Staff Application Security Engineer

SPAN designs and builds products for home electrification and decarbonization to combat climate change.
$160,000 - $215,000
Security
Staff Software Engineer
In-Person
7+ years of experience
Enterprise SaaS · Cybersecurity

Description For Staff Application Security Engineer

SPAN is a mission-driven company focused on electrification and decarbonization through innovative home energy solutions. As a Staff Application Security Engineer, you'll play a crucial role in building and enhancing SPAN's application security program. The position offers an opportunity to work at the intersection of clean energy and cybersecurity, ensuring the security of applications that contribute to environmental sustainability.

The role demands expertise in application security, with responsibilities ranging from threat modeling and code reviews to implementing security controls and maintaining compliance. You'll work closely with development teams to integrate security best practices into the software development lifecycle, while staying current with the latest security threats and best practices.

The company offers a competitive compensation package including equity, comprehensive benefits, and a flexible work environment. Located in San Francisco's SoMa neighborhood, SPAN provides a collaborative atmosphere where creative thinking and teamwork are valued. The company is committed to diversity and equal opportunity, making it an ideal workplace for talented individuals passionate about both security and renewable energy.

Working at SPAN means joining a well-funded, venture-backed company with strong growth potential. The role offers technical challenges in securing critical infrastructure while contributing to the broader mission of environmental sustainability. The company culture emphasizes work-life balance with benefits like unlimited PTO, monthly social events, and various employee resource groups.

Last updated a month ago

Responsibilities For Staff Application Security Engineer

  • Developing comprehensive application security strategy
  • Perform secure design and code reviews
  • Lead and execute SAST/DAST/SCA efforts
  • Collaborate with development teams to integrate security best practices
  • Perform threat modeling on existing and upcoming feature sets
  • Develop and enforce authentication and authorization posture
  • Design, implement, and maintain application security controls
  • Ensure compliance with regulatory requirements and industry standards
  • Stay current with latest application security threats and best practices

Requirements For Staff Application Security Engineer

Python
Node.js
Kotlin
  • Bachelor's Degree in Computer Science, Information Assurance, Cyber Security, or related field
  • 7+ years of experience in security engineering or operations role
  • Deep understanding of web and mobile application vulnerabilities and defenses
  • Hands-on experience with application security scanning tools
  • Expertise in web, mobile, and API security
  • Effective communication with technical and non-technical audiences
  • Proficient in writing production-quality code in Python, Kotlin or NodeJS
  • Experience in developing threat models (e.g., STRIDE, DREAD)

Benefits For Staff Application Security Engineer

Equity
Medical Insurance
Dental Insurance
Vision Insurance
Parental Leave
  • Competitive compensation + equity grants
  • 100% employee premiums for base plans on medical, dental, vision
  • Parental leave up to six months
  • Comfortable office space near BART and Caltrain
  • Monthly social events
  • Flexible hours
  • One holiday per month
  • Unlimited PTO

Interested in this job?

Jobs Related To SPAN Staff Application Security Engineer

Staff Software Engineer, Secure Development Engineering

Lead security engineering initiatives at Airbnb, architecting and implementing secure development solutions that protect millions of users while empowering thousands of developers.

Staff Security Engineer, EMEA

Lead security investigations and threat detection at Airbnb EMEA, developing scalable tools and mentoring team members in forensic analysis and incident response.

Senior Cloud Security Architect

Senior Cloud Security Architect position at Google's Mandiant division, focusing on cybersecurity transformation services and enterprise security architecture.

Strategic Risk Manager, Strategic Command

Strategic Risk Manager position at Google focusing on user safety, crisis management, and risk mitigation across Google's products.

Senior Staff Security Architect, Platform Security

Lead security architecture for Google Pixel phones, focusing on user protection and privacy through innovative mobile security solutions.