
Application Security – Design Reviews, Threat Modelling
Posted 1 hour ago

Posted 1 hour ago
This is a fully remote position, open to applicants in India.
• Engage in security design evaluations and threat modeling activities for new products, services, and platform functionalities.
• Collaborate with engineering teams to pinpoint security vulnerabilities and suggest practical mitigations throughout the design and development phases.
• Act as a security advisor for product and engineering teams, addressing security inquiries and offering guidance on secure implementation methodologies.
• Analyze application and system architectures, technical designs, data flows, and deployment strategies to detect security risks and propose secure design patterns.
• Work alongside engineering teams developing AI and machine learning capabilities to identify new security threats and recommend secure implementation practices.
• Assist in the maintenance and enhancement of security standards, guidelines, reference architectures, and internal documentation.
• Create or improve tools and automation that enhance the efficiency of threat modeling, security evaluations, and risk assessment processes.
• Collaborate with fellow Product Security engineers to conduct application security evaluations and investigate security issues raised during development.
• Contribute to developer training initiatives through documentation, office hours, workshops, or security awareness programs.
• Assist in security incident investigations and root cause analyses when application security vulnerabilities are identified.
• Must be available to work until 11:00AM Pacific Standard Time (PST).
• Over 5 years of experience in Application Security, Product Security, or a related domain.
• In-depth understanding of prevalent application security vulnerabilities (OWASP Top 10, API Security, authentication, authorization, secrets management, cryptography, etc.).
• Proven experience participating in security reviews, threat modeling sessions, architecture discussions, or application security evaluations.
• Exceptional technical writing abilities and experience in creating documentation and guidelines.
• Excellent communication skills and the capability to convey security concepts to engineers with various levels of security knowledge.
• Experience in collaborating with software engineering teams to identify and mitigate security risks.
• Familiarity with cloud platforms and contemporary application architectures (AWS is preferred).
• Ability to evaluate risk, prioritize issues, and offer actionable security recommendations.
• Proficient in reading and comprehending source code in one or more modern programming languages.
• Experience in developing scripts, tools, or automation to enhance engineering or security workflows.
• Health insurance
• Retirement plans
• Paid time off
• Flexible work arrangements
• Professional development
GEICO
Knak
Twilio
Yum! Center for Global Franchise Excellence
Get handpicked remote jobs straight to your inbox weekly.