Security Engineer - DevSecOps

July 11

🏡 Remote – New York

Apply Now
Logo of Bitly

Bitly

We've expanded! Your all-in-one link management platform: QR Codes, Short URLs, and Link-in-bio!

internet • URLs • data • links • social publishing

201 - 500

Description

• Partner with rest of the InfoSec Team, IT and the Product-Engineering teams to implement the strategic security vision into our products • Design, implement, and maintain robust security architectures for our applications and cloud infrastructure to ensure our systems' confidentiality, integrity, and availability • Help implement Cloud Security Best Practices by configuring and managing security controls for cloud environments, including identity and access management (IAM), network security groups (NSGs), and encryption mechanisms • Keep detailed documentation of security configurations, policies, procedures, and incidents to help keep track of the status of security initiatives and compliance efforts • Implement security automation and orchestration workflows to streamline security operations and improve incident response times • Perform security-focused code reviews • Assist the InfoSec team in supporting the development and implementation of controls to achieve and maintain compliance with SOC 2 and other relevant industry standards • Support and consult with product engineering teams in the area of application security, including threat modeling and appsec reviews • Work closely with product engineering teams to embed security frameworks and security best practices throughout the software development lifecycle, including secure coding guidelines, static and dynamic code analysis, and dependency scanning • Participate in the entire software development lifecycle (SDLC), including threat modeling, secure code reviews, and security testing • Assist teams in reproducing, triaging, and addressing application security vulnerabilities • Take the lead in incident response efforts during security breaches or incidents, managing investigation, containment, eradication, and recovery activities while implementing preventative measures for the future

Requirements

• An expert in application and cloud security with a deep understanding of the latest threats, vulnerabilities, and best practices • A cybersecurity enthusiast with a substantial technical foundation and a drive to stay ahead of emerging threats • Proficiency in programming and automation using Go, JavaScript, Bash, and Terraform • A collaborative team player who can effectively communicate and work with cross-functional teams to integrate security into every phase of the software development lifecycle and convey technical concepts to non-technical stakeholders • A problem-solver with a keen eye for detail and a proactive approach to identifying and addressing security vulnerabilities • A continuous learner who thrives in a fast-paced environment and is eager to stay updated on emerging technologies and trends in cybersecurity • Strong understanding of web application security principles, including OWASP Top 10 vulnerabilities and secure coding practices • Familiarity with both AWS and GCP production environments • Experienced in applying security best practices to meet industry compliance standards (e.g., SOC 2, PCI-DSS, HIPAA) • (Bonus) Security certifications such as CISSP, CSSLP, CEH, or GCP Professional Cloud Security Engineer / AWS Certified Security Engineer

Benefits

• Inclusive health, dental, vision built to support diverse lifestyles through Aetna & Kaiser • One Medical membership: Doctors you can text, call or email 24/7 and receive access to expert insurance guidance • Wellness reimbursement program • Enhanced care for reproductive health, family planning, pediatrics with Maven • Robust mental health support and Employee Assistance Program (EAP) with confidential counseling services through Lyra. • Impactful community building through our Employee Resource Groups • Global DEI training programs and guest speakers throughout the year • Generous HSA Contribution from Bitly • 401k with up to 4% employer match through Betterment, access to a financial professional to offer our employees the opportunity to plan-ahead for a strong financial future well beyond their working years • Company Stock Options • Life Insurance - Company provided and supplemental • Short-term and Long-term Disability • Unlimited PTO Policy (vacation, sick, & personal), including Mental Health days and 2 annual “Recharge” weeks • Partial cell phone and WiFi service reimbursement • Full support for remote work, including a $500 home office stipend • Voluntary Benefits: Pet Insurance, LegalShield, IDShield, Hospitalization, and Accident coverages • Generous parental leave policies; maternity and parental leave for growing families • Budget for professional development opportunities, including courses and conference attendance • Coworking reimbursement - $350 on a quarterly basis

Apply Now
Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or lior@techjobsnewyorkcity.com