Huntress

Senior Application Security Engineer

United States

$140,000 – $165,000Compensation
Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
Cybersecurity, Information Technology, SoftwareIndustries

About Huntress

Huntress is a fully remote, global team of passionate experts and ethical badasses on a mission to break down the barriers to cybersecurity. Whether creating purpose-built security solutions, hunting down hackers, or impacting our community, our people go above and beyond to change the security game and make a real difference.

Founded in 2015 by former NSA cyber operators, Huntress protects all businesses—not just the 1%—with enterprise-grade, fully owned, and managed cybersecurity products at the price of an affordable SaaS application. The Huntress difference is our One Team advantage: our technology is designed with our industry-defining Security Operations Center (SOC) in mind and is never separated from our service.

We protect 4M+ endpoints and 1M+ identities worldwide, elevating underresourced IT teams with protection that works as hard as they do. As long as hackers keep hacking, Huntress keeps hunting.

Job Overview

Reports to: Senior Manager, Internal Security Location: Remote US Compensation: $140,000 to $165,000 base plus bonus and equity

What You’ll Do

The Huntress Information Technology and Security team has the unique honor of securing the infrastructure that enables us to confidently protect over 4 million (and rapidly growing) of our partners’ endpoints. As our application security engineer, you will be responsible for implementing a robust application security program across internal development teams. You will mentor and guide teams to think about application security earlier in the development process and ensure that vulnerabilities are remediated before and after they make it into production.

Responsibilities

  • Design, evaluate, and implement software security standards
  • Build tools, processes, and solutions that drive continuous improvement in the Huntress security platform
  • Influence and guide teams on secure-by-design principles by actively participating in architectural and design discussions to identify and mitigate security risks early in the development lifecycle
  • Act as a security subject matter expert, providing a final set of eyes on high-risk pull requests (PRs)
  • Lead and conduct secure development training for engineering teams, educating them on common vulnerabilities, bugs, and best practices to proactively embed security throughout the software development lifecycle
  • Collaborate with development teams to drive the adoption of security tools and processes, fostering a culture of security awareness and shared responsibility.
  • Advocate for and gain buy-in from engineering stakeholders to implement security changes and improvements within existing development processes
  • Assist teams in reproducing, triaging, and addressing application security vulnerabilities
  • Partner with DevOps to ensure a robust and secure code delivery pipeline
  • Own our Vulnerability Disclosure Program, ensuring dazzling service to third-party security researchers
  • Assist in the development of security processes and automated tooling that prevent entire classes of security vulnerabilities
  • Implement an auditable Application Security program (BSIMM, SAMM, etc.)

What You Bring To The Team

  • Demonstrable experience leading application security design and architecture reviews with a key focus on Ruby on Rails
  • Extensive experience working with developers and driving application security standards
  • Expertise owning software vulnerability management from triage, assessment, and analysis to remediation through collaboration with internal development teams
  • Experience securing CI/CD pipelines by enabling strong security controls through the implementation of off-the-shelf and custom-built tooling
  • Experience deploying, tuning, and automating common security testing tools within SAST, DAST, SCA, and IaC functional areas
  • Expertise in threat modeling frameworks and processes
  • Familiarity with IaaS/PaaS cloud infrastructure, infrastructure as code, and software-oriented architecture

Bonus Points

  • Expertise in OS, agent, and me

Skills

Application Security
Software Security Standards
Secure-by-Design Principles
Vulnerability Remediation
Security Platform Development
Cybersecurity
Risk Mitigation

Huntress

Managed endpoint detection and response services

About Huntress

Huntress provides managed endpoint detection and response (EDR) services to protect businesses from cyber threats, particularly ransomware. Their service includes 24/7 monitoring of clients' systems to identify potential cyberattacks. When a threat is detected, their team of security experts verifies the activity and alerts the client only if necessary, reducing the number of false positives that can occur with other services. In addition to threat hunting, Huntress offers security awareness training and resources like eBooks and webinars to educate employees about cybersecurity risks. Their commitment to high customer support and personalized reporting distinguishes them from competitors in the cybersecurity field. The goal of Huntress is to enhance the security posture of businesses by providing effective monitoring and education against cyber threats.

Columbia, MarylandHeadquarters
2015Year Founded
$281.8MTotal Funding
SERIES_DCompany Stage
CybersecurityIndustries
501-1,000Employees

Benefits

100% remote work environment
Generous PTO including vacation, sick time, and paid holidays
12 weeks paid parental leave
Highly competitive and comprehensive medical, dental, and vision benefits plans
401(k) with 5% contribution regardless of employee contribution
Life and Disability insurance plans
Stock options for all full-time employees
One-time $500 stipend to build/upgrade home office
Annual allowance for education and professional development assistance
$75 USD/month digital reimbursement
Access to both Udemy and BetterUp platforms for coaching, personal, and professional growth

Risks

Exploitation of security flaws in data transfer tools could affect Huntress's clients.
Social engineering attacks may bypass AI security measures, posing a risk to Huntress.
Difficulty in finding specialized talent could hinder Huntress's expansion efforts.

Differentiation

Huntress offers a 24/7 Security Operations Center for continuous threat monitoring.
The company integrates with Microsoft 365, enhancing security for businesses using Microsoft tools.
Huntress eliminates false positives by verifying threats before alerting clients.

Upsides

Huntress raised $180 million to expand and accelerate product development.
Recognition in Inc.'s Power Partner Awards boosts Huntress's market credibility.
Increased demand for cybersecurity due to remote work benefits Huntress's growth.

Land your dream remote job 3x faster with AI