Avatar for Oyster®
Oyster®
Actively Hiring
Hire, pay, and give great benefits to your distributed team around the world
  • B2B
  • Scale Stage
    Rapidly increasing operations
  • Top Investors
    This company has received a significant amount of investment from top investors
  • +2

Senior Security Engineer

Posted: 3 weeks ago
Visa Sponsorship

Not Available

Hires remotely
Everywhere
RelocationAllowed

About the job

👩‍💻 The Role


Location: While this position is posted in a specific location, all of Oyster’s positions are fully remote and you can work from home. Forever. To create the best experience for our new hire, this role requires you to be based within +3 / -5 UTC.

We are looking for a high-performing Senior Security Engineer to join the Engineering Team at Oyster. In this role, you will work closely with the Data Protection/Privacy Team, IT Team, and Product Development Team to ensure that our applications are secure throughout the development lifecycle. You will be responsible for identifying and mitigating security risks, implementing best practices, and collaborating with cross-functional teams to enhance our security posture. Working in a fully distributed company, you will work synchronously and asynchronously with team members all over the world. We are looking for someone with strong technical skills, a collaborative mindset, and the ability to thrive in a dynamic, fast-paced environment.

Key Responsibilities

  • Embed Security in SDLC:

    • Collaborate with development teams to integrate security practices into the Software Development Lifecycle (SDLC).
    • Conduct security assessments, code reviews, and threat modeling exercises to identify and mitigate security risks.
    • Provide guidance on secure coding practices and remediation strategies.
  • SaaS Application Security:

    • Conduct security assessments and audits of both in-house and third-party SaaS applications.
    • Ensure proper security controls and access management are implemented for SaaS tools.
    • Stay updated on emerging threats and vulnerabilities specific to SaaS environments and address potential risks proactively.
  • Security Tools and Automation:

    • Implement and manage security tools such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
    • Integrate security tools into CI/CD pipelines for continuous security testing.
    • Monitor and analyze security tools' outputs to identify and address potential security risks.
  • Collaboration and Compliance:

    • Work with the Data Protection/Privacy Team to ensure applications comply with relevant data protection regulations (e.g., GDPR, CCPA).
    • Collaborate with the IT Team to ensure secure infrastructure configurations for hosting and deploying applications.
    • Partner with the Product Team to incorporate security requirements into product features from the design phase.
  • Training and Awareness:

    • Develop and deliver security training and awareness programs for developers and relevant stakeholders.
    • Promote a culture of security awareness and best practices throughout the organization.

Core Requirements

  • 5+ years of experience in application security, with a strong focus on SaaS environments.
  • Strong knowledge of security assessments, audits, and best practices for SaaS applications.
  • Experience in configuring and managing security controls and access management within a SaaS-centric environment.
  • Proficiency in using security testing tools such as SAST, DAST, and SCA.
  • Experience integrating security tools into CI/CD pipelines and automating security processes.
  • Familiarity with data protection regulations (e.g., GDPR, CCPA) and their implications for application security.
  • Understanding of identity and access management
  • Strong problem-solving skills and the ability to communicate complex security concepts to technical and non-technical audiences.

You'll also need

  • A drive to learn, and help the development team to progress.
  • Fluent English language skills.
  • A reliable internet connection (or be able to get one).

About the company

Oyster® company logo

Oyster®

Actively Hiring
Hire, pay, and give great benefits to your distributed team around the world201-500 Employees
Company Size
201-500
Company Type
Software
  • B2B
  • Scale Stage
    Rapidly increasing operations
  • Top Investors
    This company has received a significant amount of investment from top investors
  • Valuation $1B+
    This company has a valuation of $1B or more
  • Recently funded
    Raised funding in the past six months

Employees joined from

Learn more about Oyster® image

Funding

AMOUNT RAISED
$74.2M
FUNDED OVER
3 rounds
Rounds
B
$50,000,000
Series B - Jun 2021+2

Founders

Tony Jamous
CEO • 3 years
image
Jack Mardack
Co-founder • 3 years
San Francisco
image
View the team image

Similar Jobs

GVOS  company logo
GVOS
An Edge Cloud for Autonomous Driving
Securitybulls Intelligence company logo
Securitybulls Intelligence
Uncover high level picture of how prepared your organisation is to meet threat you face
Hive company logo
Hive
Cloud-based AI solutions to understand, search, and generate content
Kleros company logo
Kleros
A decentralized court system for dispute resolution in blockchain
Gridspace company logo
Gridspace
State of the art voice technology and automation for customers, patients, and call centers
TIKAJ company logo
TIKAJ
Security Automation, Intelligence & Compliance