Lever

Lever

Lever is a leading Talent Acquisition Suite that provides modern hiring and talent management solutions. Their applicant tracking system (ATS) with candidate relationship management capabilities empowers hiring teams to streamline recruiting efforts an...

Professional Services
251-1K
Founded 2012
$123M raised

Description

  • Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs.
  • Drive the vulnerability lifecycle through threat modeling, security assessments, and validation of remediation actions.
  • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services.
  • Review and analyze web server and application logs to detect anomalies and indicators of compromise.
  • Implement automation scripts for threat intelligence integration and application security monitoring.
  • Participate in audits, risk assessments, and security authorization activities tied to federal frameworks.

Requirements

  • Minimum of 3 years of experience in web application security, application security engineering, or secure software development lifecycle work.
  • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation.
  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, REST APIs, and SQL.
  • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts.
  • Strong understanding of the OWASP Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools.
  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies.
  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field.
  • Ability to meet federal screening and suitability requirements prior to start.
  • Current security certifications maintained for a minimum of 5 years, such as CSSLP, GWEB, CASE, OSWE, OSCP, Security+, or GSEC.

Benefits

  • Medical coverage through Cigna with 4 plan options.
  • Dental coverage through Cigna PPO Base and Buy-Up plans.
  • Vision coverage through Principal VSP Choice Network.
  • 11 paid federal holidays for full-time employees.
  • PTO accrual starting at 15 days per year.
  • Annual training allowance for job-related training or education.
  • 401(k) with multiple Fidelity fund choices and a company match.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
21 hours, 56 minutes ago

Senior Application Security Engineer

Canopy 51-250 Internet Software & Services

Canopy is hiring a Senior Application Security Engineer to help secure its remote Utah-based SaaS platform for accounting firms, with a focus on hardening infrastructure, applications, observability, and the software supply chain.

AWS CI/CD Kubernetes Network Security SIEM WAF
22 hours, 41 minutes ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
2 days, 21 hours ago

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
2 days, 22 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers