\nAs a Principal Application Security Engineer at Vimeo, you will engage in a variety of activities, either offensive, defensive, or some combination thereof, ultimately aimed at safeguarding our users who entrust Vimeo with their content every day.\n\nYouโll plan, carry out, and lead security initiatives to monitor and protect sensitive data and systems from infiltration and cyber-attacks.\n\nYou will likely collaborate frequently with and support developers, as well as members of the infrastructure security team, the compliance team, IT, Product, and other teams throughout the organization.\n\nYou love to solve puzzles, and are a great team player.\n\nThis role is remote. The role requires three hours of overlap with the US Eastern time zone (i.e., New York City) daily.\n\nWhat youโll do:\n\nDepending on your preferences and the current needs of the team, you may either focus on just one or two of the following areas, or you may choose to become involved with many of them.\n\n\n* Security architecture โ create a technical plan for partitioning and consolidating our cookies; draft up a sequence diagram for a new middleware to prevent IDOR attacks; implement a POC for leveraging CAPTCHA challenges in cross-origin embedded iframes; draft some code to modify the expiration behavior of our JWTs then pair with our API team to get feedback\n\n* Penetration testing โ either hunt for security issues on our production or staged applications during an open-box internal pen test, or help coordinate an engagement with an external firm\n\n* Writing code for internal automated security tools โ write some code, usually in Python, Bash, or Go, to support any of our team's various initiatives. Often we strive to facilitate a culture of โpaved roadsโ for our developers, such that it is easy for any developer to incorporate security into their designs and implementations\n\n* Threat modeling โ consider how malicious attackers may compromise our systems, and advise developers and product managers on what defenses are needed\n\n* Code reviews โ discover weakness in our source code before it reaches production\n\n* Bug bounty program โ help triage new incoming reports on a daily basis, plus launch creative initiatives to increase researcher engagement on our programs\n\n* Web Application Firewall and Rate Limiting โ expand coverage and tune new rules while coordinating with developers, support team members, and the site reliability team\n\n* Remediation โ enable and encourage developers to correctly fix recently discovered security issues in a timely manner, ultimately reducing our Mean Time To Remediate\n\n* Secure Software Development Lifecycle โ configure automated tooling (eg. static and dynamic code analysis,, IAST) in our SDLC to detect security issues in our source code before it reaches production\n\n* Developer Education, Security Culture โ create fun ways to spread technical security awareness throughout the engineering department\n\n* Incident response โ lead or assist in running the various phases of an incident response, including initial detection, triage, containment, recovery, root cause analysis, retrospective, etc.\n\n* Collaboration with the infrastructure security team โ pair with members of the infrastructure security team on various projects to secure our cloud instances and employee workstations\n\n* Collaboration with the compliance and privacy team โ help ensure that our company complies with industry best practices and standards\n\n* Process improvements โ help strengthen our own internal processes and procedures\n\n* A typical day will look like:\n\n\n\n* Engage with one or more product development teams and guide them through a threat model and data flow analysis.\n\n* Review the code for major new functionality to ensure security best practices are followed. \n\n* Review new tickets in our bug bounty program (http://hackerone.com/vimeo) and use your system design and threat modeling knowledge to reproduce, define risk and mitigating controls and propose a fix., \n\n* A call or two with Development, Product Management teams to discuss security-related issues\n\n* Pen test a new feature in a staging environment with Burp Pro\n\n* Assist the compliance team on a privacy-related project\n\n* Provide technical advice in response to occasional questions from developers and other members of the security team\n\n\n\n\n\n\nSkills and knowledge you should possess:\n\n\n* Required: 5+ years of prior experience in either software development, devops, or site reliability engineering with hands-on coding experience.\n\n* Preferred: prior experience in Application Security\n\n* 7+ total years of relevant experience in Engineering, Application Security, or a similar technical field.\n\n* Strong knowledge of modern web, mobile, and network security\n\n* Strong programming skills with at least one of the following languages, and the ability to read all of them: Python, Go, PHP, Javascript, and Ruby\n\n* Expertise with application pen testing, using tools like Burp or Zap\n\n* Confident working in and across cloud environments like AWS and GCP. Detailed knowledge of at least one cloud environment.\n\n* Confident with shell scripting\n\n* Confident with common SDLC components, like git, Jira, Jenkins, etc\n\n* Confident ability to communicate technical security concepts to developers\n\n* At least an upper-intermediate level of English\n\n\n\n\nBonus points:\n\n\n* Link to a Github repo with security tools/scripts youโve developed or help maintain\n\n* Full-stack web development experience creating RESTful applications (in any language) is a big plus\n\n* Open source vulnerability research or blog posts is a big plusS\n\n* Experience with system security hardening guidelines and SDLC principles\n\n\n \n\n#Salary and compensation\n
No salary data published by company so we estimated salary based on similar jobs related to Design, Cloud, API and Engineer jobs that are similar:\n\n
$62,500 — $105,000/year\n
\n\n#Benefits\n
๐ฐ 401(k)\n\n๐ Distributed team\n\nโฐ Async\n\n๐ค Vision insurance\n\n๐ฆท Dental insurance\n\n๐ Medical insurance\n\n๐ Unlimited vacation\n\n๐ Paid time off\n\n๐ 4 day workweek\n\n๐ฐ 401k matching\n\n๐ Company retreats\n\n๐ฌ Coworking budget\n\n๐ Learning budget\n\n๐ช Free gym membership\n\n๐ง Mental wellness budget\n\n๐ฅ Home office budget\n\n๐ฅง Pay in crypto\n\n๐ฅธ Pseudonymous\n\n๐ฐ Profit sharing\n\n๐ฐ Equity compensation\n\nโฌ๏ธ No whiteboard interview\n\n๐ No monitoring system\n\n๐ซ No politics at work\n\n๐ We hire old (and young)\n\n
\n\n#Location\nTel Aviv, Tel Aviv District, Israel
๐ Please reference you found the job on Remote OK, this helps us get more companies to post here, thanks!
When applying for jobs, you should NEVER have to pay to apply. You should also NEVER have to pay to buy equipment which they then pay you back for later. Also never pay for trainings you have to do. Those are scams! NEVER PAY FOR ANYTHING! Posts that link to pages with "how to work online" are also scams. Don't use them or pay for them. Also always verify you're actually talking to the company in the job post and not an imposter. A good idea is to check the domain name for the site/email and see if it's the actual company's main domain name. Scams in remote work are rampant, be careful! Read more to avoid scams. When clicking on the button to apply above, you will leave Remote OK and go to the job application page for that company outside this site. Remote OK accepts no liability or responsibility as a consequence of any reliance upon information on there (external sites) or here.
This job post is closed and the position is probably filled. Please do not apply. Work for Very and want to re-open this job? Use the edit link in the email when you posted the job!
๐ค Closed by robot after apply link errored w/ code 404 2 years ago
IMPORTANT:\nย \n1. This job is to work for a US company. An advanced level of English is a non-negotiable requirement. Please refrain from applying if this is not your case.\nย \n2. This job is remote but if youโre not located in the region mentioned in the postโs title, do not continue. Your application wonโt be reviewed. Please apply to the job posting for your country/region of residence.\nIf youโre in Brazil, Bahamas, Barbados, Bolivia, Cuba, El Salvador, Haiti, Jamaica, Nicaragua, Panama, Suriname, Trinidad, and Tobago, or Venezuela, weโre sorry but we canโt consider your application at this moment. #LI-Remote\nย \n3. To be considered for this position, resumes must be sent in English\n\nInterviewing for a new company is a serious time commitment for all parties involved. Please take the time to read this and thoughtfully consider if we would be a good fit for one another.ย No contractors or agencies. Seriously.\n\nAbout Very\n\nVery has been a remote-first company since 2011 which has allowed us to develop an amazing remote working experience and to have a remote office culture that exceeds that of any traditional on-site office.\n\nWeโve built a collaborative, tight-knit team that thrives, whether weโre hanging out in person at our annual retreat or coordinating work across time zones. The results show that weโre doing something right. In 2020, we were named one of Incโs Best Workplaces, Parity.org's Best Companies for Women to Advance List, and Fatherlyโs Best Places to Work for Dads.\n\nAt Very we are focused on delivering world-class IoT hardware, software, and smart product engineering services to our clients. We have a wide array of clients from enterprise-level clients such as Vizio, Clear and iHeart Radio to small greenfield start-ups. Whatever size company our goal remains the same - Deliver world-class IoT services and solutions and truly partner with our clients to ensure overall product success.\n\n\nAbout this Role\n\nVery is looking to hire an experienced software engineer specializing in native mobile development to work across a wide variety of projects and technology stacks.\n\nAs a Lead Software Engineer, you will be responsible for delivering high-quality, scalable and well tested code. At Very, teaching and learning is at the core of what we do. Whether through pair programming, workshops, conferences or other cross project collaboration we expect every engineer to continue advancing and developing their skills.\n\nResponsibilities:\n- Execute end-to-end software development and deployment in an agile environment\n- Provide technical guidance to other team members\n- Influence work of multiple teams relating to overall engineering group objectivesย \n- Drive continuous process and technology improvements\n- Lead production monitoring and resolution impacts\n- Own and operate large sections of software and systems\n- Partner with Product to spec out the technical aspects of a feature from inception through delivery\n- Guide software design and delivery through influence and education\n- Write acceptance, integration and unit tests\n- Coach and mentor other engineers\n- Conduct architecture discussions when necessary\n- Participate in recruiting of candidates and improvement of the overall interview process\n- Support sales and pre-sales engineering work to ensure Very Client fit\n\nAt Very we do not have just one technology stack as we work on interesting problems, not specific technologies. However, we do have some preferred stacks and proficiency in two of them is required:\n\nBackend Web / Embedded Technologies\nElixir: Phoenix / Nerves\nPython: Django / Flask / Serverless / Scientific Python\nRuby: Rails\nJavaScript: NodeJS Backends\nKotlin/Java: Web Backends\nC/C++: Zephyr RTOS / BareMetal\n\nFrontend Web / Mobile Technologies\nTypeScript: React / React Native\nSwift/Objective C: iOS Native\nKotlin/Java: Android Native\n\nWe value well-tested, reusable code and expect our engineers to be as good of practitioners as they are leaders and teachers.\n\n\nWhat Youโll Be Working On\n\nWe take customer success extremely seriously here at Very. As a senior engineer, you will be partnering with our clients to bring their products to market. You will be utilizing one or more of the above mentioned technology stacks coupled with a cloud provider to deliver an end-to-end solution for our customers.ย \n\nEach project is slightly different and can contain any combination of hardware, firmware, web / mobile frontend as well as an API backend/cloud architecture. We follow best practices such as Infrastructure as Code, well thought out and designed CI/CD pipelines, TDD, and other testing best practices, and always keep an eye on scalability.ย \n\nWe remain as agile as possible working on delivering a vertical slice of all involved layers as early as possible so we can iterate and demonstrate progress. Your role on a project will be focused on your area of expertise coupled with your learning goals.\n\n\nQualifications\n\nRequired\nUnfortunately, applicants who do not meet these criteria will not be considered.\n\n* Lead-level Software Engineering experience: Can guide a team to successful outcomes by architecting overall solutions, ensuring that work across the team meets a high standard, and helping the team focus on efficient solutions to business problems.ย Their quality of work and overall approach to problem-solving means that review of their work is mostly for the sake of discussion/clarity, rather than to ensure quality.ย \n* Lead-level native mobile engineering experience: Has developed from ent-to-end and published multiple Android and/or iOS apps\n* Strong communication skills with the ability to understand and explain technical issues to a non-technical audience\n* Strong experience with Android App and SDK development experience with Java and Kotlin\n* Experience delivering and supportingย Android applications\n* Solid understanding of the full mobile development life cycle required\n* Good understanding of cross-platform app development\n* Experience with using RESTful Web Services with applications\n* Experience building web and API services, using remote data via REST and JSON\n* Experience in object orientated design and programming, design patterns, and related frameworks\n* Demonstrated expertise in continuous integration/delivery/deployment\n\nNice-to-haves\n* Experience with Docker and Kubernetes\n* Cloud development experience with AWS\n\nContract\n\nYour contract with Very will be as an independent contractor for an indefinite period.\nThis type of contract carries some additional responsibilities for you - you'll have to save some money to take care of taxes and you'll have to pay for public social security (Health and Pension) out of pocket.\nย \nThat being said, we're confident that our competitive compensation and benefits package (see below) will still mean that you are happy with your take-home amount at the end of each month. For more information about Very and the contract type, see here.\n\nHow Youโll Be Compensated\n\nBase compensation\nDepending on your skill and experience, you can expect a monthly salary between USD $7,900 and $11,100 upon joining the company.ย We also offer performance bonuses, a generous maternity/paternity leave policy, and numerous other employee benefits (including eliminating the stress and cost of commuting each day)\n\nWe also offer world-class perks:\n-$1,000 annual Healthcare Stipend (to be used towards Health insurance premium)\n-Paid Parental Leave\n-Continuing Education Stipend - After 1 year of Employmentย ($3000/ year for learning and 100% of the costs if youโre speaking at an event)\n- Home Office Stipend ($1000 per year for your workstation / office)\n- $125/mo Monthly Communications Stipend (Can be used towards Cell Phone Data Plan, WiFi Plan, VOIP, VPN)\n- PTO / Sick Time\n- Variable Compensation based upon performance\n- MacBook Pro (Provided)\n- Personalized ESL coaching and access to an AI-powered adaptive platform to take your English to the next level\n\nAdditional Perks (could vary)\n- Paid trip to somewhere in the World for the annual global company retreat.\n\n \n\n#Salary and compensation\n
No salary data published by company so we estimated salary based on similar jobs related to Ads, Mobile, Excel, Non Tech, Salesforce, API, Senior, Sales, SaaS, Engineer, Analyst, Microsoft, Marketing, Travel, Director, Cloud, Software, Ecommerce, Teaching, Video, Education, Python, Legal, JavaScript, Amazon, Junior, Stats, HR, Finance, React, Java, Serverless and Android jobs that are similar:\n\n
$70,000 — $110,000/year\n
\n\n#Benefits\n
๐ฐ 401(k)\n\n๐ Distributed team\n\nโฐ Async\n\n๐ค Vision insurance\n\n๐ฆท Dental insurance\n\n๐ Medical insurance\n\n๐ Unlimited vacation\n\n๐ Paid time off\n\n๐ 4 day workweek\n\n๐ฐ 401k matching\n\n๐ Company retreats\n\n๐ฌ Coworking budget\n\n๐ Learning budget\n\n๐ช Free gym membership\n\n๐ง Mental wellness budget\n\n๐ฅ Home office budget\n\n๐ฅง Pay in crypto\n\n๐ฅธ Pseudonymous\n\n๐ฐ Profit sharing\n\n๐ฐ Equity compensation\n\nโฌ๏ธ No whiteboard interview\n\n๐ No monitoring system\n\n๐ซ No politics at work\n\n๐ We hire old (and young)\n\n
\n\n#Location\nLatin America
# How do you apply?\n\nThis job post has been closed by the poster, which means they probably have enough applicants now. Please do not apply.
\nThis is a fully remote position. \nWork on things that matter\n\nAd Hoc is a digital services company that helps the federal government better serve people. Our teams use modern, agile methods to design and engineer government systems that connect Veterans with services, bring affordable health care to millions of people, and support important programs like Head Start. And as we work to make critical government services intuitive, accessible, and human-centered, weโre also changing how the government thinks about and uses technology. If you thrive on change, want to help close the gap between consumer expectations and government services, and can see the possibilities in ambiguity, then we want you here with us. \nWhat matters most\n\nAd Hoc operates according to our commitment to inclusivity, acceptance, accountability, and humility. We arenโt heroes. We believe in missions larger than our individual selves and leave our egos at the door, learn from our mistakes, and iterate in order to better serve the people in our country. We prioritize building teams that represent the diversity of the people our government serves. We love the challenge of government-size projects. We want to bring skills to federal agencies, help them better meet the needs of their users, and close the gap between consumer expectations and government. \nBuilt for a remote life\n\nAd Hoc is remote-first and remote-always. Weโve designed our culture, communications, and tools to support a nationwide distributed team since the beginning. Being remote by design allows Ad Hoc to be thoughtful and intentional about creating diverse teams and supporting them with a work environment that fits their lives. With a generous PTO policy and Slack channels for every interest (from bird watching to space nerds to parenting) our culture embraces the things happening in your life. Maybe you need to adjust your schedule to care for your family or take a bike ride. At Ad Hoc, thatโs embraced. \n\nThe CMS business unit covers our work with the Centers for Medicare & Medicaid Services, including HealthCare.gov, Medicare.gov, and the Blue Button API. Our team supports CMS in building and improving online public experiences and APIs that are reliable, accessible, and user-centered. We are deeply embedded within CMS, partnering agency-wide to include with the Office of Communications, Office of Enterprise Data and Analytics, Center for Medicaid and CHIP Services, and Center for Medicare and Medicaid Innovation. Our work includes helping millions of people enroll in healthcare and access Medicare and Medicaid benefits, as well as helping CMS improve the quality of Medicare and Medicaid services for beneficiaries and clinicians.\n\nA Lead Infrastructure Architect will exhibit strong communication and infrastructure engineering skills, with the ability to engage with product management, data architecture, and application engineering teams to create an infrastructure roadmap from the present to the future that meets and exceeds stakeholder requirements.\n\nThe Lead Infrastructure Architect is responsible for (Essential Functions):\n\n\nGuiding the development and operation of the full lifecycle of the solution infrastructure\n\nPlanning and executing the design progression of Amazon Web Services and other cloud-based infrastructure\n\nMonitoring and minimizing infrastructure costs\n\nProviding theoretical and real-world expertise in DevOps use of AWS and other cloud-based services, defined using Infrastructure-as-Code tooling like Terraform\n\nEnsuring both human processes and infrastructure design provide robust defense-in-depth of sensitive data confidentiality through the implementation of security best practices.\n\nLeading and providing practical experience in the evaluation of migrations to new cloud-native data services.\n\nUnderstanding the operation and iteration of existing infrastructure, including how and when to use lower level infrastructure technologies like Packer and Docker. \n\nDemonstrating a deep awareness of how changes they make interact with all components in a broader system. This includes technologies for frontend, backend, infrastructure, usability, and design, as well as varying development, testing, and CI/CD release methodologies within an organization.\n\nReducing ambiguity and risk, and improving security in the systems they work with, including additional documentation, refactoring, and testing.\n\nActively engaging in conversations and planning sessions with partners and key stakeholders advocating for the best technical solutions and communicating tradeoffs. Working with the team to deliver on the program milestones in an ambitious roadmap. Presenting to partners and stakeholders as necessary.