Remote Otter LogoRemoteOtter

Application Security Engineer - Remote

Posted 1 week ago
Software Development
Full Time
USA

Overview

Help us protect CrowdStrike and its customers from the most advanced threats by securing our applications. CrowdStrike’s Product Security team breaks the mold of traditional internal security, and focuses on active threats to CrowdStrike’s products. As an Application Security Engineer you will dig into web applications, find design and implementation flaws, help our product engineers fix defects, and play a role in shipping secure code. You’ll hunt for security defects and play a part in fixing those defects rather than just reporting them and hoping for the best. Additionally, you will be involved in cross-cutting projects to further harden internal systems and processes against active and emerging threats.

In Short

  • Join engineering teams working on applications as a security expert and advisor, influencing the design and capabilities of our products.
  • Create and maintain threat models to drive security decisions and minimize threat surface area.
  • Review application source code, looking for security defects and risk.
  • Attack applications throughout the Secure Development LifeCycle.
  • Work with developers to help them understand defects, risks, design weaknesses, etc. and implement proven solutions.
  • Build integrated tools and automation to make life easier for you, your team, and our engineering partners.
  • Assist in responding to our bug bounty program, hunt for similar issues, and improve the security of our applications.

Requirements

  • A moderate understanding of how software products are created and shipped in Agile/DevOps like environments.
  • Moderate experience with threat modeling, especially using STRIDE.
  • Code review experience for apps built with Go (Golang), Python, or Java.
  • Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments (GCP, Azure, AWS).
  • Experience using and/or maintaining commercially available AppSec tools like SAST, DAST, CSPM, DSPM, and ASPM suites.
  • An understanding of common software weaknesses that impact cloud and web applications (not just the OWASP Top 10) and experience in application penetration testing.
  • Comfort with collaborating across technical teams: asking technical questions, challenging assumptions, getting or providing context for decisions, etc.
  • Experience with driving ambiguous research projects.

Benefits

  • Remote-friendly and flexible work culture.
  • Market leader in compensation and equity awards.
  • Comprehensive physical and mental wellness programs.
  • Competitive vacation and holidays for recharge.
  • Paid parental and adoption leaves.
  • Professional development opportunities for all employees regardless of level or role.
  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections.
  • Vibrant office culture with world class amenities.
  • Great Place to Work Certified™ across the globe.
CrowdStrike logo

CrowdStrike

CrowdStrike is a leading cybersecurity company that specializes in protecting organizations from advanced threats through innovative security solutions. With a focus on application security, CrowdStrike's Product Security team actively engages in identifying and mitigating vulnerabilities within its products. The company promotes a collaborative environment where security experts work closely with engineering teams to enhance the security of applications throughout the development lifecycle. CrowdStrike is recognized for its commitment to employee well-being, offering a remote-friendly culture, competitive compensation, and comprehensive wellness programs, making it a great place to work.

Share This Job!

Save This Job!

Similar Jobs:

Docplanner logo

Application Security Engineer - Remote

Docplanner

5 weeks ago

Join us as an Application Security Engineer to safeguard our software products and enhance the healthcare experience.

Spain
Full-time
Software Development
Remo Health logo

Security Application Engineer - Remote

Remo Health

5 weeks ago

Join Remo as a Security Application Engineer to enhance security practices and protect systems in a remote environment.

USA
Full-time
DevOps / Sysadmin
Prelim logo

Application Security Engineer - Remote

Prelim

6 weeks ago

Join Prelim as an Application Security Engineer to architect and build security systems for financial institutions.

Worldwide
Full-time
Software Development
Practical DevSecOps logo

Application Security Engineer - Remote

Practical DevSecOps

7 weeks ago

Join our team as an Application Security Engineer, focusing on enhancing security training and implementing application security best practices.

India
Full-time
Software Development
DoseSpot logo

Application Security Engineer - Remote

DoseSpot

7 weeks ago

Join DoseSpot as an Application Security Engineer to enhance security in the software development lifecycle while working remotely.

USA
Full-time
Software Development