Staff Security Engineer

Attentive

Attentive

IT
United States
Posted on Oct 31, 2024
At Attentive, we're revolutionizing the way businesses connect with their customers. Our AI-driven marketing platform infuses intelligence into every stage of the consumer journey, helping brands deliver hyper-personalized messages at scale. With a mobile-first approach, engaging two-way conversations, and enterprise-grade technology, we're driving billions in online revenue for leading brands worldwide, including CB2, Urban Outfitters, GUESS, Long John Silver’s, and Wyndham Resort. But we're not just about SMS and email—by expanding our AI capabilities to enhance multiple products and channels, our goal is to help make every interaction more meaningful. As a member of our team, you'll be at the forefront of this innovation, helping to shape the future of customer communication.
Attentive’s growth has been recognized by Deloitte’s Fast 500, Linkedin’s Top Startups and Forbes Cloud 100 all thanks to the hard work from our global employees!
Who we are
We are seeking an experienced and adaptable security engineer with strong technical skills and a developer mindset. The ideal candidate is motivated to reduce risk while enabling the business to operate swiftly and safely.
As a key member of the Security Engineering team, you will be responsible for securing Attentive’s platform (operating in AWS) and customer-facing products (primarily built with Java microservices). Your role will encompass building and operating tools to secure our code, detect abnormal behaviors, and provide security testing and guidance for new systems and features.
You will lead our product and application security program, serving as a central resource for enhancing product security for our clients. Collaborating with a talented team of security professionals, you will help shape the future of Attentive’s security program and create a positive impact for the company and its customers.
At Attentive, we strive to make interactions with our security team seamless and enjoyable. Therefore, the ideal candidate should possess: A creative and solution-oriented mindset to develop effective solutions for all stakeholders. Patience to understand developer teams' processes and goals for implementing thoughtful security measures. The ability to automate security processes to minimize the security burden on partner teams and support rapid company growth.

Why Attentive needs you

  • Architecture Design & Code Reviews: Conduct secure design and code reviews for new systems and features, identifying common vulnerabilities such as injection attacks and cross-site scripting (XSS)
  • Automation & Tooling: Develop and implement security tools for code scanning, dependency management, and CI/CD pipeline integration to protect systems throughout the development lifecycle
  • Engineering Support: Provide hands-on support to engineers in deploying security solutions, hardening services, and remediating vulnerabilities, including encryption and input validation
  • Threat Modeling: Lead the creation of comprehensive threat models for products and infrastructure to identify, assess, and mitigate security risks
  • Vulnerability Management: Establish and oversee a vulnerability management lifecycle, ensuring timely detection, reporting, and remediation of security vulnerabilities
  • Security Guidance & Documentation: Promote secure coding practices and maintain security documentation, including reports from penetration testing and product security tools

About you

  • 7+ years of experience in application/product security, with expertise in web technologies, vulnerability identification and remediation, and cloud security fundamentals
  • Proven ability to build and automate processes, such as static code analysis, enhancing code shipping practices beyond mere compliance
  • Extensive knowledge of application and network protocols, cryptography, authentication and authorization protocols, as well as common security threats and attack techniques
  • Strong coding and code review experience in Java, Python, and Golang, with a focus on Java vulnerabilities and Kubernetes/container security
  • Experience with AWS and deploying infrastructure as code
  • Skilled at communicating complex technical concepts and risks to non-technical audiences
You'll get competitive perks and benefits, from health & wellness to equity, to help you bring your best self to work.
For US based applicants:
- The US base salary range for this full-time position is $200,000 - $270,000 annually + equity + benefits
- Our salary ranges are determined by role, level and location
#LI-SK1
Attentive Company Values
Default to Action - Move swiftly and with purpose
Be One Unstoppable Team - Rally as each other’s champions
Champion the Customer - Our success is defined by our customers' success
Act Like an Owner - Take responsibility for Attentive’s success
Learn more about AWAKE, Attentive’s collective of employee resource groups.
If you do not meet all the requirements listed here, we still encourage you to apply! No job description is perfect, and we may also have another opportunity that closely matches your skills and experience.
At Attentive, we know that our Company's strength lies in the diversity of our employees. Attentive is an Equal Opportunity Employer and we welcome applicants from all backgrounds. Our policy is to provide equal employment opportunities for all employees, applicants and covered individuals regardless of protected characteristics. We prioritize and maintain a fair, inclusive and equitable workplace free from discrimination, harassment, and retaliation. Attentive is also committed to providing reasonable accommodations for candidates with disabilities. If you need any assistance or reasonable accommodations, please let your recruiter know.