ComplyAuto

ComplyAuto is a RegTech company offering cloud-based software that helps companies enhance their compliance and security capabilities while becoming more efficient and cost-effective. ComplyAuto manages and automates compliance decisions, performing tasks that would normally require manually-intensive processes and human intelligence. ComplyAuto began as a privacy compliance company for automotive dealers, but has quickly expanded into other verticals and compliance areas including cybersecurity, EHS (environmental, health, and safety), and legal compliance.

Senior Application Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteTeam 51-200

Location

United States

Posted

5 days ago

Salary

Not specified

Application SecuritySecure CodingThreat ModelingSASTDASTCi/cd SecurityNode.jsType ScriptReactAPI SecurityAWSCloud SecurityRelational Database SecuritySnykCheckmarxBurp SuiteNIST CSFSOC2PCI DSS

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

The Senior Application Security Engineer will play a critical role in ensuring the confidentiality, integrity, and availability of ComplyAuto applications and systems. You will work closely with cross-functional teams to design, implement, and maintain security measures that protect our infrastructure and customer data. This role will bring a strong background in application security, experience in startup/SaaS environments, and a solid understanding of Governance, Risk, and Compliance (GRC) principles.

  • Develop and maintain software application security policies and procedures
  • Conduct secure code reviews, threat modeling, and manual security assessments to identify potential risks, vulnerabilities, and exploits in ComplyAuto applications
  • Collaborate and provide actionable technical guidance to the software development team on remediating application security vulnerabilities and exploits
  • Promote secure coding best practices based on recognized standards
  • Develop and maintain documentation of application security controls
  • Implement software application security controls
  • Design and deliver periodic secure code training
  • Design technical solutions to address security weaknesses
  • Participate in incident response for application-related events, including lessons learned and design of test scenarios
  • Manage application security testing tools and platforms
  • Integrate and automate security testing as part of the CI/CD pipeline

Qualifications

  • Bachelor's degree in Computer Science, Software Engineering, or a related field; or equivalent work experience
  • 5-7+ years of experience as an Application Security Engineer, with experience in Cloud Security
  • Proficient in securing programming languages, including React, TypeScript, and Node.js
  • Strong understanding of relational database security
  • Knowledge of securing APIs
  • Experience configuring and managing both SAST (e.g. Synopsis, Snyk, Checkmarx, Veracode) and DAST (e.g. Stackhawk, Qualys, Burp Suite) tools
  • Experience with Cloud Infrastructure (AWS, Azure, GCP) and securing SaaS applications
  • Excellent communication skills, with the ability to effectively communicate complex technical concepts to both technical and non-technical stakeholders
  • Strong problem-solving and analytical skills
  • Knowledge of Secure Coding techniques
  • Familiarity with industry accepted security and compliance frameworks (e.g. NIST CSF, CIS, SOC2, PCI-DSS, etc.)
  • Familiarity with regulatory requirements (e.g. CCPA, GLBA, etc.)
  • General knowledge of governance, risk, and compliance

Requirements

  • Experience as a Security Engineer with a focus in Application Security
  • Ability to work in a fast-paced, high growth startup environment
  • Proficient with security tools and technologies
  • Understanding of web application architecture
  • Familiarity with performing threat modeling
  • Security Certifications are a plus
  • Applicants must be authorized to work in the United States and able to provide proof of work authorization within three days of start date
  • This is a fully remote opportunity, but candidates must reside within the Continental United States
  • We are not accepting applications from candidates residing in California, Hawaii, and Alaska for this position
  • Background check required

Benefits

  • Salary Range: $145,000-$155,000
  • 401(k) 5% match (1:1)
  • Medical, dental, and vision insurance; premiums we pay 100% for employee and family
  • HSA contribution for qualifying plans
  • Unlimited Paid time off and 11 observed holidays
  • Laptop and related hardware required provided

Company Description

ComplyAuto is a RegTech company offering cloud-based software that helps companies enhance their compliance and security capabilities while becoming more efficient and cost-effective. ComplyAuto manages and automates compliance decisions, performing tasks that would normally require manually-intensive processes and human intelligence.

ComplyAuto began as a privacy compliance company for automotive dealers, but has quickly expanded into other verticals and compliance areas including cybersecurity, EHS (environmental, health, and safety), and legal compliance.

Job Requirements

  • Bachelor's degree in Computer Science, Software Engineering, or a related field; or equivalent work experience
  • 5-7+ years of experience as an Application Security Engineer, with experience in Cloud Security
  • Proficient in securing programming languages, including React, TypeScript, and Node.js
  • Strong understanding of relational database security
  • Knowledge of securing APIs
  • Experience configuring and managing both SAST (e.g. Synopsis, Snyk, Checkmarx, Veracode) and DAST (e.g. Stackhawk, Qualys, Burp Suite) tools
  • Experience with Cloud Infrastructure (AWS, Azure, GCP) and securing SaaS applications
  • Excellent communication skills, with the ability to effectively communicate complex technical concepts to both technical and non-technical stakeholders
  • Strong problem-solving and analytical skills
  • Knowledge of Secure Coding techniques
  • Familiarity with industry accepted security and compliance frameworks (e.g. NIST CSF, CIS, SOC2, PCI-DSS, etc.)
  • Familiarity with regulatory requirements (e.g. CCPA, GLBA, etc.)
  • General knowledge of governance, risk, and compliance
  • Experience as a Security Engineer with a focus in Application Security
  • Ability to work in a fast-paced, high growth startup environment
  • Proficient with security tools and technologies
  • Understanding of web application architecture
  • Familiarity with performing threat modeling
  • Security Certifications are a plus
  • Applicants must be authorized to work in the United States and able to provide proof of work authorization within three days of start date
  • This is a fully remote opportunity, but candidates must reside within the Continental United States
  • We are not accepting applications from candidates residing in California, Hawaii, and Alaska for this position
  • Background check required

Benefits

  • Salary Range: $145,000-$155,000
  • 401(k) 5% match (1:1)
  • Medical, dental, and vision insurance; premiums we pay 100% for employee and family
  • HSA contribution for qualifying plans
  • Unlimited Paid time off and 11 observed holidays
  • Laptop and related hardware required provided

Related Categories

Related Job Pages

More Security Engineer Jobs

Senior Director - Cyber Engineering Cloud Security

Cencora

Cencora is a leading pharmaceutical solutions organization centered on improving the lives of people and animals everywhere. With 46,000+ global team members, we have the opportunity to make a positive impact on healthcare in communities everywhere. Our team members are empowered to activate their careers through a collective of tools and resources designed to support individual career interests and aspirations. We value our listening culture that actions real outcomes and our team members appreciate and recognize one another for contributions that are making a meaningful global impact. No matter what your role is here, the work we do together has meaning. When you join our team, you become a crucial part of a greater purpose. We’re committed to supporting you personally and professionally, so we can achieve more together at the center of health. Protect yourself from job scams: Recruitment scams are on the rise. To protect yourself, we urge you to be vigilant and follow these guidelines > https://careers.cencora.com/us/en/job-scams

Security Engineer5 days ago
Full TimeRemoteTeam 51,000Since 2023

This role leads the global strategy, architecture, engineering, and governance for enterprise cloud security across multi-cloud and hybrid environments, securing public cloud, SaaS platforms, and containerized workloads. The director is responsible for defining the cloud security strategy, establishing reference architectures, leading governance across AWS, Azure, GCP, and managing the cloud security policy framework.

United States

Security Intern

ezCater

ezCater is the world’s largest online marketplace for business catering.

Security Engineer5 days ago
InternshipRemoteTeam 501-1,000Since 2007H1B No Sponsor

Security Intern assisting with risk management and security solutions

CloudJavaScriptPythonRubyGo
Massachusetts
$30 - $36 / hour
Security Engineer5 days ago
Full TimeRemoteTeam 1-10H1B No Sponsor

Principal Technical Consultant leading identity solution implementations at AHEAD

Illinois
$200K - $230K / year
Security Engineer5 days ago
Full TimeRemoteTeam 5,001-10,000Since 2000H1B No Sponsor

The teacher is responsible for delivering specific course content in an online environment by providing instruction, support, and guidance, managing the learning process, and focusing on individual student needs. Essential functions include providing engaging synchronous and asynchronous learning experiences, differentiating instruction, maintaining the grade book, and actively communicating with students and parents/learning coaches.

United States