Staff Engineer, Product Security
5 months ago
Grubhub is seeking a seasoned Staff-level Software Engineer to design, develop, and maintain security infrastructure and tools to protect the company's platform and data. Grubhub is in growth-mode and we need standardized processes and tools that can be scaled across the organization, to ensure that security measures keep up with the pace of the business. You will work closely with cross-functional teams, including software engineering (FE + BE), IT, and SRE, to ensure our security practices are robust and scalable. Your expertise will help us achieve our goal of building secure, resilient, and efficient systems. A key part of your role will be to develop and maintain "paved roads" for security, creating standardized and streamlined paths that make secure practices the easiest and most efficient options for our teams. This role reports directly to the head of cybersecurity with broad latitude to work with both senior and new-grad engineers to make a measurable impact on Grubhub’s security posture.
Your Impact
- You will enhance the overall security posture of Grubhub by identifying and mitigating security defects proactively.
- You will contribute to a culture of cybersecurity awareness and continuous improvement within the organization, enabling Grubhub to launch and sustain key business initiatives with minimal risk.
- You will champion high-integrity + high-assurance outcomes in order to ensure the delivery of secure and trustworthy experiences
- You’ll tangibly reinforce our #1 technology philosophy: “security first” by integrating security into the development process from the start, rather than as an afterthought.
What You Will Do
- Identify lacking security-sensitive functionality in Grubhub’s applications and services, translating those control gaps into actionable engineering remediation plans and solutions
- Design, build, deploy and drive adoption of embedded security tooling in conjunction with internal services and platform teams
- Perform threat modeling, design, and code reviews to assess security implications and requirements for the introduction of new security systems and technologies
- Drive initiatives with outside teams to re-engineer existing services to ensure that Grubhub remains resilient against the latest security threats
- Bridge security domain knowledge gaps through technical mentorship of a team of passionate engineers while also delivering uniquely challenging projects.
What we’re expecting you to have
- Bachelor's in Computer Science, Engineering or a related field
- Professional experience of 8+ years in at least two security domains: web security (inclusive of APIs, backends, frontend and microservices), edge/perimeter security, mobile security, cloud security, systems security, or reverse engineering
- 7+ years of industry experience in a software development environment with expert-level proficiency in programming languages like Java, Python, or C++
- Demonstrable experience developing libraries and frameworks that are pre-vetted for security, which developers can use to avoid common vulnerabilities.
- Hands-on experience incorporating security checks and tests into the CI/CD pipeline so that every code change is automatically reviewed for security issues before it is deployed.
- Demonstrable experience in conducting code reviews to identify security deficiencies in how business logic is implemented.
- Experience designing, implementing, and deploying production-quality security engineering systems and incorporating security standards into supporting subsystems as needed.
- Hands-on experience with middleware, message queues, caches, and other related technologies.
- Strong experience in architecture design, high-availability, high-performance, distributed systems and working with 5x9/ zero-downtime systems.
- Demonstrable commitment to engineering and operational excellence–to include development + monitoring of SLOs/SLIs to assure adherence to EOE standards–with direct experience in driving security outcomes within an engineering culture.
- A broad knowledge of attack vectors, exploits and mitigations that work at scale or may be linked together for chained attacks
- Working familiarity with version control systems (Git), issue tracking tools (Jira) and ability to define + support your commitments within an Agile working model.
- Ability to communicate ideas and proposals concisely to a wide-range of audiences
- Ability to author both technical and non-technical documentation on a continuous cadence.
- Ability to fully participate in our on-call rotation as a service owner
What does a strong candidate have?
- Master’s (or Ph.D) in Computer Science, Engineering or a related field
- A security industry-related certification such as Certified Information Systems Security Professional (CISSP) or Offensive Security Certified Professional (OSCP)
- Knowledge of both iOS and Android architecture and development
- Expert-level knowledge within identity and access management security domain, inclusive of role-based access controls, factors-based authentication and identity-based attack (both legacy and emergent) patterns.
- Willingness to participate in incidents as needed as a security SME
- Familiarity with industry-standard threat modeling, risk modeling and vulnerability classification.
- Prior experience leading the design or reconstruction of complex systems, preferably in e-commerce or retail-related fields.
- Deep understanding of the related theories of distributed systems, such as load balancing, distributed transactions, CAP/BASE, etc
- (Bonus) Experience with hardware or embedded device security such as what you would find in a kiosk or a point-of-sale system
And Of Course, Perks
- Flexible PTO. Grubhub employees enjoy a generous amount of time to recharge.
- Health and Wellness. Excellent medical, dental and vision benefits, 401k matching, employee network groups and paid parental leave are just a few of our programs to support your overall well-being.
- Compensation. You'll receive a highly-competitive compensation package with eligibility for generous incentives, bonuses, commission, and RSUs.
- Free Meals. Our employees get a weekly Grubhub credit to enjoy and support local restaurants.
- Social Impact. We believe in giving back through programs like the Grubhub Community Relief Fund, and provide our employees opportunities to support causes that are important to them.
-
Staff Engineer, Security Engineering
2 months ago
chicago, United States Grubhub Full timeGrubhub is seeking a seasoned Staff-level Software Engineer to design, develop, and maintain security infrastructure and tools to protect the company's platform and data. Grubhub is in growth-mode and we need standardized processes and tools that can be scaled across the organization, to ensure that security measures keep up with the pace of the business....
-
Security Operations Engineer
5 days ago
Chicago, United States Iceberg Cyber Security Full timeSecurity Operations Analyst *US Citizens or Green card holders only*Reporting to the SOC Team Lead, we are supporting a global financial organization in Chicago looking to hire a Security Analyst who loves problem solving, has a curious mindset and has the ability to pick up new technology quickly. The role involves performing triage of global security...
-
Security Operations Engineer
3 weeks ago
Chicago, United States Iceberg Cyber Security Full timeSecurity Operations Analyst *US Citizens or Green card holders only* Reporting to the SOC Team Lead, we are supporting a global financial organization in Chicago looking to hire a Security Analyst who loves problem solving, has a curious mindset and has the ability to pick up new technology quickly. The role involves performing triage of global security...
-
Staff Backend Engineer- Security Engineering
1 month ago
Chicago, United States Grubhub Full timeGrubhub is seeking a Staff Software Engineer to join our Product Security team.As a member of our team you will help us analyze, design and build security technology into our products and services in order to enable trustworthy experiences for Grubhub’s diners, merchants, drivers and employees. You will dig into the complex world of building security...
-
Staff Backend Engineer- Security Engineering
1 month ago
chicago, United States Grubhub Full timeGrubhub is seeking a Staff Software Engineer to join our Product Security team.As a member of our team you will help us analyze, design and build security technology into our products and services in order to enable trustworthy experiences for Grubhub’s diners, merchants, drivers and employees. You will dig into the complex world of building security...
-
Security Operations Engineer
3 weeks ago
Chicago, United States Iceberg Cyber Security Full timeSecurity Operations Analyst *US Citizens or Green card holders only* Reporting to the SOC Team Lead, we are supporting a global financial organization in Chicago looking to hire a Security Analyst who loves problem solving, has a curious mindset and has the ability to pick up new technology quickly. The role involves performing triage of global security...
-
chicago, United States Iceberg Cyber Security Full timeSecurity Operations Analyst *US Citizens or Green card holders only* Reporting to the SOC Team Lead, we are supporting a global financial organization in Chicago looking to hire a Security Analyst who loves problem solving, has a curious mindset and has the ability to pick up new technology quickly. The role involves performing triage of global security...
-
chicago, United States Iceberg Cyber Security Full timeSecurity Operations Analyst *US Citizens or Green card holders only* Reporting to the SOC Team Lead, we are supporting a global financial organization in Chicago looking to hire a Security Analyst who loves problem solving, has a curious mindset and has the ability to pick up new technology quickly. The role involves performing triage of global security...
-
Product Manager
3 weeks ago
Chicago, Illinois, United States SpotOn: Product Full timeWelcome to a career-defining opportunity at SpotOn: Product, where you will play a pivotal role in shaping the future of payment solutions.Job OverviewWe are seeking an experienced Product Manager who is passionate about the payments industry, building innovative products, and making a significant impact on a wide range of businesses in the hospitality...
