Application Security Engineer with a passion for securing modern software platforms and protecting sensitive data. We are looking for someone with strong experience in automated vulnerability scanning and penetration testing to strengthen our application security program. Whether you are better at building software or better at breaking it, we are interested in hearing from you. We welcome security researchers and strong developers, as well as past security engineers.

This role will be responsible for conducting security assessments, identifying and mitigating risks, and implementing security best practices and process improvements across Ironclad’s Product, Platform and Engineering teams.

Roles & Responsibilities:

  • Develop and implement secure coding practices, procedures, and standards for software development teams.

  • Conduct application security assessments and vulnerability testing to identify and mitigate risks.

  • Perform security reviews of code changes and ensure that security issues are addressed.

  • Collaborate with cross-functional teams to remediate software vulnerabilities and implement secure coding practices.

  • Integrate security review processes into Ironclad’s CI/CD pipeline.

  • Conduct threat modeling and risk analysis to protect sensitive data.

  • Provide domain expertise on protective controls including system, network, encryption, and authentication services.

  • Work closely with members of the SRE, Development, IT, and Security teams to drive impactful changes to Ironclad’s cybersecurity posture.

  • Work closely with the risk and governance teams to implement compliance and security requirements.

  • Contribute to secure coding and other cybersecurity training programs.

  • Stay up-to-date with the latest security trends, vulnerabilities, and attack techniques.

  • Provide technical leadership and mentorship to other members of the engineering and security teams.

Key Skills:

  • Strong proficiency in either Typescript or Javascript.

  • 3+ Years of experience working in application security or software development, preferably with SaaS companies or in regulated fields.

  • In-depth knowledge of application security concepts and practices, including OWASP Top 10 and SANS Top 25.

  • Experience with security testing tools such as Burp Suite, AppScan, and Nessus.

  • Experience operating in any cloud provider (AWS, GCP, Azure, Digital Ocean etc.).

  • Ability to appropriately prioritize and respond to different escalations.

  • Experience working collaboratively with cross-functional teams.

  • Strong desire to take ownership of problems.

  • Comfort working in a rapidly evolving environment and dealing with ambiguity.

  • Excellent communication, analytical and problem-solving skills.

  • Team and goal-oriented.

  • High output, low ego.

Nice to Have:

  • AI penetration testing.

  • Experience with git and software branching and workflow strategies.

  • Experience working with modern, microservice architectures including in Kubernetes or other containerized environments.

  • Experience with enterprise observability platforms such as ELK, Datadog, Prometheus, Grafana, etc.

  • Knowledge of Terraform or other infrastructure-as-code and configuration management solutions.

  • Experience with SOC 2, ISO 27001, NIST, and CIS standards and frameworks.

  • Experience with SAST and SCA tools such as Snyk, Checkmarx, Veracode, WhiteSource, or Black Duck.

Base Salary Range: $170,000 - $190,000 offers company bonus

The base salary range represents the minimum and maximum of the salary range for this position based at our San Francisco headquarters. The actual base salary offered for this position will depend on numerous factors, including individual proficiency, anticipated performance, and the location of the selected candidate. Our base salary is just one component of Ironclad’s competitive total rewards package, which also includes equity awards (a new hire grant, along with opportunities for additional awards throughout your tenure), competitive health and wellness benefits, and a commitment to career growth and development.


US Full-Time Employee Benefits at Ironclad:

  • 100% health coverage for employees (medical, dental, and vision), and 75% coverage for dependents with buy-up plan options available

  • Market-leading leave policies, including gender-neutral parental leave and compassionate leave

  • Family forming support through Maven for you and your partner

  • Paid time off - take the time you need, when you need it

  • Monthly stipends for wellbeing, hybrid work, and (if applicable) cell phone use

  • Mental health support through Modern Health, including therapy, coaching, and digital tools

  • Pre-tax commuter benefits (US Employees)

  • 401(k) plan with Fidelity with employer match (US Employees)

  • Regular team events to connect, recharge, and have fun

  • And most importantly: the opportunity to help build the company you want to work at

**UK Employee-specific benefits are included on our UK job postings

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Skills Required

  • Strong proficiency in Typescript or Javascript
  • 3+ years of experience in application security or software development
  • In-depth knowledge of OWASP Top 10 and SANS Top 25
  • Experience with security testing tools such as Burp Suite, AppScan, and Nessus
  • Experience operating in cloud environments (AWS, GCP, Azure, Digital Ocean, etc.)
  • Conduct application security assessments, vulnerability testing, and penetration testing
  • Perform security code reviews and integrate security into CI/CD pipelines
  • Conduct threat modeling and risk analysis to protect sensitive data
  • Provide domain expertise on protective controls including encryption and authentication
  • Collaborate cross-functionally with SRE, Development, IT, Security, risk and governance teams
  • Provide technical leadership and mentorship to engineering and security team members
  • Excellent communication, analytical, and problem-solving skills; ability to prioritize escalations
  • AI penetration testing
  • Experience with git and branching/workflow strategies
  • Experience with modern microservice architectures and containerized environments (Kubernetes)
  • Experience with observability platforms (ELK, Datadog, Prometheus, Grafana)
  • Knowledge of Terraform or other infrastructure-as-code/configuration management
  • Experience with SOC 2, ISO 27001, NIST, and CIS standards and frameworks
  • Experience with SAST and SCA tools (Snyk, Checkmarx, Veracode, WhiteSource, Black Duck)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
543 Employees
Year Founded: 2014

What We Do

Digitize your contracts with Ironclad, the world’s #1 Contract Lifecycle Management (CLM) platform. Ironclad is the simple, secure way to create and collaborate on contracts, giving users a modern, all-in-one, customizable experience. Every company runs on contracts, but managing these contracts slows companies down and costs them millions of dollars. L’Oréal, Staples, Mastercard, and other leading innovators use Ironclad to collaborate and negotiate on contracts, accelerate contracting while maintaining compliance. It’s the only platform flexible enough to handle every type of contract workflow: sales agreements, HR agreements, complex NDAs, and more. Ironclad recently reached a $3.2B Valuation with a $150M Series E Investment round. Ironclad’s innovation and work culture has been recognized by Forbes’ 50 Most Promising AI Companies in 2021, Fortune’s Best Small & Medium Workplaces 2021, One of 25 Highest-Rated Cloud Computing Company Employers by Battery Ventures and Glassdoor, Fast Company’s 2020 Best Workplaces for Innovators, Glassdoor’s best Machine Learning startup, Enterprise Tech 30 List, and is backed by leading investors like Accel, Y Combinator, Sequoia, and Bond. For more information, visit www.ironcladapp.com or follow us on LinkedIn and Twitter.

Similar Jobs

Nclusion Logo Nclusion

Application Security Engineer

Fintech • Software • Financial Services
Hybrid
Palo Alto, CA, USA
21 Employees
200K-260K Annually

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Associate I

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Commerce, CA, USA
16000 Employees
15-24 Hourly

Golden Hippo Logo Golden Hippo

Visual Design Intern

Digital Media • eCommerce • Information Technology • Marketing Tech • Retail • Social Media • Analytics
Hybrid
Woodland Hills, CA, USA
500 Employees
18-20 Hourly

Toast Logo Toast

Account Executive

Cloud • Fintech • Food • Information Technology • Software • Hospitality
In-Office
Livermore, CA, USA
5000 Employees
148K-237K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account