Staff Application Security Engineer

5 days ago


California, United States Binti Inc Full time

Binti builds modern software to help every child have a safe, loving, and stable family. Working with county and state governments across 36 states, Binti's tools improve the child welfare system. The 500+ agencies using Binti serve about 42% of children in child welfare in the US, and agencies using Binti have increased the number of approved families by an average of 30%, making a real dent in the shortage of foster/adoptive parents for children in the US. Beyond helping families foster/adopt children, Binti is launching software to support families who are struggling to get the services they need to stay together with or reunify with their children. Binti is a for-profit, mission-driven software company based in Oakland, CA. Investors include Founders Fund, First Round Capital, Kapor Capital, and others. We’re a team of 90+ people and growing quickly. We care about creating a workplace where everyone feels welcome and can bring their full self to work. We have a huge, ambitious vision to rewire government to be more effective in expanding opportunities for people around the world, and we are looking for mission-driven, high-empathy, high-performance, and low-ego team members to join us on our exciting journey towards that vision. OVERVIEW OF ROLE As a Staff Application Security Engineer, you will play a critical role in ensuring the security and integrity of our software applications. You will work collaboratively with cross-functional teams to identify and address potential security vulnerabilities, implement best practices, and contribute to the development of secure coding standards. WHAT YOU WILL DO Conduct Security Assessments:

Provide holistic assessments of Binti’s security stance, including performing regular security reviews, code audits, penetration testing, and threat modeling to maintain the highest standard of application security.

Set Direction:

Help Binti chart a specific course of action to achieve the security stance we desire. This includes scoping and prioritizing work, determining what levels of investment and risk we should take on given our scale and capacity, and building relationships across teams to effectively communicate and advocate for these goals.

Respond To Incidents : Respond promptly to security incidents, collaborate with engineers on-call, and provide detailed post-event analyses. Evaluate the applicability of emergent security concerns through risk rating and assessment (such as OWASP).

Improve Security Architecture:

Work with engineering to identify, design, and implement technologies to enhance security automation, both for the software development lifecycle and cloud hosting environments.

Set Security Standards:

Lead efforts to design and implement secure coding standards and best practices across the development lifecycle, including automating processes as makes sense to ensure comprehensive coverage.

Share Expertise:

Stay up to date on the latest security threats, vulnerabilities, and industry best practices, and ensure the integration of this knowledge into Binti’s security strategies. Act as our company’s expert on application security matters, providing mentorship to development teams and fostering a scalable, security-aware culture.

TECH STACK Ruby on Rails

Redis

Postgres, hosted with GCP

Javascript (React + Node)

Google Cloud

Kubernetes

Pulumi

SAMPLE PROJECTS Review and implement security patches and hotfixes in production applications.

Implement streamlined feedback of security recommendations for new products before launch into the Binti platform.

Improve the security of documents and files uploaded and downloaded on the platform.

Analysis, scoping, and implementation of security improvements to better protect Personal Health Information and Personally Identifiable Information stored within the product.

Improve notification and escalation of security concerns from third parties (such as security researchers).

Integration of new and existing logging and alerting systems to centralized and/or decentralized Security Incident and Event Management (SIEM) platforms.

Assess backlog of application-specific security tickets and provide recommendations for remediation and

Support evidence collection for compliance frameworks such as SOC 2 Type II and HIPAA.

WHAT WE LOVE ABOUT YOU Technical Expertise:

Proven experience as an Application Security Engineer or in a similar role. Strong technical background with experience in full-stack development, cloud computing, and scalable architecture. Proficiency in one or more OOP coding languages (Ruby, Python, Java, etc) is strongly preferred.

Deep Understanding:

Strong understanding and knowledge of web application security principles, common vulnerabilities, and best practices.

Collaborative Approach:

Excellent communication skills with the ability to simply convey complex security concepts to non-technical stakeholders and clearly articulate the relative risks and trade-offs.

Product Orientation:

Focused on keeping the company secure while ensuring the team can still ship products and deliver value to customers and users.

Decisions That Scale:

Experience cultivating a security-aware development culture that scales through mentorship and automation.

Passion for Social Impact:

A genuine interest in leveraging technology to address social challenges, with a strong sense of purpose in improving outcomes for children in need.

