SmartRent

SmartRent

SmartRent provides smart technology solutions that deliver the ultimate smart building experience for real estate owners, managers, and residents. They offer a platform that enables property managers to control all smart devices in their properties, mo...

Real Estate
251-1K
Founded 2017
$102M raised

Description

  • Develop and execute an application security strategy aligned with business objectives and industry standards.
  • Maintain secure coding standards, security documentation, and application security processes.
  • Deliver application security and privacy training to development teams.
  • Review source code for vulnerabilities, insecure patterns, exposed secrets, and risks from AI-generated code.
  • Triage, reproduce, and support remediation of vulnerabilities identified through SAST, DAST, SCA, and manual analysis.
  • Manage security workflows, including prioritization, ticket tracking, and coordination with development and DevOps teams.
  • Maintain and improve the responsible disclosure and vulnerability reporting program.
  • Partner with developers on encryption, hashing, and secure key management practices.
  • Conduct threat modeling, attack-path analysis, application risk assessments, and adversarial security testing.
  • Investigate and mitigate application security incidents with SOC and engineering teams.
  • Advise on security and privacy controls for AWS infrastructure, applications, IoT hardware, and LLM integrations.
  • Research emerging cybersecurity risks and recommend mitigation strategies and security guardrails.

Requirements

  • 4–6 years of application security experience, including security policy development and collaboration with engineering or release teams.
  • Experience identifying and remediating vulnerabilities in Elixir, JavaScript, Ruby, Python, or similar languages.
  • Strong knowledge of OWASP Top 10, OWASP API Top 10, JWT, and OAuth.
  • Hands-on experience with SAST, DAST, and SCA tools such as GHAS, Burp Suite, or Fortra.
  • Experience with AWS security controls, web application firewalls, or similar technologies.
  • Experience managing or supporting vulnerability disclosure or bug bounty programs.
  • Strong written and verbal communication skills for explaining security requirements to technical teams.
  • Demonstrated analytical and problem-solving abilities in application security risk mitigation.
  • Preferred certifications include CSSLP, GIAC GWAPT, CEH, or equivalent.
  • Experience with Cloudflare, AWS security services, SDLC security integration, threat modeling, or application security architecture reviews.

Benefits

  • Medical, dental, vision, and life insurance with low deductibles and 75–100% employer contributions.
  • Flexible and generous paid time off.
  • 401(k) plan with employer contributions.
  • Paid parental leave.
  • Discounted pet insurance and legal services plans.
  • Employee stock purchase plan.
  • Open to candidates outside Arizona.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Engineer - Product

Wiz 251-1K IT Services

Wiz is hiring a Security Engineer for Product and Production Infrastructure to secure its cloud-native products, CI/CD systems, and production environments through reviews, vulnerability management, and detection and response operations.

AWS Azure Go Helm Kubernetes Pulumi Python Terraform
7 hours, 1 minute ago

Security Engineer - Product

Wiz 251-1K IT Services

Wiz is hiring a Security Engineer for Product and Production Infrastructure to secure its cloud-native products, CI/CD systems, and production environments through reviews, vulnerability management, and detection and response operations.

AWS Azure Go Helm Kubernetes Pulumi Python Terraform
7 hours, 1 minute ago

Staff Product Certification Manager

PQShield 11-50 Semiconductors & Semiconductor Equipment

PQShield is hiring an Experienced Security Certification Manager/Engineer to lead certification efforts for its RISC-V and post-quantum cryptography security IP platform.

CI/CD GitLab CI HubSpot
1 week, 1 day ago

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
1 week, 6 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers