Arcadia Towers

Arcadia Towers

Arcadia Towers LLC is a cell tower company that develops, owns, and operates wireless communications towers across the U.S. They provide innovative solutions for wireless infrastructure development, connecting communities today and for the future. Arca...

Real Estate
1-10
Founded 2005

Description

  • Own the end-to-end vulnerability management lifecycle across SAST, DAST, and SCA findings.
  • Triage, prioritize, and drive remediation efforts in partnership with engineering squads.
  • Maintain, optimize, and extend security automation and tooling integrations in the CI/CD pipeline.
  • Launch and run a Security Champions program with workshops and office hours across distributed teams.
  • Serve as the application-layer subject matter expert during security incidents, including triage, root cause analysis, and remediation.
  • Partner with Product and Engineering leadership to add security earlier in the SDLC through threat modeling and design reviews.
  • Act as a trusted advisor to engineers and help communicate security risks in a way that drives action.
  • Support the engineering organization by embedding security practices into day-to-day development workflows.

Requirements

  • 3–5 years of dedicated Application Security experience in a SaaS or cloud-native environment.
  • Hands-on proficiency with at least two of the following: SAST, DAST, SCA, or CSPM tooling such as Snyk, Checkmarx, Semgrep, or Wiz.
  • Strong working knowledge of CI/CD pipelines such as GitHub Actions, Jenkins, or GitLab CI, with the ability to write and maintain integrations.
  • Experience with container security using Docker and Kubernetes.
  • Experience with API security patterns including REST and GraphQL.
  • Ability to communicate technical risk to non-security engineers in a clear, action-oriented way.
  • Experience standing up or maturing a Security Champions program is preferred.
  • Familiarity with AWS security services such as GuardDuty, Security Hub, and IAM Access Analyzer is preferred.
  • Exposure to threat modeling frameworks such as STRIDE, PASTA, or similar lightweight methods is preferred.
  • Relevant certifications such as OSCP, GWAPT, or CSSLP are valued but not required.
  • Ability to work remotely from anywhere in the US with a reliable internet connection.
  • Visa sponsorship is not available for this position.

Benefits

  • Remote-first work environment with the flexibility to work anywhere in the US.
  • Flexible PTO with no accrued hours and no limit on vacation days for exempt employees.
  • 12 annual holidays and 10 days of sick leave.
  • Up to 4 weeks of bereavement leave.
  • 2 volunteer days off and 2 professional development days off.
  • 12 weeks of paid parental leave for all parents.
  • Medical, dental, and vision coverage with 75–95% employer cost coverage for employees and dependents.
  • Competitive target annual compensation of $131,250 to $235,156 plus equity and bonus potential.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Product Security Engineer

Modern Health 251-1K Health Care Providers & Services

Modern Health is hiring a remote Product Security Engineer to strengthen security and compliance across its mental health platform, applications, cloud infrastructure, and software development lifecycle.

Agile AWS Bash CI/CD Cybersecurity Datadog Django Flask GitLab HashiCorp Vault Packer Penetration Testing PostgreSQL Python Redis Terraform
1 day, 9 hours ago

Application Security Engineer - Senior

Banco Plata, S.A., Institución de Banca Múltiple. 1001-5000 Banking / financial services

Plata is seeking an Application Security Engineer to join its Information Security team and embed security controls, testing, and practices throughout the software development lifecycle.

Burp Suite CI/CD Kubernetes Microservices OWASP Penetration Testing
3 days, 9 hours ago

Senior Product Security Engineer

payabl. 51-250 Diversified Financial Services

Payabl is seeking a Senior Product Security Engineer to establish and embed product security across its payments engineering organization, integrating secure practices throughout the software development lifecycle.

AWS CI/CD Penetration Testing
3 days, 9 hours ago

Senior Product Security Engineer (Contract)

Iru Enterprise IT, cybersecurity, identity/security, endpoint management, compliance software

Iru is seeking a Senior Product Security Engineer for a 6-month, 40-hour-per-week contract to embed security throughout the software development lifecycle and help teams build secure-by-design products.

AWS Azure GCP GitHub Actions Kubernetes Microservices OAuth OpenID Connect
5 days, 8 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers