Security Engineer
- Loom
- Full Time
- Engineering
- Remote-US
- Other
Remote Job Description
As a member of the security team at Loom, you will be responsible for leading and implementing the various initiatives that relate to improving Loom's security. We will achieve that by working and collaborating with cross-functional teams to provide guidance on security best practices and help with security automation to scale security for engineering initiatives. The Security Team is focused on enabling our engineering teams to build and ship secure products. This is done by designing, building, and deploying state of the art security alongside our product and infrastructure teams.
We're looking for experienced Engineers to join our fast moving Security Team. As part of the security team you will get to work on some interesting problems around SAST, DAST, SCA and building automations to assists Kubernetes and AWS security.
Responsibilities
- Perform application design and code reviews with product teams.
- Build, deploy and maintain security tooling.
- Improve existing threat hunting and security detection across our platform.
- Drive our bug bounty program with HackerOne.
- Be an incident commander for security incidents to triage, remediate P0 security issues. Identify proactive defense strategies.
- Work with stakeholders across the organization, provide security training and outreach to our internal development teams to achieve a consistently high security bar
- Experience with GDPR, CCPA and SOC2 compliance
- Experience with SIEM platforms and the ability to extend their functionality
What We're Looking For
- 3+ years of relevant security experience in security consulting or in product/infrastructure security demonstrating strong application security fundamentals.
- Solid understanding of application security concepts and best practices.
- Ability to work well cross-functionally, and communicate with audiences who may not have a security background.
- Willingness to learn new technologies or languages.
- Experience with security reviews and threat modeling.
- Ability to work with a high degree of autonomy.