\n\nElaborating and evolving on complex and ambiguous products to uncover new constraints and opportunities.\n\nManaging the technical relationship with the client, and influencing their technical decision-making.\n\nActively contributing code and performing code review on your applications as an engineer.\n\nExhibiting strategic and critical analysis leadership, with the ability to summarize findings and provide comprehensive recommendations\n\nEnsure that all systems operate smoothly and, in coordination with security-focused team members, align with CMS and NIST quality and compliance standards to retain its Authority To Operate(ATO).\n\nEffectively communicate on existing systems, design decisions, past performance, and a major history of the projects that theyโve been part of for bid-writing, tech demos, and other potentially client-facing communications.\n\nCollaborating with a multidisciplinary team of product owners, engineers, designers and researchers, and adapting communication style to the audience.\n\nProviding mentorship and guidance to team members through practice, code review, presentations, and architecture.\n\n\n\nSome basic requirements\n\n\nAll work must be conducted within the U.S., excluding U.S. territories. Some federal contracts require U.S. citizenship to be eligible for employment.\n\nYou must be legally authorized to work in the U.S now and in the future without sponsorship.\n\nAs a government contractor, you may be required to obtain a public trust security clearance.\n\n8+ years of professional software development\n\nBachelor's Degree is required.\n\n\n\nBenefits\n\n\nCompany-subsidized Health, Dental, and Vision Insurance\n\nVanguard 401K Plan\n\nUnlimited Vacation\n\nContinuing Education/Annual Conference Attendance Stipend\n\n\n\n\nAd Hoc LLC is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, national origin, ancestry, sex, sexual orientation, gender identity or expression, religion, age, pregnancy, disability, work-related injury, covered veteran status, political ideology, marital status, or any other factor that the law protects from employment discrimination.\n\nIn support of theโฏColorado Equal Pay Transparency Act, and others like it across the country, Ad Hoc job descriptions feature the starting range we reasonably expect to pay to candidates who would join our team with little to no need for training on the responsibilities we've outlined above. Actual compensation is influenced by a wide range of factors including but not limited to skill set, level of experience, and responsibility. The range of starting pay for this role is $113,900 - $149,040 and information on benefits offered is here. Our recruiters will be happy to answer any questions you may have, and we look forward to learning more about your salary requirements. \n\n#Salary and compensation\n
No salary data published by company so we estimated salary based on similar jobs related to DevOps, Amazon and Engineer jobs that are similar:\n\n
$70,000 — $120,000/year\n
\n\n#Benefits\n
๐ฐ 401(k)\n\n๐ Distributed team\n\nโฐ Async\n\n๐ค Vision insurance\n\n๐ฆท Dental insurance\n\n๐ Medical insurance\n\n๐ Unlimited vacation\n\n๐ Paid time off\n\n๐ 4 day workweek\n\n๐ฐ 401k matching\n\n๐ Company retreats\n\n๐ฌ Coworking budget\n\n๐ Learning budget\n\n๐ช Free gym membership\n\n๐ง Mental wellness budget\n\n๐ฅ Home office budget\n\n๐ฅง Pay in crypto\n\n๐ฅธ Pseudonymous\n\n๐ฐ Profit sharing\n\n๐ฐ Equity compensation\n\nโฌ๏ธ No whiteboard interview\n\n๐ No monitoring system\n\n๐ซ No politics at work\n\n๐ We hire old (and young)\n\n
\n\n#Location\nBoston, Massachusetts, United States
๐ Please reference you found the job on Remote OK, this helps us get more companies to post here, thanks!
When applying for jobs, you should NEVER have to pay to apply. You should also NEVER have to pay to buy equipment which they then pay you back for later. Also never pay for trainings you have to do. Those are scams! NEVER PAY FOR ANYTHING! Posts that link to pages with "how to work online" are also scams. Don't use them or pay for them. Also always verify you're actually talking to the company in the job post and not an imposter. A good idea is to check the domain name for the site/email and see if it's the actual company's main domain name. Scams in remote work are rampant, be careful! Read more to avoid scams. When clicking on the button to apply above, you will leave Remote OK and go to the job application page for that company outside this site. Remote OK accepts no liability or responsibility as a consequence of any reliance upon information on there (external sites) or here.
This job post is closed and the position is probably filled. Please do not apply. Work for GRIMM and want to re-open this job? Use the edit link in the email when you posted the job!
