Senior Application Security Engineer
Gemini
Job highlights
Summary
Join Gemini's Application Security team as a Senior Security Engineer and play a crucial role in protecting our company and customers from application security threats. You will collaborate with engineering and product teams, providing security recommendations and identifying issues throughout the software development lifecycle. Responsibilities include design reviews, threat modeling, code review, penetration testing, and developing security training. This role requires 5+ years of experience in application security, strong communication skills, and a deep understanding of application security best practices. Gemini offers a competitive salary, discretionary annual bonus, equity grant, comprehensive health plans, 401k matching, paid parental leave, and flexible time off.
Requirements
- 5+ years of experience in application security or similar roles
- Ability to perform design reviews, threat modeling, secure code reviews, or penetration testing with an attacker mindset
- Strong background in application security best practices and familiarity with common vulnerabilities (e.g. SSRF, race conditions, privilege escalations, etc.)
- Some background in development or scripting experience (Python, Scala, C++, or JavaScript)
- Familiarity with and ability to understand business objectives, business context, and security risk
- Strong communication skills and the ability to collaborate on a cross-functional team
Responsibilities
- Support the Gemini Secure Software Development Lifecycle as an application security subject matter expert through design review, threat modeling, code review, and penetration testing
- Collaborate and advise engineering teams on application security best practices and vulnerability remediation
- Perform deep-dive security reviews to ensure all Gemini products and services follow secure design principles across our product portfolio (web, mobile, and APIs)
- Develop tools and research to scale the Product Security team
- Create and deliver hands-on software security training to engineering teams to increase security awareness
- Participate in the Application Security on-call rotation to support engineering teams during incidents
- Manual source code review
- Penetration testing
- Design and implementation review
- Threat modeling
- Design and implementation consultation
- Continuous assurance activities
- Risk identification and categorization / management
- Engineering education and engagement
Preferred Qualifications
- Experience with microservice architectures
- Experience with cloud-native environments
- Experience with preventing application security vulnerabilities through secure design patterns, automated tooling, or frameworks
Benefits
- Competitive starting salary
- A discretionary annual bonus
- Long-term incentive in the form of a new hire equity grant
- Comprehensive health plans
- 401K with company matching
- Paid Parental Leave
- Flexible time off
Share this job:
Similar Remote Jobs
- πGermany
- πGermany
- π°$175k-$210kπUnited States
- πUnited States
- π°$188k-$230kπWorldwide
- π°$170k-$190kπUnited States
- π°$166k-$207kπUnited States
- πBrazil