Application Security Engineer
2 months ago
Nextdoor is where you connect to the neighborhoods that matter to you so you can belong. Our purpose is to cultivate a kinder world where everyone has a neighborhood they can rely on.
Neighbors around the world turn to Nextdoor daily to receive trusted information, give and get help, get things done, and build real-world connections with those nearby - neighbors, businesses, and public services. Today, neighbors rely on Nextdoor in more than 315,000 neighborhoods across 11 countries.
Meet Your Future Neighbors
As an Application Security Engineer (focusing on DevSecOps) you will be responsible for monitoring Nextdoor's enterprise and product core platforms/systems and managing security tools and capabilities. This role requires an understanding of security threats, vulnerabilities, and the organizational best practices required to mitigate them. The ideal candidate will have a proactive mindset, staying ahead of potential security issues, and solving security challenges with practical solutions.
At Nextdoor, we offer an inclusive work environment. We embrace a hybrid experience, enabling connectedness while providing a flexible experience for our valued employees.
The Impact You'll Make
In the role of Application Security Engineer, you will enable developers to build secure applications and infrastructure at Nextdoor. You will collaborate with engineers to establish secure-by-default practices and application security monitoring, striking a balance between "shift left" and "shift right" security approaches, while embedding security into fast-moving development processes.
Your responsibilities will include providing critical application security services such as security reviews, developer security education, and incident response. Additionally, you will lead engineers who champion security and reliability, helping to shape security practices across Nextdoor's evolving platform through new tools and processes.
Your responsibilities will include:
- Continuously monitor security infrastructure, identify suspicious activities
- Utilize data and security tools to analyze and respond to security alerts
- Lead and coordinate incident response efforts by executing the incident response strategy through incident remediation and closure
- Monitor and maintain vulnerability reporting and bug bounty programs
- Triage vulnerability and threat notifications to determine priority and necessary remediation
- Conduct regular security audits and vulnerability assessments to identify threats and reduce risk
- Evaluate, implement and maintain security controls across devices and cloud environments
- Work closely with IT, DevOps, and Cloud Infrastructure to integrate security practices and tools
- Build integrations, and implementations of technologies to support security operations
- Script and automate integrations, detections, and security reporting
- Champion security by providing awareness training for new hires and employees
- Stay informed about emerging threats and vulnerabilities, and update security measures accordingly
- Maintain detailed and up-to-date documentation of security procedures, policies, and protocols
- Ensure compliance with relevant regulations and standards (e.g., GDPR, HIPAA, ISO 27001)
- Assist with internal and external security audits
- Participate in in-person Nextdoor events, trainings, off-sites, volunteer days, and other team building exercises
- Build in-person relationships with team members and contribute to the KIND culture that Nextdoor values
- Experience with scripting languages (e.g., Python, Bash), APIs, and integration for automation of security tasks.
- 5+ years of experience in a security operations and/or vulnerability management role.
- Get a deep understanding of Nextdoor's platform, developer processes, CI/CD integrations, and current mechanisms for security and configuration management.
- Lead the development and implementation of secure-by-default solutions across engineering.
- Serve as an SME and conduct threat modeling on new and existing products with engineering.
- Design and lead developer security training to enhance design and coding best practices.
- Maintain automated security testing tools and scripts within CI/CD pipelines such as SCA, SAST, DAST, and CNAPP.
- Evaluate and implement next generation tools to embed security in Development processes.
- Identify top threats across products and services and prioritize remediation efforts.
- Empathize with the full spectrum of our customers and our engineers by advocating for effective solutions that scale with the needs of our business and our customers.
- Foster security champions across engineering and product and enhance the shared security program.
- Participate in the on-call rotation for security and product incident response.
- Coordinate with internal teams to respond to incidents swiftly and effectively.
- Document incidents, response actions, and lessons learned to improve future responses.
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Excellent communication and teamwork abilities.
- Models Nextdoors values including Earn Trust Everyday, Invest in Customer, Customer Obsessed, Experiment and Learn Quickly, and Act Like an Owner.
- Experience with macOS MDM and cloud-native environments, (e.g. AWS or GCP) is required.
- Experience with security cloud-based microservices infrastructure and IaaC
- Experience with IdPs, SSO, and Identity and Access Management
- Threat driven or offensive security mindset with practical defense experience
- Experience building dashboards for security metrics and cross-org security posture
- Data analytics, data engineering, data science, or ML/AI experience
- Hands-on certifications (e.g. OSCP, Certified Ethical Hacker, SANS) and/or demonstrated code projects. Please share your github or public code samples with us
- Offensive Security Certified Professional (OSCP)
- Certified Ethical Hacker (CEH)
- GIAC Security Certifications (e.g. GSEC, GCIH, GCIA, GWEB, GWAPT, GPEN, GMOB)
- AWS Security Certifications
Compensation, benefits, perks, and recognition programs at Nextdoor come together to create one overall rewards package.