-
chicago, United States Grubhub Full timeGrubhub is seeking a Staff Software Engineer to join our Product Security team.As a member of our team you will help us analyze, design and build security technology into our products and services in order to enable trustworthy experiences for Grubhub’s diners, merchants, drivers and employees. You will dig into the complex world of building security...
-
Engineering Director
1 week ago
Chicago, Illinois, United States SpotOn: Product Full time**Job Description:**We're seeking an experienced Engineering Manager to lead our software engineering team in delivering high-quality products that meet the needs of our customers. As a key member of our team, you'll be responsible for providing technical direction and leadership on software development projects.About the Company:SpotOn is a technology...
-
Staff Software Engineer
3 months ago
Chicago, United States Grubhub Full timeGrubhub is seeking a Staff Software Engineer to join our Product Security team. As a member of our team you will help us analyze, design and build security technology into our products and services in order to enable trustworthy experiences for Grubhub’s diners, merchants, drivers and employees. You will dig into the complex world of building security...
-
Staff Software Engineer
2 months ago
chicago, United States Grubhub Full timeGrubhub is seeking a Staff Software Engineer to join our Product Security team. As a member of our team you will help us analyze, design and build security technology into our products and services in order to enable trustworthy experiences for Grubhub’s diners, merchants, drivers and employees. You will dig into the complex world of building security...
-
Information Security Operations Specialist
2 days ago
Chicago, Illinois, United States Iceberg Cyber Security Full timeIceberg Cyber Security is seeking an Information Security Operations Specialist to join our team. This position offers a competitive salary of around $90,000 to $125,000 per year.In this role, you will be responsible for analyzing security alerts to identify and respond to incidents, managing internal support tickets, and creating threat detections. You will...
-
Security Engineer
2 weeks ago
Chicago, United States OpenGov Full timeOpenGov is home to an exceptional team - passionate about our mission to power more effective and accountable government. By bringing the OpenGov Cloud to our nation‘s state and local government, we‘re transforming communities so they can thrive! Imagine yourself being able to help small business owners open their doors faster, ensuring our tax dollars...
-
Senior Security Engineer
2 months ago
Chicago, United States Democorp Full timeOverview: The Senior Security Engineer works in Optiv's 24x7x365 Security Operations Center as a member of the Managed Security Services team. The Senior Security Engineer uses technical knowledge on a number of security technologies to analyze and respond to security threats from various security platforms and technologies. The Senior Security Engineer...
-
Senior Product Security Strategist
2 weeks ago
Chicago, Illinois, United States Humana Inc. Full timeAbout the RoleWe are seeking a seasoned Senior Product Security Strategist to join our team at Humana Inc. This is a high-profile position that requires strong leadership and technical expertise in product security.Job SummaryThe successful candidate will be responsible for defining the strategy for product and data security, supporting all Humana business...
-
Production Support Engineer
2 weeks ago
Chicago, United States Mastech Inc. Full timeMastech Digital is an IT Staffing and Digital Transformation Services company. Mastech Digital provides digital and mainstream technology staff as well as Digital Transformation Services for all American Corporations. We are currently seeking a Production Support Engineer for our client in the IT-Services/Consulting domain. We value our professionals,...
-
Senior Software Engineer
2 weeks ago
Chicago, United States SpotOn: Product Full timeJob DescriptionJob DescriptionAt SpotOn, we're helping restaurants and small businesses compete and win with flexible payment and software technology—backed by real people who really care. From seamless point-of-sale systems to integrated restaurant management solutions, every SpotOn tool is designed to help local businesses increase profits and create...
-
Chicago, Illinois, United States SpotOn: Product Full timeJob DescriptionAt SpotOn, we're pushing the boundaries of innovation in restaurant and small business software technology. We empower local businesses to increase profits and deliver exceptional customer experiences through our seamless point-of-sale systems and integrated management solutions.We've received recognition for our efforts, including:Fast...