๐ค Closed by robot after apply link errored w/ code 404 3 years ago
Thank you for considering GRIMM...\n\nSr Challenge Development Lead\nThe GRIMM AppSec team works with clients not just to assess current technologies and systems but to help train developers, architects, operators, and leadership through the use of hands on capture the flag (CTF) style exercises. These include both internal product development as well as custom solutions developed in partnership with our clients. \n\nGRIMM is seeking a senior engineer to primarily lead these types of engagements, but with the flexibility to support other engagements as needed. This is a customer-facing position; qualified applicants will need to be comfortable engaging with clients on their own to gather and refine requirements, discuss findings and development, present progress, and also to help establish and expand business relationships with our customers.ย \n\nIn addition to creating, deploying, and running Capture The Flag events, the AppSec team focuses on a range of topics covering security design reviews (architecture, protocol analysis, etc.) including threat modeling, kernel vulnerability research, mobile/web/desktop app vulnerability research, embedded systems analysis, and more.ย All members of our team are constantly learning about new topics and applying that knowledge to challenging problems.ย We all share information and help guide each other as a team, and everyone has opportunity to work independently and direct their own activities.\n\nEducation and Certification\nA degree or comparable work experience is required in the fields of Computer Science, Computer Engineering, or a related discipline.ย Degreed or certified candidates will not receive preferential consideration.ย If a specific certification is required by a client GRIMM will cover certification costs.\nย \nLocation\nThe AppSec team is 100% remote.ย Some future (post-pandemic) projects may require travel to customer sites or other venues where in person CTFs may be hosted.ย Travel will be less than 25%, though opportunities for additional travel may be available if desired.\n\nCompany Description\nGRIMM researches and develops the art of the possible in business modernization and computing technologies through cybersecurity, sensors, tools, analytics, frameworks, modeling and simulation, automated testing, cyber range Installation, Operations, and Maintenance (IOM), consulting, and intelligence. Our practices build on extensive experience in cyber mission support for national defense, and commercial service improvement and consulting. Our engineers and subject matter experts (SMEs) learned their trade from real-world engagements, not just textbooks.ย \nย \nPosition Requirements:\nThe ideal candidate will have at least 5 years of experience in application in security, including at least 2 years creating/deploying/running Capture The Flag (CTF) competitions. They will also need to be able to manage and lead all technical aspects of a client engagement.ย A senior engineer must be able to oversee and mentor junior and mid level engineers. ย \n\nDesired Qualities:\nStrong technical background in multiple application security fields such as:\n* Vulnerability Analysis\n* Threat Modeling\n* Security Design Reviews\n* In-depth knowledge of an operating system\n* Network traffic analysis\n* Web security\n* Source analysis\n\nAdditional desired traits include:\n* US Resident\n* Desire and aptitude for public speaking\n* Willingness to go to conferences and represent the company (speaking, running contests/exhibits, etc.)\nย \nPerks:\nAbility to work from home, with some travel\nWork with a team of skilled people who think hacking is fun\nTake on a variety of high caliber technical challenges\nStrong benefits package\nMedical/dental/vision insurance premiums paid 100% by the company\n5% company match for 401K plan, no vesting period\n10 paid holidays and flexible vacation policy\nย \nGRIMM promotes a Drug-Free Workplace, is an Equal Opportunity Employer (EOE) and an Affirmative Action Employer.\n\nGRIMM researches and develops the art of the possible in business modernization and computing technologies through cybersecurity, sensors, tools, analytics, frameworks, modeling and simulation, automated testing, cyber range Installation, Operations and Maintenance (IOM), consulting, and intelligence. Our practices build on extensive experience in cyber mission support for national defense, and commercial service improvement and consulting. Our engineers and subject matter experts (SMEs) learned their trade from real-world engagements, not just textbooks.ย \n\nWe promote a Drug-Free Workplace, are an Equal Opportunity Employer (EOE) and Affirmative Action Employer. \n\n#Salary and compensation\n
No salary data published by company so we estimated salary based on similar jobs related to Executive, Travel, Senior, Junior and Engineer jobs that are similar:\n\n
$80,000 — $120,000/year\n
\n\n#Benefits\n
๐ฐ 401(k)\n\n๐ Distributed team\n\nโฐ Async\n\n๐ค Vision insurance\n\n๐ฆท Dental insurance\n\n๐ Medical insurance\n\n๐ Unlimited vacation\n\n๐ Paid time off\n\n๐ 4 day workweek\n\n๐ฐ 401k matching\n\n๐ Company retreats\n\n๐ฌ Coworking budget\n\n๐ Learning budget\n\n๐ช Free gym membership\n\n๐ง Mental wellness budget\n\n๐ฅ Home office budget\n\n๐ฅง Pay in crypto\n\n๐ฅธ Pseudonymous\n\n๐ฐ Profit sharing\n\n๐ฐ Equity compensation\n\nโฌ๏ธ No whiteboard interview\n\n๐ No monitoring system\n\n๐ซ No politics at work\n\n๐ We hire old (and young)\n\n
# How do you apply?\n\nThis job post has been closed by the poster, which means they probably have enough applicants now. Please do not apply.