Skip to main content
Back to jobs

Application Security Engineer

External
virtru logoVirtru · Washington, DC
$180K–$200K/yrFull-timeRemote1w ago
AndroidApplication SecurityCryptographyJavaScriptPenetration TestingREST
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


Benefits

Paid time off

Additional Information

About Virtru: While the rest of the security industry obsesses over locking data down to prevent it from being lost or stolen, we're doing something fundamentally different at Virtru. We're setting data free so that you can intentionally share it with others, but without sacrificing security, privacy, or control. We've created both a suite of powerful data protection applications and an open platform that's sparking an ecosystem of innovation. Through the Trusted Data Format (TDF) open standard, we're not just protecting data; we're creating a new paradigm where security enables sharing rather than preventing it. Think of us as the Android of data protection: a robust platform with an open core that developers and partners can build upon, coupled with our own best-in-class applications that showcase what's possible when you reimagine security from the ground up. Backed by Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global, we're helping Fortune 500 companies and government agencies discover that true data security means having the freedom to share, collaborate, and innovate - without compromise. About Virtru: While the rest of the security industry obsesses over locking data down to prevent it from being lost or stolen, we're doing something fundamentally different at Virtru. We're setting data free so that you can intentionally share it with others, but without sacrificing security, privacy, or control. We've created both a suite of powerful data protection applications and an open platform that's sparking an ecosystem of innovation. Through the Trusted Data Format (TDF) open standard, we're not just protecting data; we're creating a new paradigm where security enables sharing rather than preventing it. Think of us as the Android of data protection: a robust platform with an open core that developers and partners can build upon, coupled with our own best-in-class applications that showcase what's possible when you reimagine security from the ground up. Backed by Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global, we're helping Fortune 500 companies and government agencies discover that true data security means having the freedom to share, collaborate, and innovate - without compromise. Compensation: $180,000 - $200,000/year Team & Position Details: Here at Virtru you'll join an innovative product security team that is helping secure some of the world's most important information. Our platform, built on an open source core, functions in a wide range of threat models. As an application security engineer you will help our engineering teams maintain and develop our product, and directly have impact in a security centric company and product. An ideal candidate is prepared to operate in a public and open source form, in addition to being able to review complex systems and product requirements. You should have a strong foundation in the fundamentals of cryptography, and be able to talk and collaborate with development teams. Our applications are primarily built in Go and Javascript. We use a range of security tools, and aggressively automate where we can (even if we have to code and build it). If you are excited rather than scared by highly technical problems, we are offering a security role where you can learn and grow while having direct impact in continuing to harden a security critical mission. As an Application Security Engineer, your responsibilities will include: Security Engineering Collaborate with development teams, Site Reliability Engineering, and other stakeholders to strengthen the adoption of security best practices throughout the SDLC. Independently identify security improvements and implement them. Vulnerability Management: Implement, manage, and automate vulnerability management processes. Prioritize and remediate vulnerabilities discovered through internal scans, penetration tests, and bug bounties. Security Assessments Conduct threat modeling, code audits, design reviews with engineers to ensure effective and secure development. Collaborate in providing actionable recommendations to find workable solutions. Threat Hunting: Establish a threat hunting capability and automate where appropriate. Enhance logging capabilities related to security events. Security Tools Integration and Management: Integrate and manage dynamic and static code analysis tools. Ensure operation of security tools within the development pipeline. Skills that will help you thrive in this role: 4+ years experience in secure development or application security. Deep knowledge of security concepts such as authentication, web architecture, etc. Experience with Nodejs, Go, etc. Experience running bug-bounty, penetration testing, vulnerability scanning programs. Experience setting up and maintaining SAST, DAST, IAST and SCA tooling Experience using assessment tools such as Burp, ZAP, Qualys, Nessus, etc. Experience building and maintaining WA


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at virtru? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect