What You’ll Do
Engineer, implement and monitor security measures for the protection of computer systems, networks, and information
Prepare, maintain and document standard operating procedures and protocols
Configure and troubleshoot security infrastructure systems
Develop and maintain technical solutions and security tools to help mitigate security vulnerabilities and automate repeatable tasks
Work closely with technical leads to collate, drive and deliver on a technical strategy and roadmap that encompasses product, cloud, and enterprise security
Assist with security reviews, threat modeling, code reviews
Assist with our vulnerability management efforts across functional teams (enterprise and application security) to ensure we meet our SLAs and help mitigate risks
Be an advocate for security best practices and the point of contact throughout the company
Any other tasks that may be assigned to help the company meet its goals
What You’ll Bring
8+ years of experience with auditing web applications.
3+ years using at least one high level programming language e.g. Node.js, Python, Go, Java, Ruby.
Experience utilizing web application security scanning software and penetration testing tools e.g. Burp Suite, ZAP, Nessus, Qualys, Metasploit, CANVAS, Nuclei, Cobalt Strike.
Experience and desire conducting Security training for developers and the security team.
Experience performing threat modeling and secure design review in order to assess the security implications and requirements of new systems and technologies.
Experience building or working with distributed multi-tier web server-client architectures.
Experience with cloud environments AWS or Azure.
Strong foundational understanding of network and application fundamentals and best practices; e.g. HTTP, DNS, VPN, SAML, OAuth, OpenID etc.
Strong understanding of OWASP Top 10 vulnerabilities in web applications, including XSS, SSRF, IDOR, RCE, CSRF vulnerabilities.
Working knowledge of the Microsoft Security Development Lifecycle (SDL), OWASP Software Assurance Maturity Model (SAMM), or Building Security in Maturity Model (BSIMM)
Experience implementing security practices in automated CI/CD pipelines for application code, infrastructure, and/or serverless is a plus.
Strong sense of ownership, urgency and drive.
Strong ability to lead cross-team initiatives and communicate proposals and ideas concisely.
Preferred Qualifications:
- Certifications: OSCP, OSWA, OSWE, or Burp Suite Certified Practitioner (BSCP).
- Programming: Strong programming skills in NodeJS, Python, and/or Go.
- Cloud Fluency: Experience securing applications specifically within AWS environments (Lambda, ECS/EKS, DynamoDB security).
- Compliance: Familiarity with mapping technical application controls to compliance frameworks like SOC 2, HIPAA, or PCI-DSS.
Skills Required
- 8+ years of experience with auditing web applications
- 3+ years using at least one high-level programming language e.g. Node.js, Python, Go, Java, Ruby
- Experience utilizing web application security scanning software and penetration testing tools
- Experience and desire conducting Security training for developers and the security team
- Experience performing threat modeling and secure design review
- Experience building or working with distributed multi-tier web server-client architectures
- Experience with cloud environments AWS or Azure
- Strong foundational understanding of network and application fundamentals and best practices
- Strong understanding of OWASP Top 10 vulnerabilities in web applications
- Working knowledge of the Microsoft Security Development Lifecycle (SDL)
- Experience implementing security practices in automated CI/CD pipelines
- Certifications: OSCP, OSWA, OSWE, or Burp Suite Certified Practitioner (BSCP)
FloQast Compensation & Benefits Highlights
-
Healthcare Strength — Health coverage includes multiple medical plan options with some 100% employer‑paid, plus dental/vision, mental‑health access, and income‑protection coverage. Options are described as generous, with fully paid plans available for employees and in some cases families.
-
Parental & Family Support — Parental support features paid leave commonly cited around 16 weeks for birthing parents, alongside fertility benefits via Carrot and a subsidized SNOO rental. Adoption assistance and broader family‑forming support are also referenced as part of the package.
-
Leave & Time Off Breadth — Time away includes an unlimited PTO framework, generous vacation and sick time, and company‑wide Catch‑Up Days to recharge. Additional paid holidays and flexible time off constructs are highlighted.
FloQast Insights
What We Do
By automating and streamlining common accounting workflows to make them more efficient, FloQast is where accounting teams want to work so they can focus on what matters most, even when that’s just logging off on time. Whether automating reconciliations, documentation requests, or streamlining recurring accounting processes, such as the month-end close, financial reporting, or payroll, FloQast's platform enhances the way accounting teams already work to help them operate more efficiently.
Why Work With Us
Our cloud-based, AI-enhanced software is trusted by more than 3,000 accounting teams, including those at Twilio, Gong, Instacart, and The Golden State Warriors - and still growing! We aspire to forever elevate accounting and improve both the practice and perceptions of the profession.
Gallery
FloQast Teams
FloQast Offices
Remote Workspace
Employees work remotely.
FloQast's Employee Choice policy allows employees to choose to be hybrid or remote!

%20(1).jpg)



%20(1).jpg)






