Thumbtack

We help people care for their home from top to bottom — and empower small businesses nationwide to grow.

Security Engineer – App Sec, Cloud Infra

Security EngineerSecurity EngineerFull TimeRemoteTeam 1,001-5,000H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

51 days ago

Salary

$151.3K - $229.9K / year

4 yrs expEnglishAWSCloudGoogle Cloud Platform

Job Description

• Own and deliver application security work within defined projects or domains. Contribute to cross-functional security initiatives, executing clearly scoped pieces of larger efforts. • Identify, prioritize, and help remediate application security risks in partnership with engineering teams. • Apply secure-by-default patterns and approved architectures when designing or reviewing systems. • Support cloud infrastructure security by integrating security controls into CI/CD pipelines, IAM, networking, and runtime environments. • Partner with product and engineering teams to assess risk and recommend practical, risk-informed security improvements. Participate in application security design reviews and threat modeling for new and existing systems. • Write code, reviews, and documentation to address vulnerabilities and reduce recurring classes of issues. • Participate in security incident response and contribute to post-incident analysis and remediation.

Job Requirements

  • 4+ years of experience in software engineering, application security, or cloud infrastructure security.
  • Practical experience with application security techniques such as threat modeling, secure design patterns, authentication and authorization, secrets management, and vulnerability remediation. Strong understanding of secure coding practices and common application security risks (e.g., OWASP Top 10).
  • Experience securing cloud-native systems in AWS and/or GCP.
  • Ability to assess security risks and break down complex problems, reason about tradeoffs, make sound recommendations, and deliver practical, impactful solutions with guidance when needed.
  • Strong sense of ownership over assigned work, with the ability to execute independently and follow through.
  • Clear written and verbal communication skills, including the ability to explain security issues to engineers with varying levels of security expertise.
  • A growth mindset and interest in learning from more senior engineers and expanding depth in both application and cloud infrastructure security over time.

Related Categories

Related Job Pages

More Security Engineer Jobs

Cryptographic Systems Expert

SilverEdge Government Solutions

SilverEdge Government Solutions was founded on the belief that nurturing talent and collaborating closely with our customers enables us to think big and deliver the best for our country. Our mission is to bring top technology talent together to solve the world’s most challenging problems while protecting the United States and our allies. SilverEdge Government Solutions, LLC is an Equal Opportunity Employer and applicants receive lawful consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Security Engineer52 days ago
Full TimeRemoteTeam 201-500H1B No Sponsor

SilverEdge Government Solutions is seeking a highly skilled and knowledgeable Post-Quantum Cryptography (PQC) Evaluation Expert to join our team. The successful candidate will be responsible for creating and evaluating question-answer pairs to assess the understanding and applica...

CryptographyPost-Quantum CryptographyLattice-based CryptographyHash-based CryptographyCode-based CryptographyMultivariate Polynomial CryptographyNIST StandardsQuantum Computing
United States

Product Security Engineer

Hashgraph

Hashgraph, formerly Swirlds Labs, is a software company home to some of the brightest minds in web3.

Security Engineer52 days ago
Full TimeRemoteTeam 51-200Since 2022H1B No Sponsor

Product Security Engineer focusing on blockchain and Web3 security at Hashgraph

IPFSJavaRustWeb3
United States
Full TimeRemoteTeam 51-200Since 2012H1B No Sponsor

Senior Account Manager driving sales for advanced safety solutions at 908 Devices

United States

Senior Sales Recruiter – National Security

TRM Labs

Blockchain intelligence solutions to detect, monitor and investigate fraud and financial crime in digital assets.

Security Engineer52 days ago
Full TimeRemoteTeam 51-200H1B Sponsor

Senior Sales Recruiter for TRM Labs in National Security sector

United States