At Vanta, our mission is to secure the internet and protect consumer data. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. As a Senior Security Engineer at Vanta, you'll own projects with impact across the business to help us run an efficient and highly effective security team. The security team at Vanta ensures that we are a trusted and trustworthy steward of sensitive data. We also contribute subject matter expertise to the product, sales, marketing, support, and engineering functions, given the nature of our business.
You'll join Vanta's Security organization, which provides essential security operational services, is directly involved in the software development process and building tools to make it easy for developers to ship products securely, sets policies and standards regarding enterprise-wide security requirements, and offers advisory services to enable our business to thrive while effectively managing risk.
What you'll do as a Senior Security Engineer at Vanta:
- Participate in team exercises to identify potential security risks, including threat modeling and tabletop scenarios
- Contribute to complex prioritization discussions around which risks are the most important to solve next
- Plan projects to address the risks we prioritize, and coordinate with cross-functional stakeholders across the company to execute those projects
- Build maintainable programs to implement operational excellence where ongoing work is needed to achieve our goals (e.g. vulnerability management)
- Collaborate with engineers to review project plans and pull requests for potential security concerns and improvements
- Build, customize, and run tools to increase the maturity of our security program without adding undue friction to the company's operations
- Support ongoing bug bounty and penetration testing programs
- Establish and maintain a network of security champions
- Understand security knowledge gaps of the development organization and help to deliver training to address gaps
- Provide input into architectural discussions to enable teams to innovate in a secure and repeatable manner
How to be successful in this role:
- A track record of independent ownership of areas of responsibility
- Experience with threat modeling, red teaming, penetration testing, or other means of identifying security issues
- Experience writing code, and an ability to read code to find security flaws
- Strong collaboration and communication skills, with deep developer empathy
- Highly organized project management skills
If you're someone who has high initiative and enjoys problem solving while having impact at a high-growth company, we would love to hear from you!