Quanata

Quanata

Quanata is a software development company based in San Francisco, specializing in context-based insurance solutions. The company leverages AI, real-time telematics, and data science to enhance risk prediction, promote safer driving behaviors, and create modern insurance products. Quanata aims to transform the insurance industry by fostering positive behaviors and advancing digital experiences. The company develops a range of software platforms and tools for insurers. Their offerings include AI-powered risk assessment, telematics for driver monitoring, and claims solutions that optimize and automate processes. Quanata also focuses on customer engagement through personalized products and retention tools, supporting insurtech modernization with big data analytics and cloud-native platforms. With a team of around 26 professionals, Quanata draws on talent from Silicon Valley to drive innovation in the insurance sector.

information technology & services
201-500

Description

  • Partner with a product portfolio to manage product security, including AI/ML-specific security concerns and cross-functional work with data science teams.
  • Perform security design reviews and threat modeling for APIs, web features, and service integrations.
  • Integrate SAST, SCA, and DAST tools into CI/CD pipelines and developer workflows.
  • Review source code and deployment configurations for security vulnerabilities.
  • Collaborate with developers to triage, fix, and validate vulnerability findings.
  • Participate in cross-functional incident response and remediation planning.
  • Draft and maintain application security guidance for engineering teams and security champions.
  • Contribute to security awareness and enablement across the engineering organization.
  • Develop application security integrations and automation solutions, including ASVS scanning and Burp Suite Enterprise.
  • Support application security integration reviews, SaaS security assessments, and open-source software reviews.

Requirements

  • Bachelor’s degree or equivalent relevant experience.
  • 6-8 years of experience in application security or full-stack development with security expertise.
  • Strong understanding of secure coding in JavaScript/TypeScript, Node.js, and web standards.
  • Familiarity with application risk and vulnerabilities, including OWASP Top 10, API security, and SSRF.
  • Experience with code scanning tools such as CodeQL, Semgrep, SonarQube, or Snyk.
  • Ability to read and debug complex codebases across the stack.
  • Clear and thoughtful communication skills with the ability to guide engineers at all levels.
  • Working knowledge of offensive security testing such as pentesting or bug bounties.
  • Experience with GraphQL security is preferred.
  • Participation in security champions programs or secure SDLC rollouts is preferred.
  • Contributions to open-source security tooling are preferred.
  • Familiarity with infrastructure-as-code and container security is preferred.

Benefits

  • Salary range of $220,000 to $350,000.
  • Medical, dental, vision, life insurance, and supplemental income plans for employees and dependents.
  • Headspace app subscription and a monthly wellness allowance.
  • 401(k) plan with company match.
  • One-time $2,000 home office equipment stipend.
  • Four weeks of PTO in the first year.
  • Twelve weeks of fully paid parental leave for birthing and non-birthing parents.
  • Up to $5,000 per year for professional learning, continuing education, and career development, plus LinkedIn Learning and BetterUp access.
  • Remote-first work environment with flexibility to work from anywhere in the U.S., excluding U.S. territories.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Blockchain Security Engineer

Coinbase 1K-5K Capital Markets

Coinbase is hiring a Blockchain Security Engineer for its Decentralized Financial Security Team to help design and secure upcoming crypto products and features used by millions of customers.

Blockchain Databricks Generative AI Snowflake
10 hours, 10 minutes ago

Application Security Engineer - Pentester

Veeam Software 1K-5K Internet Software & Services

Veeam is hiring an Application Security Engineer (Offensive Testing) to lead penetration testing and DAST for Veeam Data Cloud products and help engineering teams remediate exploitable web and API security issues.

Burp Suite CI/CD OAuth OpenID Connect Penetration Testing SAML
10 hours, 55 minutes ago

Senior Application Security Engineer

Brex 1K-5K Diversified Financial Services

Brex is hiring a Senior Application Security Engineer to secure its financial platform by identifying vulnerabilities, improving secure development practices, and helping protect new AI-driven product features.

AWS GraphQL gRPC Kotlin Kubernetes Penetration Testing Python
12 hours, 25 minutes ago

AppSec Engineer I

LivePerson 1K-5K Internet Software & Services

LivePerson is hiring an Application Security specialist to test and strengthen the security of its cloud and on-premises applications and environments as part of the AppSec team.

Burp Suite GCP Java Node.js Penetration Testing Python
12 hours, 55 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers