Current Statistics
1,301,530 Total Jobs 268,174 Jobs Today 14,879 Cities 222,737 Job Seekers 146,873 Resumes |
|
|
 |
|
 |
 |
Staff Application Security Engineer - San Francisco California
Company: SPAN Location: San Francisco, California
Posted On: 05/09/2025
Our MissionSPAN is enabling electrification for allSPAN is mission-driven to design, build, and deploy products that electrify our built environment, decarbonize our world, and slow the effects of climate change. - Decarbonization is the process to reduce or remove greenhouse gas emissions, especially carbon dioxide, from entering our atmosphere.
- Electrification is the process of replacing fossil fuel appliances that run on gas or oil with all-electric upgrades for a cleaner way to power our lives.At SPAN, we believe in:
- Enabling homes and vehicles powered by clean energy
- Making electrification upgrades possible
- Building more resilient homes with reliable backup
- Designing a flexible and distributed electrical gridThe RoleWe are seeking a highly skilled and experienced individual to join our Security & Privacy team at SPAN as a Staff Application Security Engineer. In this critical role, you will be instrumental in building and enhancing SPAN's application security program. Your responsibilities will ensure the security of our applications through proactive assessment, threat modeling, code reviews, and close collaboration with the development teams. Ideal candidates will have extensive experience in application security, a deep understanding of secure coding practices, and the ability to influence and educate others on security matters.Responsibilities include:
- Developing a comprehensive application security strategy aligned with company objectives.
- Performing secure design and code reviews to identify, mitigate, and prevent security vulnerabilities, enabling SPAN teams to deliver secure, high-quality products.
- Leading and executing SAST/DAST/SCA efforts.
- Collaborating closely with development teams to integrate security best practices into the software development lifecycle (SDLC).
- Performing threat modeling on existing and upcoming feature sets in SPAN applications to ensure appropriate security controls are built from the ground up.
- Developing and enforcing a robust authentication and authorization posture.
- Designing, implementing, and maintaining application security controls and solutions, leveraging hands-on coding experience.
- Ensuring compliance with regulatory requirements and industry standards including risk assessments and risk mitigation strategies for application security.
- Staying current with the latest application security threats, vulnerabilities, and best practices. Continuously evaluating and improving application security processes and technologies.About You
- Bachelor's Degree in Computer Science, Information Assurance, Cyber Security, or related field of study.
- 7+ years of experience in a security engineering or operations role, with a focus on application security.
- Deep understanding of web and mobile application vulnerabilities and defenses.
- Hands-on experience with one or more application security scanning tools.
- Expertise in web, mobile, and API security.
- Ability to effectively communicate with technical and non-technical audiences.
- Proficient in writing production-quality code in one or more languages such as Python, Kotlin, or NodeJS.
- Experience in developing threat models (e.g., STRIDE, DREAD).Nice-to-Have
|
 |
 |
 |
 |
|
|