Jobs
>
San Francisco

    Security Engineer II - San Francisco, United States - NerdWallet

    Default job background
    Description

    We are seeking a Security Engineer II to join our Application Security team. The Application Security team enables NerdWallet's mission, to provide clarity for all of life's financial decisions, by taking steps to ensure the products and services we design and build safeguard our user's data and trust.

    In this role, you can expect to partner with technical teams across the company, executing on initiatives that mitigate risk and prevent harm to user trust throughout the lifecycle of products. You'll have the opportunity to mature the tools, workflows, and standards that lead to secure software coding practices, while providing a phenomenal developer experience and empowering partners to take ownership of the security posture of their products.

    The right candidate will be eager to help engineers secure their software, have a desire to empower developers, and be a terrific collaborator maturing our security posture in meaningful ways. If you would like to develop your security skills in a supportive environment and contribute to maturing an organization's security program, we encourage you to apply

    This role will report to a Business Information Security Officer.

    If you were here 6 months ago, here are some things you might have worked on:

    • Designed and Implemented a secret scanner in the CI/CD
    • Helped triage and respond to security events and findings identified by various application security tools
    • Rolled out a Content-Security-Policy response header for various applications

    Where you can make an impact:

    • Help scale our application security program through automation and developer empowerment
    • Influence engineering and product partners to remediate security gaps across multiple functional areas while balancing company and security needs
    • Build tools and processes to drive greater security posture visibility for leadership
    • Review developer pull requests for adherence to security best practices
    • Support operational work in response to security incidents

    You are:

    • Familiar with industry standards, risk mitigation techniques, and new developments within application security, e.g. OWASP Top 10
    • Pragmatic in your approach to reducing risk in a manner that incorporates business and product needs that balances time and risk reduction
    • Asking questions, seeking guidance, and soliciting feedback when clarification is needed about assigned work or discussion topics
    • Continuously training to understand application security fundamentals and goals for a company
    • Committed to fostering a respectful, blameless, and collaborative work environment and are receptive to constructive feedback from peers and mentors

    Your experience:


    We recognize not everyone will meet all of the criteria. If you meet most of the criteria below and you're excited about the opportunity and willing to learn, we'd love to hear from you.

    • 2+ years of experience in a professional application security engineering role and experience developing software deployed in a cloud environment, especially AWS
    • Identified, triaged, and remediated security vulnerabilities
    • Proficient in Python
    • Comfortable reading JavaScript
    • Comfort with learning new languages as needed

    Where:

    • This role is remote, based in the U.S.
    • We believe great work can be done anywhere. No matter where you are based, NerdWallet offers benefits and perks to support the physical, financial, and emotional well being of you and your family

    What we offer:


    Work Hard, Stay Balanced (Life's a series of balancing acts, eh?)

    • Industry-leading medical, dental, and vision health care plans for employees and their dependents
    • Rejuvenation Policy – Flexible Time Off + 13 holidays + 4 Mental Health Days Off
    • New Parent Leave for employees with a newborn child or a child placed with them for adoption or foster care
    • Mental health support through Headspace
    • Financial wellness, guidance, and unlimited access to a Certified Financial Planner (CFP) through Northstar
    • Paid sabbatical for Nerds to recharge, gain knowledge and pursue their interests
    • Health and Dependent Care FSA and HSA Plan with monthly NerdWallet contribution
    • Weekly Virtual Bootcamp, Yoga, and Mindfulness Meditation sessions
    • Monthly Wellness Stipend, Cell Phone Stipend, and Wifi Stipend

    Have Some Fun (Nerds are fun, too)

    • Nerd-led group initiatives – Intramural Sports, Employee Resource Groups for Parents, Diversity and Inclusion, Women, LGBTQIA, and other communities
    • Hackathons, Happy Hours, and team events across all teams and departments
    • Company-wide events like Little Nerds Day (aka bring your kids to work day, even if you're remote) and our annual Charity Auction

    Lifestyle (Be your best self - we'll take care of the details)

    • Our Nerds love to make an impact by paying it forward – Donate to your favorite causes with a company match
    • Work from home equipment stipend and co-working space subsidy
    • Anniversary recognition program – choose from different items and experiences
    • Commuting stipend

    Plan for your future (And when you retire on your island, remember the little people)

    • 401K with company match
    • Annual Enrichment Stipend for learning and development
    • Be the first to test and benefit from our new financial products and tools
    • Access to Rocket Lawyer for online legal support and resources

    If you are based in California, we encourage you to read this important information for California residents linked here.

    NerdWallet is committed to pursuing and hiring a diverse workforce and is proud to be an equal opportunity employer. We prohibit discrimination and harassment on the basis of any characteristic protected by applicable federal, state, or local law, so all qualified applicants will receive consideration for employment.

    NerdWallet will consider qualified applicants with a criminal history pursuant to the California Fair Chance Act and the San Francisco Fair Chance Act, which requires this notice.

    NerdWallet participates in the Department of Homeland Security U.S. Citizenship and Immigration Services E-Verify program for all US locations. For more information, please see:


    1. E-Verify Participation Poster (English+Spanish/Español)
    2. Right to Work Poster (English) / (Spanish/Español)

    #LI-DNI
    #LI-Remote
    #LI-3

    Base pay offered may vary within the posted range based on several factors, including but not limited to education, job-related knowledge, skills, experience, and location.

    The pay range for this role is $110,000—$166,000 USD

  • Commit Partnership

    Security Engineer

    3 weeks ago


    Commit Partnership San Francisco, United States

    About the company: Company size: <50 · Industry: Data Analytics, Data Science, AI · Founding year: 2019 · Stage: B · Funding: $100M · Backed by: Top-tier investors including Sequoia Capital, Andreessen Horowitz, and Snowflake · Tech Stack/Key Tech: Kubernetes, AWS, Terrafor ...

  • HonorVet Technologies

    Security Engineer

    2 weeks ago


    HonorVet Technologies San Francisco, United States

    Title: Security Engineer · Location: Remote · Duration: 12+ months · Position Description · A Security Engineer serves as the security engineer of complex technology implementations in a product-centric environment; is comfortable with bridging the gap between legacy developmen ...

  • ShiftCode Analytics

    Security Engineer

    2 weeks ago


    ShiftCode Analytics San Francisco, United States

    Interview : Video · Visa : All apart from H1b and CPT · This is hybrid from day-1. Candidate must be local. · Description : · Qualifications: · 4+ years of security engineering experience OR equivalent experience in a SWE/DevOps role and an interest in working on security en ...

  • Hive

    Security Engineer

    3 weeks ago


    Hive San Francisco, CA, United States

    About Hive · Hive is the leading provider of cloud-based AI solutions for content understanding, trusted by the world's largest, fastest growing, and most innovative organizations. The company empowers developers with a portfolio of best-in-class, pre-trained AI models, serving ...

  • Retool

    Security Engineer

    1 week ago


    Retool San Francisco, United States

    ABOUT RETOOL: · Nearly every company in the world runs on custom software: Gartner estimates that up to 50% of all code is written for internal use. This is the operational software for refunding orders, underwriting loans, onboarding employees, analyzing transactions, and prov ...

  • Insight Global

    Security Engineer

    1 week ago


    Insight Global San Francisco, United States

    Role: Security EngineerPR: $50 -70/hrLocation: hybrid phx azContract: 12 month contract (possible extensions) · * 2-4 Years of professional experience as a Security Engineer or equivalent position.* Professional experience utilizing Palo Alto.* Professional Experience working wi ...

  • Retool

    Security Engineer

    2 weeks ago


    Retool San Francisco, United States Full time

    ABOUT RETOOL: · Nearly every company in the world runs on custom software: Gartner estimates that up to 50% of all code is written for internal use. This is the operational software for refunding orders, underwriting loans, onboarding employees, analyzing transactions, and prov ...

  • NCC Group (Americas), Inc

    Security Engineers

    6 days ago


    NCC Group (Americas), Inc San Francisco, United States

    Security Engineers · Company: NCC Group (Americas), Inc · Location: San Francisco, CA · Position Type: Full Time · Experience: 1 year · Education: MS · NCC Group (Americas), Inc. seeks Security Engineers w/MS and min. 1 yr experience sought for positions in San Francisco. Salary ...

  • Remotework

    Security Engineer

    1 week ago


    Remotework San Francisco, United States

    Security Engineer (Detection and Response) · Alchemy · Whether you're a beginner developer, startup, web3 market leader, or a large enterprise, Alchemy makes multichain web3 development easy. · View company page · Our mission is to bring blockchain to a billion people. The Al ...

  • Gunderson Dettmer

    IT Security Engineer

    3 weeks ago


    Gunderson Dettmer San Francisco, United States

    Gunderson Dettmer · is the only business law firm of its kind - exclusively serving the global venture capital and emerging technology marketplace. With 400 attorneys in eleven offices - from Silicon Valley to Singapore - we innovate for innovators, accelerate entrepreneurship, ...

  • Hive

    Security Engineer

    4 days ago


    Hive San Francisco, United States

    About Hive · Hive is the leading provider of cloud-based AI solutions to understand, search, and generate content, and is trusted by hundreds of the world's largest and most innovative organizations. The company empowers developers with a portfolio of best-in-class, pre-trained ...

  • Retool

    Security Engineer

    3 weeks ago


    Retool San Francisco, CA, United States

    Retool aspires to be the single best way companies build internal tools, bringing good software to everyone. Retool both handles our clients' most sensitive data and offers a Turing-complete coding environment, so security is a core criterion for everything we build. Bringing our ...

  • HonorVet Technologies

    Security Engineer

    2 weeks ago


    HonorVet Technologies San Francisco, United States

    Title: Security Engineer · Location: Remote · Duration: 12+ months · Position Description · A Security Engineer serves as the security engineer of complex technology implementations in a product-centric environment; is comfortable with bridging the gap between legacy development ...


  • Gunderson Dettmer San Francisco, United States

    Gunderson Dettmer is the only business law firm of its kind - exclusively serving the global venture capital and emerging technology marketplace. With 400 attorneys in eleven offices - from Silicon Valley to Singapore - we innovate for innovators, accelerate entrepreneurship, and ...

  • Anyscale

    Security Engineer

    2 weeks ago


    Anyscale San Francisco, United States

    About Anyscale · At Anyscale , we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We're commercializing Ray , a popular open-source project that's creating an ecosystem of libraries for scalable machine lear ...

  • HeyGen

    Security Engineer

    3 weeks ago


    HeyGen San Francisco, United States

    About HeyGen · HeyGen is a cutting-edge AI-powered platform revolutionizing the world of video creation. · Position Summary: · As a Security Engineer at HeyGen, you will play a critical role in protecting our systems and data from threats. Your expertise will be essential in i ...

  • Insight Global

    Security Engineer

    3 weeks ago


    Insight Global San Francisco, United States

    Job Description · * The Security Engineer on the Enterprise Security team is responsible for protecting Grammarly's infrastructure, including the corporate environment within which all our employees do their work and our cloud infrastructure within which all our product offering ...

  • HonorVet Technologies

    Security Engineer

    1 week ago


    HonorVet Technologies San Francisco, United States

    Title: Security EngineerLocation: RemoteDuration: 12+ months · Position DescriptionA Security Engineer serves as the security engineer of complex technology implementations in a product-centric environment; is comfortable with bridging the gap between legacy development or opera ...

  • Vouch

    Security Engineer

    2 weeks ago


    Vouch San Francisco, United States

    [Full Time] Security Engineer at Vouch (United States) | BEAMSTART Jobs · Security Engineer · Vouch United States · Date Posted · 04 Jan, 2023 · Work Location · San Francisco, United States · Salary Offered · $145000 — $165000 yearly · Job Type · Full Time · Experience Required ...

  • Asana

    Security Engineer

    4 days ago


    Asana San Francisco, United States

    We're looking for a motivated security engineer interested in maturing Asana's product security posture to expand trust with our growing customer base. As a member of the Product Security team, you will focus on shipping features that are free from critical security bugs, enablin ...