Skip to content

Open nowPosted 11 hours agoWe saw it 117 min after it went up

Software Engineer, Security Focus

Workable (global search)107,585 open roles

Where
Mesa, AZ, United States
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSoftware Engineer, Security FocusWorkable (global search) · Mesa, AZ, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 3 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted 11 hours ago

Workable (global search) median: 3 days open

The posting

We are looking for a hands-on full-stack Software Engineer who will focus primarily on security remediation. Your first priority will be owning the remediation of vulnerabilities identified through penetration testing: not just reporting findings, but digging into the codebase, session traffic, and infrastructure to fix the underlying issues and prevent them from recurring. You will work closely with engineering and design teams to translate real-world security findings into concrete, testable requirements in our Technical Requirements Documents (TRDs), and you will personally implement or oversee the fixes.

This is an engineering role first. As the security backlog comes under control, you will have the flexibility to contribute to application development across our Ruby on Rails and React platform, bringing a security-minded perspective to the features you build.

Key Responsibilities

Security Remediation

  • Vulnerability Remediation: Own end-to-end remediation of vulnerabilities surfaced by penetration tests and other security assessments, from triage through verified fix.
  • Traffic and Session Analysis: Use browser-based code inspection tools to examine session traffic between the front end and back end, identify cases where excessive or sensitive information is being exposed, and translate those findings into concrete design and engineering requirements.
  • TRD Input: Feed vulnerability findings and remediation requirements directly into the Technical Requirements Document (TRD) process so fixes are captured as durable design requirements, not one-off patches.
  • Session Management: Review and harden session management practices across the application stack.
  • Full-Stack Remediation: Work within a Ruby on Rails and React codebase and across containerized services (AWS, Fargate) to implement fixes at both the application and infrastructure layers.
  • API and Real-Time Systems: Assess and secure real-time and API-driven features, including those built on Pusher and AnyCable, and RESTful APIs generally.
  • Documentation: Produce clear, thorough documentation of vulnerabilities, root causes, remediation steps, and verification results.
  • Compliance Support: Contribute security context and vocabulary to FedRAMP-related discussions and requirements, partnering with compliance and engineering stakeholders.

Application Development

  • Feature Development: Design, build, and ship features across the Ruby on Rails back end and React front end alongside the broader engineering team.
  • Secure by Design: Apply what you learn from remediation work to new development, helping the team avoid reintroducing known classes of vulnerabilities.
  • Code Quality: Participate in code reviews, testing, and technical design discussions, with an eye toward both security and maintainability.

Requirements

Engineering Experience

  • 5+ years of hands-on software engineering experience, with broad full-stack work across multiple applications and technology layers.
  • Working proficiency in Ruby on Rails and React.
  • Experience with containerized environments, AWS, and Fargate.
  • Solid API experience, including RESTful API design and security considerations.
  • Hands-on experience with Pusher and AnyCable, or comparable real-time messaging technologies.
  • Knowledge of Ruby data models and how schema and query design affect performance and scalability.

Security Experience

  • 5+ years of experience in a security engineering or closely related role.
  • Proven experience remediating vulnerabilities identified through penetration testing.
  • AWS Security certification(s) (e.g., AWS Certified Security – Specialty).
  • General familiarity with FedRAMP: enough understanding of the vocabulary and framework to contribute meaningfully to a FedRAMP-related project.

Analytical Skills

  • Comfortable using browser developer/code inspection tools to inspect network and session traffic.
  • Able to identify when too much information is being exposed between backend and frontend, and to explain the risk clearly to engineering and design stakeholders.
  • Able to translate security findings into actionable design requirements that feed directly into the TRD.

Coding and Technical Skills

  • Working proficiency in Ruby on Rails.
  • Experience with containerized environments, AWS, and Fargate.
  • Solid API experience, including RESTful API design and security considerations.
  • Solid understanding of session management principles and common pitfalls.
  • Hands-on experience with Pusher and AnyCable, or comparable real-time messaging technologies.
  • Broad, full-stack experience across multiple applications and technology layers.
  • Knowledge of Ruby data models and how schema and query design affect performance and scalability.

Documentation

  • Strong written communication skills, with the ability to document vulnerabilities, remediations, and technical requirements clearly for both engineering and non-engineering audiences.

Nice to Have

  • Experience with Pulumi for infrastructure as code.
  • Python experience.
  • SQL skills.
  • Active or eligible for security clearance.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.