Lever

Lever

Lever is a leading Talent Acquisition Suite that provides modern hiring and talent management solutions. Their applicant tracking system (ATS) with candidate relationship management capabilities empowers hiring teams to streamline recruiting efforts an...

Professional Services
251-1K
Founded 2012
$123M raised

Description

  • Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs.
  • Drive the vulnerability lifecycle through threat modeling, security assessments, and validation of remediation actions.
  • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services.
  • Review and analyze web server and application logs to detect anomalies and indicators of compromise.
  • Implement automation scripts for threat intelligence integration and application security monitoring.
  • Participate in audits, risk assessments, and security authorization activities tied to federal frameworks.

Requirements

  • Minimum of 3 years of experience in web application security, application security engineering, or secure software development lifecycle work.
  • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation.
  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, REST APIs, and SQL.
  • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts.
  • Strong understanding of the OWASP Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools.
  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies.
  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field.
  • Ability to meet federal screening and suitability requirements prior to start.
  • Current security certifications maintained for a minimum of 5 years, such as CSSLP, GWEB, CASE, OSWE, OSCP, Security+, or GSEC.

Benefits

  • Medical coverage through Cigna with 4 plan options.
  • Dental coverage through Cigna PPO Base and Buy-Up plans.
  • Vision coverage through Principal VSP Choice Network.
  • 11 paid federal holidays for full-time employees.
  • PTO accrual starting at 15 days per year.
  • Annual training allowance for job-related training or education.
  • 401(k) with multiple Fidelity fund choices and a company match.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Mobile Software Engineer (iOS / Android), Identity & Security - India

JumpCloud 251-1K Internet Software & Services

JumpCloud is hiring a Senior Mobile Software Engineer to build secure native iOS and Android applications that protect enterprise identities through authentication, password management, and identity verification.

Android AWS CI/CD Encryption Espresso GCP GitHub Actions Go iOS Kotlin OpenID Connect REST API Swift WebSockets XCTest
2 hours, 47 minutes ago

Staff Application Security Engineer (R5949)

Bitly 51-250 Internet Software & Services

Shield AI is seeking a Staff Application Security Engineer to establish and scale a developer-centered secure software development and software supply-chain security program across its defense-technology engineering organization.

Burp Suite DevSecOps Kubernetes Microservices SonarQube
3 hours, 17 minutes ago

Application Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a remote Application Security Engineer to triage and validate vulnerability submissions for large-scale bug bounty programs while coordinating with clients and security researchers.

Burp Suite Nmap
1 day, 2 hours ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI/ML security, secure architecture, and assurance practices across the product lifecycle.

CI/CD DevSecOps Encryption Java JavaScript Kubernetes Python SAML Secrets Management TLS
1 day, 2 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers