Application Security Engineer

Stride · Remote

Company

Stride

Location

Remote

Type

Full Time

Job Description

Today, 60 million Americans work independently, and that trend is only accelerating. But benefits are tightly coupled with full-time, W2-based jobs. As a result, the millions of Americans who work independently are excluded from that financial safety net.

Stride is the world’s first benefits platform built specifically for contractors, part-timers, and the self-employed. We provide them all the same benefits you’d expect from a W2 job, like insurance, tax support, and discounts on products and services. In fact, since launching in 2014, Stride has helped over 3.5 million Americans save over $4 billion on their benefits and taxes.

We’re partnered with the top employers of non-benefited workers, including DoorDash, Uber, Postmates, MasterCard, Amazon, Aon, and Willis Towers Watson. We’re backed with over $86 million in capital by Venrock, New Enterprise Associates, Fidelity’s F-Prime Capital Partners, King River Capital, Mastercard, and Allstate.
And we’re growing!  While we started off exclusively serving non-benefited workers, other companies in our space started knocking on our door to tailor our platform for their customers. Now we need outstanding people (like you!) to help us reach our mission and improve access to affordable benefits for all.

Cash compensation range: $123,000 - $145,000 USD annually + equity

The Stride team is seeking an experienced Application Security Engineer to enhance our Security program. As part of our small security team, you will collaborate with the Director of Security and Compliance to shape the future of our overall security program and strengthen Stride's system security. As the primary AppSec engineer, your role will focus on shifting security left, ensuring the safety and resilience of our applications. You will work closely with our application engineering teams, integrating security best practices into the development lifecycle, and advancing our organization's overall security posture. We are looking for a collaborative partner who can identify and resolve vulnerabilities, streamline security practices in development pipelines, and develop innovative solutions.

Our engineering teams primarily use Javascript, Python, Swift, and Kotlin. Our frontend is written in Typescript with React and Redux. We employ Terraform for Infrastructure as Code, with all components containerized on AWS and deployed using CI/CD.

Responsibilities:

  • Collaborate with engineering teams to reduce vulnerabilities using a risk-focused framework.
  • Develop and deliver training on secure coding practices, vulnerability management, and the secure development lifecycle.
  • Identify, set up, and maintain application security tooling, including static and dynamic scanning solutions (SAST and DAST) and reporting.
  • Advise and oversee the secure design and configuration requirements of key application projects to ensure the implementation of security requirements.
  • Collaborate with development teams to validate vulnerability scanning and penetration testing results, and assist in devising remediation solutions for identified issues.
  • Conduct threat modeling and risk assessment exercises to mitigate potential attack vectors.
  • Act as a subject matter expert, providing guidance on application security matters to engineering and management teams.
  • Maintain documentation of application security controls.
  • Implement software application security controls.
  • Design technical solutions to address security weaknesses.
  • Communicate effectively and organize effectively to collaborate with engineering teams and address security issues.
  • Utilize project management skills to oversee long-term remediation projects.

Qualifications:

  • 3+ years of experience in application security or a related field, preferably within a DevSecOps environment.
  • Proficiency in Python, Javascript, and PostgreSQL, with a specific emphasis on Python scripting.
  • Familiarity with security tools and frameworks, including SAST and DAST.
  • Understanding of vulnerability management.
  • Solid understanding of secure coding best practices and the security aspects of application architecture.
  • Experience reviewing technical designs and proactively identifying risks in collaboration with engineers.
  • Ability to develop and maintain documentation of application security controls.
  • Proficiency in implementing software application security controls.
  • Capability to design technical solutions to address security weaknesses.
  • Strong communication and organizational skills to collaborate effectively with engineering teams and resolve security issues.
  • Project management experience for overseeing long-term remediation projects.

Nice-to-haves:

  • Strong knowledge of AWS security best practices and tools.
  • Solid understanding of threat modeling and risk assessment methodologies.
  • Familiarity with container security and orchestration tools, such as Docker and Kubernetes.
  • Experience in building a product security program or being an early member of a security team, contributing to scaling a security program.

#LI-RR

Helpful Information:

This resource will help explain Stride’s Compensation Philosophy and compensation practices, and will answer some common questions you might have.

Stride’s Compensation Philosophy utilizes a National Payscale, which is designed to fairly and equitably pay employees based on their performance and impact regardless of geographic location. For employees in the United States, our National Payscale leverages San Francisco Bay Area market data to determine our compensation bands for cash, commissions, or bonus (if applicable) and equity.

Unless otherwise noted, the cash compensation above is the total salary and does not include a bonus.  In addition to cash compensation, all full-time Striders will be given stock options to participate in Stride’s equity incentive program.  We want all Striders to be an owner of the company, value that ownership, and be able to participate in any future positive outcomes for the company.

Individual compensation packages are based on a few different factors unique to each candidate, including their skills, experience, qualifications, and other job-related reasons. Our compensation ranges are designed to be competitive, equitable, and growth-oriented.

We know that benefits are also an important piece of your total compensation package. To learn more about what’s included in total compensation, check out some of the benefits and perks Stride offers to all US-based employees.

At Stride, we believe in compensating Striders in ways that are true to their value in the marketplace, that inspire and motivate the team to execute our vision, that shape behavior toward productively building and sustaining Stride's culture, and that support the risks and rewards of a fast-growing technology company. 

We know the confidence gap and imposter syndrome are a real thing. This can get in the way of meeting incredible candidates, so please don’t hesitate to apply — we’d love to hear from you!

If you are interested in learning more about us, you can check us out on-  Built In, The Muse, Stride in the News, and  Additional Press.

Stride is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Apply Now

Date Posted

06/02/2023

Views

8

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8
142,000+ Jobs Tracked
12,400+ Companies
1,930 Categories