Workstream is a mission-driven company that believes in building premium, modern software solutions for hourly businesses. As a Security Engineer, you will provide security guidance to Engineering and Product teams, build threat models, and conduct risk assessments for new features and services.
Requirements
- 4+ years of security experience
- 4+ years of software development experience
- Strong understanding of Web application security, including hands-on exploitation skills coupled with defensive skills
- Familiarity with secure development practices and security testing techniques (SAST, DAST, fuzzing, etc.)
- Familiarity with infrastructure and systems security domains
- Familiarity with web application security defense techniques and technologies (WAF, RASP, sanitization/validation, etc.)
- Familiarity with microservices architectures, platforms, and 12-factor design
- Familiarity with relevant technologies (listed below)
- Strong understanding of Ruby on Rails or NodeJS. Knowledge of mobile development, such as Flutter and React Native will be nice to have.
- Modest ability to build tools and automation in Python or other languages.
- Ability to explain complex security issues and their impact to diverse audiences.
- Be a fast learner and have experience partnering with cross-functional teams.
- BA/BS in Computer Science or similar technical degree or equivalent experience.
Benefits
- Competitive salary and equity
- Learning/development stipend
- Unlimited PTO
- Hybrid Office/WFH schedule