FLEXIBILITY We offer flexible scheduling for all team members. Ideal candidates will be open to working a schedule that allows real-time collaboration with the team. LOCATION This role is open to fully remote candidates authorized to work within the United States. If candidates are in the San Francisco Bay Area, we have an office in Oakland and you can work from the office. BENEFITS & PERKS An above-market compensation package (salary + equity)

Excellent medical, dental, vision, and life insurance - 99% of insurance premiums covered for you + your dependents

Flexible vacation time to promote a healthy work-life blend

13 paid holidays; 11 federally observed holidays (including Juneteenth), plus

Election Day and the day after Thanksgiving

16 weeks of paid parental bonding leave for the arrival of a newborn or newly placed infant

Sick/mental health time separate from vacation days (accrue up to a cap of 160 hours)

4 weeks of sabbatical after 4 years of service at the company

401k, Commuter benefits, FSA, and DCSA with administration paid for

$5,000 annual bonus for employees who volunteer as a

CASA

(court-appointed special advocates)

$2,500 annual reimbursement for ongoing learning and development, with opportunities to attend trainings/conferences, on-site speaker series, and lunch and learns

$300 reimbursement for virtual home office setup

$50 a month remote work stipend to cover internet, electricity, home office setup costs or lunch/snacks with coworkers

Paid jury duty

At Binti, we celebrate having a diverse team and believe our differences make us stronger. Binti is proud to be an equal-opportunity workplace and is an equal-opportunity employer. We welcome all qualified applicants to apply without regard to race, color, religion, gender, sexual orientation, age, national origin, disability, or protected Veteran status.

#J-18808-Ljbffr



  • California, United States Crescent Solutions Full time

    Crescent Solutions is seeking Application Security Engineer for our client, a large, global entertainment company, who will be a subject matter expert with hands-on experience in a wide range of cloud technologies, software development, application security, security architectures, security tools, and methodologies. The Application Security Engineer will...

  • Security Engineer

    5 days ago


    California, United States YOUNGHARRY DG INTERNATIONAL LTDq Full time

    Job ID# 10239 – Posted 4/18/23 – Remote, CA Position Description A Security Engineer serves as the security engineer of complex technology implementations in a product-centric environment; is comfortable with bridging the gap between legacy development or operations teams and working toward a shared culture and vision; works to ensure developers create...


  • California, United States Obsidian Security Full time

    Who We Are: Obsidian Security, established in 2017, emerged with a clear mission: addressing the overlooked blindspot in SaaS Security. Recognizing that SaaS applications empower employees and safeguard crucial business information, our focus is on preventing the detrimental consequences that arise when these tools face disruptions or data is compromised. At...


  • California, United States Tandym Group Full time

    A recognized financial services company is currently seeking an experienced professional to join their team as their new Cloud Security Engineer. ***The qualified professional in this role can sit at either the company's Los Angeles or NYC-based office.*** Responsibilities: The Cloud Security Engineer will: Manage, configure, and utilize network protection...


  • California, United States Open Systems Technologies Full time

    A law firm is looking for a Senior Applications Engineer - Finance to join their team in New York, NY. Compensation: $120-170k The Senior Applications Engineer, Finance acts as IT owner of several applications and platforms owned by the firm's Finance team. These include Elite 3E, Design Gallery, Chrome River, eBillingHub, IntApp Time, Proforma Tracker, Star...


  • California, United States Okx Full time

    Who We Are OKX is revolutionising world systems through our cutting-edge digital asset exchange, Web3 portal and blockchain ecosystems.We are deeply committed to shaping a fairer, more transparent and accessible society through blockchain technology and to date, we have 50+ million users, 3000+ employees and 180+ countries believing in the same vision as us....


  • California, Missouri, United States Shpe Sv Full time

    The Anti-Harassment Tools Team at Wikimedia Foundation is looking for a Staff Software Engineer to work with us to build features that help identify and stop harassment on all of our Wikimedia projects, including Wikipedia. This role is full-time, 100% remote, and global.The Anti-Harassment Tools Team is an interdisciplinary product team developing tools...