The starting salary for this role is expected to range from $135,000 to $170,000 USD on an annualized basis, or potentially greater in the event that your 'level' of proficiency exceeds the level expected for the role. Compensation may also vary by geography.
We also expect to award a meaningful equity grant for this role. With equal quarterly vesting, your first vest date would be within the first 3 months of your start date.
Overall, total compensation will vary depending on your relevant skills, experience, and qualifications. We have you covered Nextdoor employees can choose between a variety of great health plans. We cover 100% of your personal monthly premium for health, dental, and vision - and provide a OneMedical membership for concierge care.
At Nextdoor, we empower our employees to build stronger local communities. To create a platform where all feel welcome, we want our workforce to reflect the diversity of the neighbors we seek to serve. We encourage everyone interested in our purpose to apply. We do not discriminate on the basis of race, gender, religion, sexual orientation, age, or any other trait that unfairly targets a group of people. In accordance with the San Francisco Fair Chance Ordinance, we always consider qualified applicants with arrest and conviction records.
For information about our collection and use of applicants' personal information, please see Nextdoor's Personnel Privacy Notice, found here.
-
Principal Security Engineer
3 weeks ago
San Francisco, United States Gusto Full timePrincipal Security Engineer - Application SecurityAbout GustoGusto is a modern, online people platform that helps small businesses take care of their teams. On top of full-service payroll, Gusto offers health insurance, 401(k)s, expert HR, and team management tools. Today, Gusto offices in Denver, San Francisco, and New York serve more than 300,000...
-
Principal Security Engineer
1 month ago
San Francisco, United States Gusto Full timeAbout Gusto Gusto is a modern, online people platform that helps small businesses take care of their teams. On top of full-service payroll, Gusto offers health insurance, 401(k)s, expert HR, and team management tools. Today, Gusto offices in Denver, San Francisco, and New York serve more than 300,000 businesses nationwide. Our mission is to create a world...
-
Principal Security Engineer
3 weeks ago
San Francisco, United States Gusto Full timePrincipal Security Engineer - Application SecurityAbout GustoGusto is a modern, online people platform that helps small businesses take care of their teams. On top of full-service payroll, Gusto offers health insurance, 401(k)s, expert HR, and team management tools. Today, Gusto offices in Denver, San Francisco, and New York serve more than 300,000...
-
Ambient Security | Staff Software Engineer
4 days ago
san francisco, United States Ambient Security Full timeAmbient Security is an exciting new startup, looking to reduce the risk of account takeovers and cyber attacks for large enterprises. The founder and CEO is a 7x cyber security entrepreneur with a track record of successful exits.Ws seeking software engineers at all levels to lead the design and implementation of innovative technologies. We are seeking...
-
Senior Application Security Engineer
1 month ago
San Francisco, United States Tbwa ChiatDay Inc Full timeHeadway’s mission is a big one – to build a new mental health care system everyone can access. We’ve built technology that helps people find great therapists with the first software-enabled national network of providers accepting insurance.1 in 4 people in the US have a treatable mental health condition, but the majority of providers don’t accept...
-
Cloud Security AI Engineer
2 weeks ago
San Francisco, California, United States Oleria Security Full timeCompany OverviewOleria Security is a leading enterprise cybersecurity startup revolutionizing access control solutions for cloud applications. Founded by industry senior leaders, we have received over $43M in funding from notable investors. Our mission is to reduce data breaches by addressing access risks through advanced AI-powered technology.We recognize...
-
Sr. Staff Application Security Engineer
2 months ago
San Francisco, United States Aurora CO Full timeWho We Are Aurora (Nasdaq: AUR) is delivering the benefits of self-driving technology safely, quickly, and broadly to make transportation safer, increasingly accessible, and more reliable and efficient than ever before. The Aurora Driver is a self-driving system designed to operate multiple vehicle types, from freight-hauling trucks to ride-hailing...
-
Senior Backend Security Engineer
3 weeks ago
San Francisco, California, United States Oleria Security Full timeWe are looking for a talented Senior Backend Security Engineer to join our team. As an early hire, you will have the opportunity to build and architect our systems and platforms, including development practices and processes. Your expertise in backend development and cybersecurity will be crucial in helping us achieve our goal of providing adaptive and...
