Staff Application Security Engineer

Details of the offer

Our MissionSPAN is enabling electrification for allSPAN is mission-driven to design, build, and deploy products that electrify our built environment, decarbonize our world, and slow the effects of climate change.
Decarbonization is the process to reduce or remove greenhouse gas emissions, especially carbon dioxide, from entering our atmosphere.
Electrification is the process of replacing fossil fuel appliances that run on gas or oil with all-electric upgrades for a cleaner way to power our lives.
At SPAN, we believe in:
Enabling homes and vehicles powered by clean energy
Making electrification upgrades possible
Building more resilient homes with reliable backup
Designing a flexible and distributed electrical grid
The Role We are seeking a highly skilled and experienced individual to join our Security & Privacy team at SPAN as a Staff Application Security Engineer.
In this critical role, you will be instrumental in building and enhancing SPAN's application security program.
Your responsibilities will ensure the security of our applications through proactive assessment, threat modeling, code reviews, and close collaboration with the development teams.
Ideal candidates will have extensive experience in application security, a deep understanding of secure coding practices, and the ability to influence and educate others on security matters.
Responsibilities include: Developing a comprehensive application security strategy aligned with company objectives.
Performing secure design and code reviews to identify, mitigate, and prevent security vulnerabilities, enabling SPAN teams to deliver secure, high-quality products.
Leading and executing SAST/DAST/SCA efforts.
Collaborating closely with development teams to integrate security best practices into the software development lifecycle (SDLC).
Performing threat modeling on existing and upcoming feature sets in SPAN applications to ensure appropriate security controls are built from the ground up.
Developing and enforcing a robust authentication and authorization posture.
Designing, implementing, and maintaining application security controls and solutions, leveraging hands-on coding experience.
Ensuring compliance with regulatory requirements and industry standards including risk assessments and risk mitigation strategies for application security.
Staying current with the latest application security threats, vulnerabilities, and best practices.
Continuously evaluating and improving application security processes and technologies.
About You Bachelor's Degree in Computer Science, Information Assurance, Cyber Security, or related field of study.
7+ years of experience in a security engineering or operations role, with a focus on application security.
Deep understanding of web and mobile application vulnerabilities and defenses.
Hands-on experience with one or more application security scanning tools.
Expertise in web, mobile, and API security.
Ability to effectively communicate with technical and non-technical audiences.
Proficient in writing production-quality code in one or more languages such as Python, Kotlin, or NodeJS.
Experience in developing threat models (e.g., STRIDE, DREAD).
Nice-to-Have Hands-on experience with AWS Security best practices.
Experience with vulnerability management.
Certifications such as CISSP, CSSLP, or relevant industry certifications.
The U.S. base salary range for this position is $160,000 - $215,000, plus benefits and equity.
This range represents SPAN's good faith estimate of a competitively-priced salary for the role based on national, real-time industry data from companies of a similar growth stage.
This range reflects minimum and maximum new hire salaries for the role in San Francisco county. Within this range, individual pay is determined by location and individual factors including relevant skills, experience, and education or training.
This range correlates to the relative level of the candidate we believe we need for the role and may require an adjustment for candidates of a different level.
Your recruiter can share more about the specific salary range for the location this role is based during the hiring process.
Life at SPANHeadquartered in San Francisco's vibrant SoMa neighborhood, we are an eclectic group of creative thinkers who value open communication, teamwork, and a 'make it happen' approach to addressing complex challenges.
SPAN embraces diversity and equal opportunity in a serious way.
We are committed to building a team that represents a variety of backgrounds, perspectives, and skills.
We're hiring talented individuals who are driven by success and are passionate about shaping the future of renewable energy.
If that sounds like you, we'd love for you to consider joining the rapidly growing team at SPAN.
The Perks: Competitive compensation + equity grants at a well-funded, venture-backed company.
Comprehensive benefits: 100% employee premiums for base plans on medical, dental, vision with options for additional coverage.
Parental leave up to six (6) months depending on eligibility.
Comfortable, sunny office space located near BART and Caltrain public transit.
Strong focus on team building and company culture: Employee Resource Groups, monthly social events, SPANcakes recognition breakfast, lunch and learns.
Flexible hours, one holiday per month, and unlimited PTO.
Interested in joining our team?
Submit an application today and we'll be in touch with next steps!

#J-18808-Ljbffr


Nominal Salary: To be agreed

Source: Jobleads

Requirements

Backend Engineer, Developer Sdks, Golang Expert

Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world's largest enterprises to the most ambitious startups - u...


Rollbar, Inc. - California

Published 7 days ago

Senior Software Engineer - Containers And Platform

By making evidence the heart of security, we help customers stay ahead of ever-changing cyber-attacks. Corelight is a distributed first cybersecurity startup...


Job Board - California

Published 7 days ago

Software Engineer, Infrastructure

Why HarveyHarvey is a secure AI platform for professionals in law, tax, and finance that augments productivity and automates complex workflows. Harvey uses a...


Harvey.Ai - California

Published 7 days ago

Senior Software Engineer- Reliability

Luma's mission is to build multimodal AI to expand human imagination and capabilities. We believe that multimodality is critical for intelligence. To go beyo...


Luma Ai - California

Published 7 days ago

Built at: 2025-01-22T13:08:31.349Z