  • California, United States Conductor Full time

    What Youll Do Come join the Customer Engineering team that manages the technical account for SSD and NAND solution (e.g. eMMC, UFS and other application) customers in CA region related to Enterprise, Datacenter and SMB (Small & Medium Business) to maintain the close customer engineering relationship and SSD and NAND solution product technology leadership to...

  • Sr. Security Engineer

    2 weeks ago


    California, United States Americor Full time

    Americor is currently seeking a Senior Security Engineer to be part of the team. In this position, you will have a key role in safeguarding our networks and systems, adhering to industry standards and Americor's security protocols.Compensation: Annual salary ranges from $170,000 to $190,000, based on experience, plus bonus.Location: Irvine, CA (Hybrid...


  • California, United States hims & hers Full time

    About the Role: As a Senior Security Engineer, you will be a thought leader in the Security Team focused on helping design, implement, and mature innovative and cutting-edge security capabilities. Senior Security Engineer ensures defense-in-depth, provides hands-on technical leadership for security domains, assists with defining vision and execution of...


  • California, United States Conductor Full time

    What You’ll Do Come join the Customer Engineering team that manages the technical account for SSD and NAND solution (e.g. eMMC, UFS and other application) customers in CA region related to Enterprise, Datacenter and SMB (Small & Medium Business) to maintain the close customer engineering relationship and SSD and NAND solution product technology leadership...


  • California, United States Deere & Company Full time

    Advanced Options 18 open jobs. Match scores are indicators of potential fit and not a promise of any hiring activities. Jobs will be labeled when they're a good or great match Great matches will be shown first in search results Relevant skills and experience will be listed so you know why those jobs are a match 2024020 Staff Software Engineer (CA) 2024014...


  • California, United States Unbabel Inc Full time

    About Unbabel The company’s language operations platform blends advanced artificial intelligence with human editors, for fast, efficient, high-quality translations that get smarter over time. Unbabel integrates seamlessly in any channel so that agents can deliver consistent multilingual support from within their existing workflows. Making it easy for...


  • California, Missouri, United States Unbabel Inc Full time

    About Unbabel The company's language operations platform blends advanced artificial intelligence with human editors, for fast, efficient, high-quality translations that get smarter over time. Unbabel integrates seamlessly in any channel so that agents can deliver consistent multilingual support from within their existing workflows. Making it easy for...


  • California, United States Rocket Lab Full time

    IT Rocket Lab’s IT team is responsible for how our global teams access information and run operations across our computer systems, networks, and devices. Our hardworking IT team is a group of flexible problem-solvers working in a fast-paced environment but who also thrive under the challenge of supporting all of our proprietary systems and people, from...


  • California, United States Cisco Full time

    The Cisco Security AI team delivers AI products and platform for all Cisco Secure products and portfolios so businesses around the world can defend against threats and safeguard the most vital aspects of their business with security resilience. We are passionate about making our customers secure by simplifying security with zero compromise using AI and...


  • California, United States Robinhood Full time

    About the Team + Role: Robinhood is looking for a Coupa Applications Engineer to join our Finance Applications team. You’ll partner with teams across the business (Compliance, Legal, Security, Privacy, and People, etc.) and assist with support and enhancing Robinhood’s processes for requisitions, purchase orders, invoices, SIM, invoice smash, CaaS, and...


  • California, United States Cisco Full time

    Senior Manager, Cloud Security Engineering Location: Offsite, San Jose, California, US Area of Interest Security Compensation Range 184000 USD - 266000 USD Job Type Professional Cloud and Data Center, Security, Software Development Job Id 1420266 Cisco’s Cloud Security Engineering team is seeking an experienced and accomplished Engineering Leader to lead...


  • California, United States Cisco Full time

    The Cisco Security AI team delivers AI products and platform for all Cisco Secure products and portfolios so businesses around the world can defend against threats and safeguard the most vital aspects of their business with security resilience. We are passionate about making our customers secure by simplifying security with zero compromise using AI and...

  • Application Developer

    2 weeks ago


    California, United States TalentBurst, Inc. Full time

    Job Title:Application Developer Location:Downey CA Duration:12 Months W2 Acceptable Position Description:A Senior Programmer is responsible for leading and/or working on the most complex IT applications design, documentation, development, modification, testing, installation, implementation and support of new or existing applications software. This...