ClearCapital.com,

ClearCapital.com,

Clear Capital is a real estate valuation technology company that provides valuation services, data and analytics tools, and a full suite of appraisal services. They offer intelligent valuation solutions for properties nationwide, serving the mortgage a...

Real Estate
1-10

Description

  • Plan and perform application security testing across all phases of the software development lifecycle.
  • Assess vulnerabilities and recommend risk-mitigating solutions, using automation to improve testing and remediation efficiency.
  • Communicate findings, risks, and recommendations to stakeholders and track progress against SLAs and business metrics.
  • Lead AI security initiatives, including threat modeling for production LLM stacks and auditing third-party models and APIs.
  • Participate in product and application projects with business and technical teams to improve security early in development.
  • Collaborate with architects and development teams to drive secure design practices using established standards and frameworks.
  • Define, maintain, and follow an automated and repeatable security review process.
  • Monitor the security community for emerging issues and new testing tactics.
  • Train developers and junior application security engineers on common weaknesses and secure practices.
  • Assess the security of business-to-business initiatives, third-party relationships, outsourced solutions, and vendors.

Requirements

  • 4+ years of related experience.
  • Bachelor’s degree in a technically related field such as Computer Science, Information Technology, or Software Engineering, or equivalent work experience.
  • Technical and analytical background in software development and scripting languages such as Java, Python, C++, Ruby, JavaScript, PowerShell, or PHP.
  • Hands-on experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools.
  • Experience with threat modeling, vulnerability testing, penetration testing, API security, OWASP Top Ten mitigation, and securing applications in AWS and private cloud environments.
  • Relevant certifications such as C|ASE, CSSLP, GWAPT, OSCP, or equivalent.
  • Experience with security and compliance frameworks such as ISO 27001, NIST, GDPR, CIS, or SOC 2.

Benefits

  • Base salary range of $111,000 to $144,400 annually, depending on location, experience, and qualifications.
  • Eligibility for a company profit-sharing bonus program, communication stipends, and referral bonuses.
  • Comprehensive medical, dental, and company-paid vision insurance.
  • 401(k) retirement plan with employer match.
  • Paid time off and paid holidays.
  • Employee assistance and wellness programs, including company-paid access to Galileo for virtual primary care and Rula for virtual mental health resources.
  • Company-paid short-term disability coverage and company contributions to health savings funds for eligible high-deductible health plan participants.
  • Career and skill development resources to support professional growth.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Manager, Product Security

Tines 51-250 Construction & Engineering

Tines is seeking a Senior Manager, Product Security to lead and scale its product security program for cloud-native, AI-forward products while partnering with engineering and product leaders to manage risk and support growth.

AWS CI/CD DevSecOps Docker Kubernetes Penetration Testing Ruby Rust TypeScript
1 day, 10 hours ago

Application Security Engineer

Glean 11-50 Internet Software & Services

Glean is hiring a remote Application Security Engineer to lead vulnerability management and strengthen software supply-chain security across its Work AI platform.

AWS Burp Suite CI/CD Cybersecurity GCP Kubernetes Microservices
1 day, 10 hours ago

Lead Application Security Engineer

Remofirst 11-50 Professional Services

RemoFirst is hiring an application and cloud security engineer to secure its global Employer of Record platform, customer identity systems, infrastructure, and emerging AI initiatives across a distributed engineering organization.

AWS Django FastAPI Java Kafka Kubernetes MongoDB OpenID Connect Penetration Testing PostgreSQL Python RabbitMQ REST API SAML Secrets Management Spring Boot Terraform
1 day, 11 hours ago

Application Security Engineer II

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring an Application Security Engineer to triage and validate vulnerability submissions for major clients, communicate with researchers and customers, and support incident response across diverse security programs.

Burp Suite Nmap
2 days, 11 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers