
Senior Software Engineer, Application Security – AV and Software Infrastructure
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in California, +3 more states.
• Evaluate application designs and code, create threat models, and assist teams in mitigating security risks prior to deployment.
• Design and establish authentication and authorization mechanisms for APIs, services, and applications, encompassing service identities, tenant isolation, and resource-level access.
• Develop reusable libraries, tools, and reference implementations that facilitate the adoption of secure patterns.
• Enhance the management of credentials, secrets, sensitive data, and security-related logging within applications.
• Incorporate practical security checks into development and CI/CD workflows, providing actionable insights and clear remediation strategies.
• Investigate application vulnerabilities, collaborate with service owners to devise fixes, and implement regression coverage.
• Collaborate with infrastructure and corporate security teams to prioritize enhancements and evaluate their effectiveness.
• Over 12 years of relevant experience.
• Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related discipline, or equivalent practical experience.
• Proven experience in building and managing production software, particularly in application or product security.
• Proficient programming skills in Go, Python, Java, C++, or a similar programming language.
• Capability to review and modify unfamiliar code efficiently.
• Solid understanding of web and API security, along with authentication, authorization, and typical vulnerability classes.
• Experience in threat modeling and conducting security reviews for distributed systems.
• Ability to translate security findings into actionable engineering modifications and prioritize tasks based on risk and impact.
• Excellent communication skills and a collaborative approach to working with engineering teams.
• Familiarity with OAuth 2.0, OpenID Connect, service identity, and authorization policy frameworks.
• Experience in securing multi-tenant services, data platforms, or developer infrastructure.
• Knowledge of Kubernetes, cloud IAM, infrastructure as code, and CI/CD systems.
• Proven track record in enhancing vulnerability detection or dependency security while minimizing false positives.
• A history of establishing security capabilities that engineering teams actively adopt and implement.
• Equity.
• Comprehensive benefits.
GE Vernova
GE Vernova
Allata
Guardian Industries - DeWitt
Get handpicked remote jobs straight to your inbox weekly.