Movable Ink is hiring a Product Security Engineer to help secure their codebases, CI/CD pipelines, and development practices. The role involves implementing and maintaining static application security testing, configuring software composition analysis, and integrating security scanning into CI/CD pipelines.
Requirements
- 2+ years of experience in application security, DevSecOps, or a security-focused software engineering role
- Hands-on experience with SAST, SCA, or secrets scanning tools (Semgrep, Dependabot, Snyk, or similar)
- Familiarity with CI/CD pipelines and GitHub Actions
- Understanding of common web application vulnerabilities (OWASP Top 10) and how to detect/prevent them
- Experience reading and reviewing code in at least one language (Ruby, Python, JavaScript, or Go preferred)
- Comfortable navigating codebases and working with engineering teams to explain and prioritize security findings
- Strong written communication skills for documentation and customer-facing security responses
- Self-motivated and able to manage competing priorities in a fast-paced environment
Benefits
- Full range of medical, financial, and/or other benefits
- Base pay range: $170,000-$200,000/year, plus additional bonus