Job Description
Job Overview
CaptivateIQ is looking for a Senior Security Engineer focused on Application & Product Security to join their fast-growing team. This role is critical in embedding security into every phase of product development, ensuring the trustworthiness of their services. The ideal candidate will drive the AppSec strategy, conduct threat modeling, lead penetration testing, and manage compliance with security frameworks.
Technical Requirements
Required Skills
- • penetration testing
- • secure architecture design
- • vulnerability management
- • incident response
Preferred Skills
- • OSCP
- • GCIH
- • GWAPT
- • CISSP
Experience Level
7+ years of experience in security engineering, including 4+ years specializing in web application, API, and product security.
Responsibilities
- • Conduct threat modeling and architecture reviews
- • Perform offensive security testing for web applications and APIs
- • Integrate security into the Software Development Life Cycle (SDLC)
- • Manage vulnerability assessments and remediation
- • Deliver secure development training and resources
- • Oversee Bug Bounty program
- • Lead incident response for security events
- • Support compliance with SOC 2 and ISO 27001
Benefits & Perks
- • 100% of medical, dental, and vision covered including 75% for dependents
- • Flexible vacation days and quarterly mental health days
- • One-time expense on 1-year work anniversary
- • 401k plan to participate in
- • Newest Apple products for work
- • Employee Resource Groups (ERGs)
Additional Information
- Location
-
Remote, Raleigh, NC, Nashville, TN, Toronto, Canada
- Type
-
Full-time
- Compensation
-
$154,500 - $197,760 a year