HighLevel

HighLevel

HighLevel provides an all-in-one sales and marketing platform that agencies can white label and resell, offering tools and resources designed to help businesses consolidate their marketing efforts and achieve their growth objectives.

Internet Software & Services
251-1K
Founded 2018
$60M raised

Description

  • Lead application security initiatives across HighLevel’s products and engineering teams.
  • Embed security standards and secure SDLC practices into development workflows.
  • Conduct architecture reviews, secure design assessments, and threat modeling for new features and platforms.
  • Perform security assessments for web, mobile, and API-based applications.
  • Partner with developers to identify, prioritize, and remediate security vulnerabilities.
  • Lead security reviews for AI/LLM-powered applications, agents, and integrations.
  • Develop guardrails for AI systems to address prompt injection, data leakage, insecure tool usage, model abuse, and emerging attacks.
  • Improve security tooling and automate security testing in CI/CD pipelines.
  • Champion secure coding practices through documentation, training, and developer enablement.
  • Mentor engineers and communicate security risks to technical and non-technical stakeholders.

Requirements

  • 8+ years of experience in cybersecurity, with deep expertise in application security and engineering-focused security initiatives.
  • Experience securing web, mobile (Android/iOS), and API (REST/GraphQL) environments.
  • Knowledge of OWASP standards and authentication protocols including OAuth 2.0, OIDC, JWT, and SAML.
  • Experience with threat modeling, secure design/code reviews, penetration testing, and architecture reviews.
  • Hands-on DevSecOps experience automating security in CI/CD pipelines.
  • Experience with container security in Kubernetes and Docker.
  • Experience managing security tooling such as SAST, DAST, SCA, and secret scanning.
  • Specialized expertise in AI/LLM security, including prompt injection, data leakage, model misuse, and insecure agent/tool integration.
  • Proficiency in Python, Go, JavaScript, or Bash.
  • Preferred: experience securing workloads on Google Cloud Platform (GCP), Terraform security, CSPM/CNAPP solutions, red teaming, security certifications such as CEH, OSCP, GWAPT, CISSP, or GCP Professional Cloud Security Engineer, and contributions to open-source security, bug bounty, or security research.

Benefits

  • Remote-first global work environment.
  • Opportunity to work on a platform serving over 1 million businesses.
  • Work across a large-scale engineering environment with complex systems and AI capabilities.
  • Equal Opportunity Employer status.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Engineer - Product

Wiz 251-1K IT Services

Wiz is seeking a Security Engineer for Product & Production Infrastructure to secure its cloud-native products, CI/CD systems, and production environments while helping shape security controls across the company.

AWS Azure CI/CD CloudFormation GCP Go Helm Kubernetes Pulumi Python Terraform
48 minutes ago

Senior Cloud Security Engineer - InfoSec

Mercury 251-1K Banks

Mercury is hiring a Cloud Security Engineer to design and automate cloud security controls and architecture that protect its AWS-based infrastructure while enabling the company to scale securely and efficiently.

AWS Cybersecurity
1 hour, 18 minutes ago

SOAR and AI Engineer - Managed Security

AHEAD 1K-5K IT Services

AHEAD is hiring a SOAR and AI Engineer to build and improve automation for its Managed Security operations, supporting security monitoring, incident response, and client-focused workflows.

AWS Azure Elasticsearch GCP IDS JSON LLM Machine Learning Python SIEM
1 hour, 18 minutes ago

[Job-30892] Senior Identity and Security Operations Developer, Brazil

CI&T 5K-10K Internet Software & Services

CI&T is seeking a Senior Identity and Security Operations Developer to help design, implement, and support identity and security platforms for enterprise environments focused on Zero Trust and secure access.

Active Directory AWS Azure Cybersecurity Kanban OAuth OpenID Connect Penetration Testing REST API SAML Scrum Secrets Management SOAP
1 hour, 33 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers