Application Security Engineer
OverviewCorporate Tools is hiring an Security Engineer for $175,000/year. You will be a traditional company employee. This is a remote position, but if you're near one of our local offices, you're welcome to come hangout with us in-office as well. Our main offices are in Post Falls, ID, and Spokane, WA; we also have satellite offices in Austin, TX, and Salt Lake City, UT. You'll be working 40 hours a week and, of course, enjoy great company benefits.We are expanding our team to include a Security Engineer to be 100% focused on our security efforts. As the right candidate, you will have experience working in-house as a full-time penetration tester, a regular 3rd party bug bounty program pen tester, or in a similar security type role. Your job will be to identify our vulnerabilities to help keep our information safe and secure.WageUp to $175,000 / yearBenefits100% employer-paid medical, dental & vision Full coverage for employees - nothing comes out of your paycheck. Plus an annual review with a raise option.Time off that grows with you 22 days PTO + 4 holidays to start. After 3 years it bumps to 29 days, and after 5 years you move to flexible time off - not accrued, not capped. Take time off when you want.Parental leave & 401(k) match Paid parental leave, plus up to 6% company 401(k) matching with no vesting period - it's yours from day one.Quarterly allowance Spend it on whatever makes work better: a comfier remote setup, continuing-education classes, a plant for your desk, coffee for a coworker, a massage for yourself... really, whatever.No dumb perks (and a trail mix bar) No weekend dog-walking gimmicks that look cool but cost nothing because nobody uses them. We spend on benefits you'll actually use - an open-concept office, friendly coworkers, a creative environment, and yeah... a trail mix bar.ResponsibilitiesUnderstand and safely use various open source penetration testing tools and when appropriate, emulating hacker tactics, techniques, proceduresCreate security vulnerability reports for both technical and executive audiencesWhile in-between assessments, you will be expected to help our security engineers think through solutions to problems you findAutomate tasks and script at a basic level to enhance penetration testing processesPassion for learning new technologies and processes, and contributing to refining existing capabilitiesCommunicate with stakeholders (technical and non-technical), both verbal and writtenStay up to date on 0 day exploits for tech stacks we useRequirementsSolid fundamentals in webapp and network pentesting (2+ years). Pentesting experience in mobile apps, APIs, and/or cloud environments a bonus4+ years of professional experience in Ruby on Rails or equivalent and Vue or a Frontend equivalent frameworkExperience with Linux and cloud environment testingUnderstanding of security issues for desktop, virtual, cloud services and network infrastructuresWorking knowledge of information systems security standards/practices (e.g., access control and system hardening, system audit and log file monitoring, security policies, and incident handling)Experience with secure network protocols and encryption of communications between networked hostsExperience in IT systems and security policies, standards, industry trends, and techniquesExperience with assessing APT threats, Penetration Testing, Vulnerability Management, attack methodologies, forensics analysis techniques, malware analysis, attack surface comprehension, Cyber Threat Emulation operations, Cyber Advanced Threat Emulation Team operations and research, identification, and/or verification of new APT TTPsFundamental understanding of security knowledge of testing mobile, native applications, web applications, distributed and database systemsMust be detail-oriented and possess strong problem-solving skills and ability to analyze for potential future issuesSolid understanding of common webapp vulnerabilities, exploitation techniques, and remediation options