Summary
Join Gemini's Application Security team as a Senior Application Security Engineer and play a key role in protecting the company and its customers from application security threats. Collaborate with engineering and product teams to provide security recommendations and identify security issues throughout the software development lifecycle. Responsibilities include design reviews, threat modeling, secure code review, penetration testing, developing security tools, and delivering security training. This position requires a strong background in application security best practices and some development experience. The role is hybrid, requiring in-person presence twice a week in either the Seattle, WA or New York City, NY office.
Requirements
- 5+ years of experience in application security or similar roles
- Ability to perform design reviews, threat modeling, secure code reviews, or penetration testing with an attacker mindset
- Strong background in application security best practices and familiarity with common vulnerabilities (e.g. SSRF, race conditions, privilege escalations, etc.)
- Some background in development or scripting experience (Python, Scala, C++, or JavaScript)
- Familiarity with and ability to understand business objectives, business context, and security risk
- Strong communication skills and the ability to collaborate on a cross-functional team
Responsibilities
- Support the Gemini Secure Software Development Lifecycle as an application security subject matter expert through design review, threat modeling, code review, and penetration testing
- Collaborate and advise engineering teams on application security best practices and vulnerability remediation
- Perform deep-dive security reviews to ensure all Gemini products and services follow secure design principles across our product portfolio (web, mobile, and APIs)
- Develop tools and research to scale the Product Security team
- Create and deliver hands-on software security training to engineering teams to increase security awareness
- Participate in the Application Security on-call rotation to support engineering teams during incidents
Preferred Qualifications
- Experience with microservice architectures
- Experience with cloud-native environments
- Experience with preventing application security vulnerabilities through secure design patterns, automated tooling, or frameworks
Benefits
- Competitive starting salary
- A discretionary annual bonus
- Long-term incentive in the form of a new hire equity grant
- Comprehensive health plans
- 401K with company matching
- Paid Parental Leave
- Flexible time off
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.