-
Sr. Application Security Engineer
2 months ago
San Francisco, United States Bridge Technologies and Solutions Full timeWe need a resource who has experience working within a Vulnerability Management Program that understands Application Security with 5-7 years of security experience.Responsibilities:• Experience with any of the following commercial application scanning tools such as Acunetix, IBM's AppScan, Client's WebInspect, NTOSpider, Cenzic's Hailstorm, Burp Suite...
-
Senior/Staff Application Security Engineer
1 month ago
San Francisco, United States Crusoe Full timeCrusoe is building the World's Favorite AI-first Cloud infrastructure company. We're pioneering vertically integrated, purpose-built AI infrastructure solutions trusted by Fortune 500 companies to power their most advanced AI applications. Crusoe is redefining AI cloud infrastructure, with a mission to align the future of computing with the future of the...
-
Data Security Engineer
2 weeks ago
San Francisco, California, United States Oleria Security Full timeOleria Security is a leading provider of adaptive and autonomous identity security solutions. We empower organizations to accelerate at the pace of change, trusting that their data is protected.Job Overview:We are seeking an experienced Senior Backend Software Engineer to join our team. As an early hire, you will have the opportunity to build and help...
-
Senior/Staff Application Security Engineer
2 months ago
San Francisco, United States ZipRecruiter Full timeJob DescriptionCrusoe is building the World’s Favorite AI-first Cloud infrastructure company. We’re pioneering vertically integrated, purpose-built AI infrastructure solutions trusted by Fortune 500 companies to power their most advanced AI applications.Crusoe is redefining AI cloud infrastructure, with a mission to align the future of computing with the...
-
Staff Embedded Security Engineer
4 weeks ago
San Francisco, CA, United States IDENTIFY SECURITY Full timeWe are currently seeking a Staff Embedded Security Engineer . This position requires an experienced professional with a proven track record of cyber security development achievements. Our ideal candidate exhibits a can-do attitude and approaches his or her work with vigor and determination. Candidates will be expected to demonstrate excellence in their...
-
Staff Product Security Engineer
6 days ago
San Francisco, United States Code Red Partners Full timeIntroductionCode Red is Partnered with one of the most innovative AI companies in the world. This hire will be on the Product Security team, focusing on native applications. The company is global, profitable, $400million+ funded, and on the up and up!What You’ll Do:Drive the security posture for native applicationsCarry out threat models, code reviews, pen...
-
Application Security Engineer
2 months ago
San Ramon, United States Wavestrong Full timeFounded in 2001, WaveStrong is an industry leader in enterprise and cloud information security consulting services. We pride ourselves on our best of breed security solutions and services that span a myriad of government, education and business verticals. Our staff is comprised of both certified technical and business professionals who can help you...
-
Web Application Security Engineer
4 weeks ago
San Francisco, CA, United States Direct Staffing Inc Full timeVisa candidates are welcome to apply. Shopping has changed more in the past five years than in the past five decades, and going forward, retailing will require investing more in people and technology. With the rapid changes in retail, it is critical that technology be a strategic enabler for our company to accelerate delivery, be adaptive to market changes,...
-
Senior Application Security Engineer
4 weeks ago
San Francisco, CA, United States Tbwa ChiatDay Inc Full timeHeadway’s mission is a big one – to build a new mental health care system everyone can access. We’ve built technology that helps people find great therapists with the first software-enabled national network of providers accepting insurance. 1 in 4 people in the US have a treatable mental health condition, but the majority of providers don’t accept...
-
Application Security Engineer
2 weeks ago
San Jose, California, United States Intelliswift Full timeJoin our mission to prioritize security during product development at Intelliswift. The estimated salary for this position is $58.15 per hour on W2.We own the charter of ensuring security is prioritized during product development and identify security threats at scale. This enables development teams to fix issues before deployment to production.Your...
-
Native Application Security Specialist
7 days ago
San Francisco, California, United States Tbwa ChiatDay Inc Full timeAbout the OpportunityWe're seeking a seasoned Security Engineer to join our Product Security team within Trust & Enterprise organization. As a key member, you will drive the security posture for our native applications, ensuring the trust of millions of users who rely on our products.Key ResponsibilitiesDrive security enhancements throughout our portfolio of...
-
San Francisco, United States salesforce Full timeTo get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job Category: Software EngineeringAbout Salesforce:We’re Salesforce, the Customer Company, inspiring the future of business with AI + Data + CRM. Leading with our core values, we help companies across every...