ClearCapital.com,

ClearCapital.com,

Clear Capital is a real estate valuation technology company that provides valuation services, data and analytics tools, and a full suite of appraisal services. They offer intelligent valuation solutions for properties nationwide, serving the mortgage a...

Real Estate
1-10

Description

  • Plan and perform application security testing across all phases of the software development lifecycle.
  • Assess vulnerabilities and recommend risk-mitigating solutions, using automation to improve testing and remediation efficiency.
  • Communicate findings, risks, and recommendations to stakeholders and track progress against SLAs and business metrics.
  • Lead AI security initiatives, including threat modeling for production LLM stacks and auditing third-party models and APIs.
  • Participate in product and application projects with business and technical teams to improve security early in development.
  • Collaborate with architects and development teams to drive secure design practices using established standards and frameworks.
  • Define, maintain, and follow an automated and repeatable security review process.
  • Monitor the security community for emerging issues and new testing tactics.
  • Train developers and junior application security engineers on common weaknesses and secure practices.
  • Assess the security of business-to-business initiatives, third-party relationships, outsourced solutions, and vendors.

Requirements

  • 4+ years of related experience.
  • Bachelor’s degree in a technically related field such as Computer Science, Information Technology, or Software Engineering, or equivalent work experience.
  • Technical and analytical background in software development and scripting languages such as Java, Python, C++, Ruby, JavaScript, PowerShell, or PHP.
  • Hands-on experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools.
  • Experience with threat modeling, vulnerability testing, penetration testing, API security, OWASP Top Ten mitigation, and securing applications in AWS and private cloud environments.
  • Relevant certifications such as C|ASE, CSSLP, GWAPT, OSCP, or equivalent.
  • Experience with security and compliance frameworks such as ISO 27001, NIST, GDPR, CIS, or SOC 2.

Benefits

  • Base salary range of $111,000 to $144,400 annually, depending on location, experience, and qualifications.
  • Eligibility for a company profit-sharing bonus program, communication stipends, and referral bonuses.
  • Comprehensive medical, dental, and company-paid vision insurance.
  • 401(k) retirement plan with employer match.
  • Paid time off and paid holidays.
  • Employee assistance and wellness programs, including company-paid access to Galileo for virtual primary care and Rula for virtual mental health resources.
  • Company-paid short-term disability coverage and company contributions to health savings funds for eligible high-deductible health plan participants.
  • Career and skill development resources to support professional growth.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Product Security Engineer

Modern Health 251-1K Health Care Providers & Services

Modern Health is hiring a remote Product Security Engineer to strengthen security and compliance across its mental health platform, applications, cloud infrastructure, and software development lifecycle.

Agile AWS Bash CI/CD Cybersecurity Datadog Django Flask GitLab HashiCorp Vault Packer Penetration Testing PostgreSQL Python Redis Terraform
1 day, 14 hours ago

Application Security Engineer - Senior

Banco Plata, S.A., Institución de Banca Múltiple. 1001-5000 Banking / financial services

Plata is seeking an Application Security Engineer to join its Information Security team and embed security controls, testing, and practices throughout the software development lifecycle.

Burp Suite CI/CD Kubernetes Microservices OWASP Penetration Testing
3 days, 14 hours ago

Senior Product Security Engineer

payabl. 51-250 Diversified Financial Services

Payabl is seeking a Senior Product Security Engineer to establish and embed product security across its payments engineering organization, integrating secure practices throughout the software development lifecycle.

AWS CI/CD Penetration Testing
3 days, 14 hours ago

Senior Product Security Engineer (Contract)

Iru Enterprise IT, cybersecurity, identity/security, endpoint management, compliance software

Iru is seeking a Senior Product Security Engineer for a 6-month, 40-hour-per-week contract to embed security throughout the software development lifecycle and help teams build secure-by-design products.

AWS Azure GCP GitHub Actions Kubernetes Microservices OAuth OpenID Connect
5 days, 13 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers