👉 Hiring for a remote Python position?on the 🏆 #1 remote jobs board
Sr. Application Security Engineer - Oakland or
Sr. Application Security Engineer - Oakland or
Are you looking to join an innovative organization powering payments for the next generation of fintech and commerce innovators? Marqeta has built the world’s first open API issuer processor platform from scratch, powering prepaid, debit, and credit cards for the most recognizable names in financial technology, alternative lending, on-demand services and e-commerce. Marqeta has become the leader in payment innovation. Our company is comprised of a team of industry experts, a dynamic approach to working on challenging problems, and an open environment and culture that is focused on ideas and innovation.\n\nNot only do we have an inspiring and innovative culture, but only Marqeta can offer you a chance to help redefine the payments industry. As a testament to the company we've collectively built, our world-class team voted Marqeta one of the Bay Area’s Best Places to Work.\n\nMarqeta is proud of its Oakland roots and strives to build a team as diverse as the cities in which we operate. Underrepresented populations are encouraged to apply. \n\nWe are not expecting any single candidate to have an expertise under all areas of our requirements section. Please apply if you meet some but not all of the requirements.\n\n**Position Summary**\n\nMarqeta is growing a fresh Application Security Team with the goal of significantly improving industry standards in Secure Application Development in the Payments space. We are based in Oakland, California but are open to remote engineers for this role!\n\nAs a member of the Application Security Engineer (ASE) Team, you serve as a key contributor to Marqeta’s open payments platform. This role supports the safety and security of our customer’s payments, ensuring the growth of an innovative platform that provides direct access to a strong suite of Payment Card Issuer/Processor APIs. Our long term goal is the development of a strong Product Security Program that protects the global development and deployment of payment and virtual cards as well as mobile authorization.\n\nOur ASEs define Security Engineering standards and practices around Secure Code, Continuous Delivery/Integration, Pre and Post Release S-SDLC, Verification/Validation models, Penetration Testing and innovative Security tooling designed around self-service and rich integration models.\n\nYou'll work closely with Marqeta’s Frontend and Backend Engineers, you'll contribute to critical design input for API development and service architectures, and you’ll assist the company in developing strong engineering practices in support of Product Security. Our goal is to both enhance the workflow of our engineers with security-centric tool sets and implement innovative methods of testing code in the pre-release phase.\n\nThe ideal candidate has a strong core skill set in two or more of the following areas - Automation, QE Testing, Security Engineering, REST API Design, and/or Strong Knowledge in Modern App Frameworks (esp ReactJS, Rails, or Tomcat). You’re knowledgeable and conversant in common vulnerabilities affecting modern web applications, familiar with modern cloud and datacenter based infrastructure, are looking to grow strong application security experience, and you intend to be an excellent communicator and collaborator. Our ASEs are particularly concerned with scaleable tooling strategies and strong process and practice management, which includes constant refinement in how we engage with our cross-functional team of engineers.\n\n\n# Responsibilities\n **Primary Responsibilities**\n* Build Self Service Tools for QE, Frontend and Backend Engineers\n* Assist with Definition, Implementation, and Maintenance of S-SDLC\n* Lead Application Security Assessments and Design Reviews\n* Execute Critical Validation/Verification Functions in Pre- and Post-Release\n* Implement SAST, DAST and Coherent Dependency Vuln Management into the Build Pipeline\n* Execute Greybox and Whitebox Application Security Assessments\n* Execute and Support HTTP/S Service-Layer Pen-Testing\n* Develop Security Training and Guidelines for Engineers\n* Build and Enhance S/W Testing Strategies with Specialized End-to-End Clients, RSpec, Puppeteer and Selenium-Based Test Cases\n* Lead Software Vulnerability Management and Risk Mitigation Practices\n* Offer Guidance and Leadership in PCI Complianc \n\n# Requirements\n**Requirements**\n* 3-5 yrs Demonstrable and Practical Experience in Application Security Engineering or Comparable Experience in a Security Engineering Role\n* You have a passion for Security Engineering as a discipline\n* You’re an excellent communicator\n* You employ strong collaboration patterns and enjoy creating positive team dynamics\n* You know how to own and support positive outcomes\n* You remain constructive under pressure, with a flexible working style\n* Functional Development Experience and Proficiency in Python, Go, JS, Ruby, or Java\n* Familiarity with Java and JVM based Application Stacks (e.g. Tomcat)\n* Functional Experience with Testing Frameworks and Modern Testing Paradigms (BDD, TDD, and similar)\n* Solid Knowledge of OAuth and SAML\n* Strong Knowledge of HTTP/S Service Architectures\n* Strong Knowledge of Transport Security, specifically TLS and CAs\n* Strong Knowledge of OWASP and Common Software Vulnerabilities\n* Solid Understanding of Secure Coding/Development Practices\n* Experience with Production Build Pipeline and CI/CD stacks (Ex. Jenkins, Nexus, Drone CI)\n* Familiarity with Container Technology (Ex. Docker, RKT)\n* Demonstrable Experience with Python, Ruby, JS and/or Go Tool Development\n* Strong Interest in Automation Practices\n* Familiarity and Interest in Cloud Services and SAAS Platforms (AWS, GCP)\n* Familiarity with Terraform and Ansible Automation Stac\n\n**Perks**\n* Be a member of an exceptional team - we’re growing and your career and opportunities with us will, too!\n* Rich suite of benefit plans - Employee premiums paid 100%\n* Generous Paid Time Off plan\n* Market-leading fully paid Parental Leave\n* Retirement savings - 401k plan with a Company match\n* Meaningful Equity\n* Bi-annual Hack Weeks to support and reward innovation\n* Beautiful downtown Oakland office in a great location, with stunning views of Lake Merritt\n* Conveniently located close to public transportation\n* Open, transparent culture that includes weekly All Hands meetings, Lunch-and-Learns, all-company offsite, etc.\n* Commuter and Parking monthly subsidy\n* Access to corporate gym membership rates and other discounts and employee perks!\n* Fully stocked kitchen, catered lunches twice a week, breakfast on Fridays, and more!
See more jobs at Marqeta
# How do you apply? This job post is older than 30 days and the position is probably filled. Try applying to jobs posted recently instead.Apply for this Job
👉 Please reference you found the job on Remote OK, this helps us get more companies to post here!