Application Security Engineer / Architect (DevSecOps)
Job description
About the role
Clear Street is on the lookout for an Application Security Engineer / Architect who will play a pivotal role in strengthening the security architecture of our offerings. In this role, you will work closely with engineering teams throughout the product development process, emphasizing security in applications and cloud environments within a DevSecOps framework.
Key facts
What you'll do
- Assume responsibility for implementing security protocols within CI/CD pipelines, which includes static and dynamic application security testing, software composition analysis, and the detection of secrets.
- Partner with engineering teams to discover and remediate vulnerabilities present in application source code.
- Manage the vulnerability assessment process, which involves evaluating scanner results, prioritizing risks, monitoring remediation actions, and analyzing trends.
- Spearhead cloud security initiatives, ensuring that best practices are adhered to across identity and access management (IAM), network controls, storage security, and workload protection.
- Maintain and enhance security tools, including static application security testing (SAST) and dynamic application security testing (DAST) scanners, along with container security solutions.
- Create automation and AI-enhanced tools to improve DevSecOps workflows.
- Collaborate with Infrastructure Engineering teams to set secure infrastructure-as-code standards and enforce these through policy-as-code practices.
- Engage in threat modeling and security design evaluations for new features and services.
- Support incident response activities related to application and cloud security breaches.
- Contribute to the development of security documentation, operational runbooks, and guidance materials for developers.
Requirements
- At least 7 years of experience in DevSecOps, application security, or cloud security engineering.
- Hands-on experience with CI/CD platforms such as GitHub Actions, GitLab CI, or Jenkins.
- Proficient in one of the major cloud service providers (AWS, Azure, or GCP) and knowledgeable about their security offerings.
- Familiarity with SAST/SCA tools like Semgrep, Snyk, Checkmarx, or Veracode, along with the ability to analyze and interpret their results.
- Understanding of container security and Kubernetes, including image scanning and role-based access control (RBAC).
- Scripting skills in languages such as Python or Bash for automation tasks.
- Experience with infrastructure-as-code tools (Terraform, CloudFormation, Pulumi) and policy frameworks (OPA/Rego, Checkov).
- Knowledge of the OWASP Top 10, Common Weakness Enumeration (CWE), and prevalent vulnerability types.
- Strong communication skills, with the ability to convey security risks to audiences without a technical background.
Your performance will be evaluated not through traditional server management metrics, but by the effectiveness and satisfaction of our engineering teams.
Nice to have
- Familiarity with security frameworks and compliance standards such as NIST, ISO 27001, or PCI-DSS.
- Experience in conducting security training sessions or workshops for development teams.
- Knowledge of advanced threat detection and response techniques.
Skills & tools
- Proficiency in security tools and technologies relevant to application and cloud security.
- Strong understanding of secure coding practices and methodologies.
- Familiarity with agile development methodologies and their integration with security practices.
Practical notes
The compensation for this role ranges from $175,000 to $210,000. This range represents the base salary for the position at Clear Street, with the final offer influenced by factors such as experience, skill set, and geographic location. It is important to note that this range pertains solely to base salary and does not encompass additional compensation components like bonuses or equity.
Clear Street provides competitive remuneration packages, including equity options, 401k matching, generous parental leave policies, and comprehensive medical, dental, and vision insurance. We emphasize in-person collaboration, requiring employees to be present in the office four days a week. In-office benefits include lunch stipends, well-stocked kitchens, social events, and a prime location with breathtaking views.
Our dedication is to our employees. We foster a collaborative culture that supports one another through challenges and celebrates achievements. We believe that a diverse workforce - encompassing a variety of ideas, cultures, and experiences - is essential for success in today's workplace. We are committed to creating an inclusive environment and are proud to be an equal opportunity employer.