Senior Application Security Engineer
Tbwa Chiat/Day Inc - New York
Work at Tbwa Chiat/Day Inc
Overview
- View job
Overview
Join us, and help change mental healthcare for the better. About the role
The Trust team at Headway is focused on security and privacy for all of Headway’s customers - therapists, patients, and payers (ex: insurance companies and health systems). As an early member on the team, you’ll have the unique opportunity to be the builder and driver of our dedicated, in-house product and application security engineering efforts. In this role, you will partner closely with our product and engineering teams to ensure that our application is designed and developed securely so that we can maintain and grow customers’ trust in Headway. What you’ll do at Headway:
Partner with Product and Engineering:
Headway has many new product launches on the horizon that will transform the industry and have a rich data component. You will be a partner at both the design and development stage to ensure that we implement new features securely, including (but not limited to): Participating in the implementation efforts Doing security reviews Helping with product design decisions Auditing and surfacing vulnerabilities in our current products Develop and Improve our Automated Tooling:
Further enhance our automated tooling to scale our application security capabilities and find potential code problems both before and after we deploy. Make the safe way, the easy way:
Work on defining and building application guardrails so that developers can build securely by default. You also will work to instill a culture of secure development across engineering. Assist in ongoing security operations:
You will be part of the security and privacy team and have responsibilities to assist in incident response, vulnerability management, penetration testing, security reviews, and other operational tasks to ensure that our security program is operating at a world-class level. Tools we use:
Languages:
Python 3, TypeScript Libraries:
FastAPI, SQLAlchemy, React Infrastructure:
AWS (Fargate, ECS, S3, and more), Spark and Kafka Version Control:
Github Vulnerability Management:
Snyk, Semgrep You’ll be great for this role if you have:
Have 0 → 1 security experience:
You have 5+ years experience in security and/or software engineering roles with a demonstrated history of working on security-related projects or with responsibilities as a security generalist. Strong cross-functional experience:
You love partnering with other teams to help both teams achieve their goals. Strong technical depth and breadth:
You have technical experience with building secure platforms and products at a deep level. You are excited to perform security design and code reviews. You want to understand security systems and improve their efficiency and scalability. Thrive in ambiguity:
You love tackling ambiguous problems in a fast-paced environment with an optimistic and energizing attitude. Innovation at Scale:
You seek opportunities to lead the industry in implementing the latest security and privacy technologies. Results driven:
You care deeply about creating impact and driving results for Headway’s business. Mission driven:
You are motivated by Headway’s mission, increasing access to high quality mental health care. Compensation and Benefits:
The starting salary for an Application Security Engineer is $188,000 and increases to $230,000 based on industry tenure and experience. Benefits offered include: Equity Compensation Medical, Dental, and Vision coverage HSA / FSA 401K Work-from-Home Stipend Therapy Reimbursement 16-week parental leave for eligible employees Carrot Fertility annual reimbursement and membership 13 paid holidays each year as well as a Holiday Break during the week between December 25th and December 31st Flexible PTO Employee Assistance Program (EAP) Training and professional development We believe a team's strength is in its people, and we cannot achieve this mission without a team that reflects the diversity of this problem – across race, ethnicity, gender, sexuality, age, national origin, religion, family status, disability, military status, and experience. Headway is committed to the full inclusion of all qualified individuals. As part of this commitment, Headway will ensure that persons with disabilities are provided with reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or receive other benefits and privileges of employment, please contact Headway employees work remotely across the US, with the option to work from offices in New York City and San Francisco. Headway participates in E-Verify. Apply for this job #J-18808-Ljbffr