Alma is seeking a mission-driven Senior Application Security Engineer to join our team. We are dedicated to building secure and compliant tools and services which help mental healthcare providers more easily manage and grow their practice. In this role, you will help validate that our services, applications and web technologies are designed and implemented in a way that meets Alma’s security standards. You will help analyze, discover, and address security issues across our technical platform.
On this scaling team, you will have a strong hand in defining how Alma's engineering team approaches application security in the software development process. The ideal person for this role loves to work with other teams to design and build amazing security controls and automation.
- You have 4-7 years of experience working in an application security role, including familiarity with common security libraries and tools, and an expert knowledge of web application protocols.
- You strongly understand security best practices for the development lifecycle (SDLC).
- You have deep technical knowledge of Content Security Policies (CSP) and how to implement them.
- You have expert understanding of application security testing tools like OWASP ZAP and Burpsuite.
- You have experience writing code and scripts for application security testing.
- You have expert understanding of the OWASP Top 10 and other application attacks.
- You have experience installing and running a local developer environment for local testing of code.
- You have deep technical knowledge of application development, operating system environments, and AWS cloud infrastructure as they pertain to application security.
- You have personally implemented/managed SAST and DAST tools such as StackHawk and Snyk.
- You have experience identifying security issues through threat modeling and code reviews.
- You have experience building and maintaining security systems that can scale, with high levels of automation while fully owning projects from inception to completion.
- You have strong communication skills and can convey complex technical topics to non-technical stakeholders clearly and concisely.
- You enjoy user-centered software development and actively work closely with a team of engineers, designers, and product managers.
Benefits:
- We’re a remote-first company
- Health insurance plans through Cigna (medical and dental) and MetLife (vision), including FSA and HSA plans
- 401K plan (Roth and traditional)
- Monthly therapy and wellness stipends
- Monthly co-working space membership stipend
- Monthly work-from-home stipend
- Financial wellness benefits through Northstar
- Pet discount program through United Pet Care
- Financial perks and rewards through BenefitHub
- EAP access through Cigna
- One-time home office stipend to set up your home office
- Comprehensive parental leave plans
- 11 paid holidays, 1 Alma Mental Health Day, and 1 Alma Volunteering Day
- Flexible PTO
Salary Band: $145,000 - $175,000
Alma’s compensation philosophy is driven by our company value of building equity. To best ensure pay equity, we typically bring in new hires near the middle of our listed salary bands and we do not negotiate our compensation (i.e. all people hired at the same level & role are brought in at the same salary, equity, and benefits). The recruiter you work with can provide more details on our philosophy.